Search the docs

User and Group Management

builtin-group-user-add

builtin-group-user-add [options]

Add user to a builtin group

Options

--group

Group name to be added to (Required)

--help

Display this help and exit

--username

The username to be added (Required)


builtin-group-user-list

builtin-group-user-list [options]

List users of a builtin group

Options

--group

The group name to be listed (Required)

--help

Display this help and exit


builtin-group-user-remove

builtin-group-user-remove [options]

Remove user from a builtin group

Options

--group

Group name to be removed from (Required)

--help

Display this help and exit

--username

The username to be removed (Required)


login-policy-config

login-policy-config [options]

Configure the system login policies

Options

--allowed-networks

Space separated list of allowed networks in CIDR notation (i.e. 10.50.100.0/24)

--allowed-networks-clear

Allow access from all remote networks

--help

Display this help and exit

--lock-after-failures

The number of consecutive login failures after which an account will be locked. When not set, the account lockout feature is disabled

--lock-after-failures-clear

Clears all login failure lock attributes. Resets failure counts for all users

--lock-failure-interval

The time in seconds between failed login attempts that constitutes consecutive failures. When not set, the default is 15 minutes. Requires that lock-after-failures is, or has been set

--lockout-time

The amount of time in seconds an account remains locked due to too many consecutive login failures. When not set, the default is 10 minutes. Requires that lock-after-failures is, or has been set

--view

View the default login policies


role-create

role-create [options]

Create a user role with access permissions

Example
role-create --name graham --acl "ANY:+c+r+u+d"
Available OBJECT_TYPEs include ANY,EVENT,NODE,DATA_MOVER,NETWORK_IF,SHARE,USER,USER_GROUP,ROLE,TASK,SMTP,NOTIFICATION_RULE,HEARTBEAT,NTP,LOGICAL_VOLUME,LDAP,CLUSTER,ELEMENTAL_OBJECTIVE,OBJECTIVE,SCHEDULE,SNAPSHOT_RETENTION,FILE_SNAPSHOT,OBJECT_STORAGE_VOLUME,CLOUD_MOVER,OBJECT_STORE_LOGICAL_VOLUME,SNMP,SW_UPDATE_TASK,CTDB,SHARE_SNAPSHOT,BACKUP,SAMBA_AD,DOMAIN_IDMAP,DATA_PORTAL,DNS,VOLUME_GROUP

Options

--acl

ACL, in the format: {OBJECT_TYPE}:{+{grant permissions}}{-{revoke permissions}}. Possible permissions: 'c'-create, 'r'-read, 'u'-update, 'd'-delete (Required)

--help

Display this help and exit

--idle-timeout

This role’s idle timeout for user interfaces (Web UI, CLI). When not specified, the default is 1 hour. May be formatted as 10seconds, 1minute, "1 hour 30 minutes", etc. When no units are specified, minutes are assumed

--name

The role name (Required)

--no-idle-timeout

Disables this role’s idle timeout for user interfaces


role-delete

role-delete [options]

Remove a user role

Options

--help

Display this help and exit

--id

The ID of the role to be deleted. Required unless "--name" is specified

--name

The name of the role to be deleted. Required unless "--id" is specified


role-list

role-list [options]

List user roles

Options

--full

Print extra information for each element

--help

Display this help and exit

--id

The ID of the role to list

--name

The name of the role to list


role-update

role-update [options]

Update an existing user role

Example
role-update --name graham --acl "ANY:+c+r+u-d"
Available OBJECT_TYPEs include ANY,EVENT,NODE,DATA_MOVER,NETWORK_IF,SHARE,USER,USER_GROUP,ROLE,TASK,SMTP,NOTIFICATION_RULE,HEARTBEAT,NTP,LOGICAL_VOLUME,LDAP,CLUSTER,ELEMENTAL_OBJECTIVE,OBJECTIVE,SCHEDULE,SNAPSHOT_RETENTION,FILE_SNAPSHOT,OBJECT_STORAGE_VOLUME,CLOUD_MOVER,OBJECT_STORE_LOGICAL_VOLUME,SNMP,SW_UPDATE_TASK,CTDB,SHARE_SNAPSHOT,BACKUP,SAMBA_AD,DOMAIN_IDMAP,DATA_PORTAL,DNS,VOLUME_GROUP

Options

--acl

ACL, in the format: {OBJECT_TYPE}:{+{grant permissions}}{-{revoke permissions}}. Possible permissions: 'c'-create, 'r'-read, 'u'-update, 'd'-delete

--help

Display this help and exit

--id

The ID of the role to update. Required unless "--name" is specified

--idle-timeout

This role’s idle timeout for user interfaces (Web UI, CLI). May be formatted as 10seconds, 1minute, "1 hour 30 minutes", etc. When no units are specified, minutes are assumed

--idle-timeout-clear

Disables this role’s idle timeout for user interfaces

--name

The name of the role to update. Required unless "--id" is specified


user-create

user-create [options]

Create a system user

Options

--data-access-role

Data access role(s) assigned to user. Required unless any of the following is specified: --mgmt-role-name, --mgmt-role-id Possible values: SMB | S3.

--email

The user’s email address

--first-name

The user’s first name

--gid

Group identifier

--help

Display this help and exit

--last-name

The user’s last name

--mgmt-role-id

The management role ID to apply to the user (that includes the user’s management permissions). Required unless any of the following is specified: --mgmt-role-name, --data-access-role

--mgmt-role-name

The management role name to apply to the user (that includes the user’s management permissions). Required unless any of the following is specified: --mgmt-role-id, --data-access-role

--password

The user’s password. Passwords must be 8-20 characters long and contain at least one each of: lower case letter, upper case letter, digit and non-alphanumeric. (Required)

--public-key

The user’s public encryption key

--uid

User identifier

--username

The username that will be used to identify the user in the system. Valid usernames contain the following characters: a-z, A-Z, 0-9, '-'. '_', '.', and can optionally end with a '$'. Valid usernames must start with a-z, A-Z, or '_'. (Required)


user-delete

user-delete [options]

Delete a system user

Options

--help

Display this help and exit

--id

The ID of the user to delete. Required unless "--name" is specified

--name

The name of the user to delete. Required unless "--id" is specified


user-import

user-import [options]

Imports users from CSV file

Example of a CSV file:

username,password,uid,gid,role,groups,public-key,first-name,last-name,email,data-access-roles
user1,P@ssword1,0,0,,"group1,group2",,John,Doe,john@example.com,"S3,SMB"

Options

--help

Display this help and exit

--uri

The URI for the CSV file containing users details. For example: file:/tmp/user.csv (Required)


user-list

user-list [options]

List all existing users

Options

--full

Print extra information for each element

--help

Display this help and exit

--id

The ID of the user to list

--name

The name of the user to list


user-password-update

user-password-update [options]

Update a user password

Options

--help

Display this help and exit

--id

The ID of the user whose password will be updated. Required unless "--name" is specified

--name

The name of the user whose password will be updated. Required unless "--id" is specified

--new-password

The new password. Passwords must be 8-20 characters long and contain at least one each of: lower case letter, upper case letter, digit and non-alphanumeric. (Required)

--old-password

The user’s old password


user-update

user-update [options]

Update the user’s properties, including the applied user role. If a new role is provided it overwrites the current user’s role

Options

--data-access-role-add

Add a data access role to the user. May be repeated. Required unless any of the following is specified: --data-access-role-remove, --enable, --public-key, --data-access-role-clear, --last-name-clear, --public-key-clear, --mgmt-role-clear, --uid-clear, --disable, --email, --first-name-clear, --last-name, --mgmt-role-name, --first-name, --gid-clear, --mgmt-role-id Possible values: SMB | S3.

--data-access-role-clear

Remove all data access roles. Required unless any of the following is specified: --data-access-role-remove, --enable, --public-key, --last-name-clear, --public-key-clear, --mgmt-role-clear, --uid-clear, --data-access-role-add, --disable, --email, --first-name-clear, --last-name, --mgmt-role-name, --first-name, --gid-clear, --mgmt-role-id

--data-access-role-remove

Remove a data access role from the user. May be repeated. Required unless any of the following is specified: --enable, --public-key, --data-access-role-clear, --last-name-clear, --public-key-clear, --mgmt-role-clear, --uid-clear, --data-access-role-add, --disable, --email, --first-name-clear, --last-name, --mgmt-role-name, --first-name, --gid-clear, --mgmt-role-id Possible values: SMB | S3.

--disable

Disable the user. Required unless any of the following is specified: --data-access-role-remove, --enable, --public-key, --data-access-role-clear, --last-name-clear, --public-key-clear, --mgmt-role-clear, --uid-clear, --data-access-role-add, --email, --first-name-clear, --last-name, --mgmt-role-name, --first-name, --gid-clear, --mgmt-role-id

--email

The user’s email address. Required unless any of the following is specified: --data-access-role-remove, --enable, --public-key, --data-access-role-clear, --last-name-clear, --public-key-clear, --mgmt-role-clear, --uid-clear, --data-access-role-add, --disable, --first-name-clear, --last-name, --mgmt-role-name, --first-name, --gid-clear, --mgmt-role-id

--enable

Enable the user. Required unless any of the following is specified: --data-access-role-remove, --public-key, --data-access-role-clear, --last-name-clear, --public-key-clear, --mgmt-role-clear, --uid-clear, --data-access-role-add, --disable, --email, --first-name-clear, --last-name, --mgmt-role-name, --first-name, --gid-clear, --mgmt-role-id

--first-name

The user’s first name. Required unless any of the following is specified: --data-access-role-remove, --enable, --public-key, --data-access-role-clear, --last-name-clear, --public-key-clear, --mgmt-role-clear, --uid-clear, --data-access-role-add, --disable, --email, --first-name-clear, --last-name, --mgmt-role-name, --gid-clear, --mgmt-role-id

--first-name-clear

Clear the first name. Required unless any of the following is specified: --data-access-role-remove, --enable, --public-key, --data-access-role-clear, --last-name-clear, --public-key-clear, --mgmt-role-clear, --uid-clear, --data-access-role-add, --disable, --email, --last-name, --mgmt-role-name, --first-name, --gid-clear, --mgmt-role-id

--gid

Group identifier

--gid-clear

Clear the group identifier. Required unless any of the following is specified: --data-access-role-remove, --enable, --public-key, --data-access-role-clear, --last-name-clear, --public-key-clear, --mgmt-role-clear, --uid-clear, --data-access-role-add, --disable, --email, --first-name-clear, --last-name, --mgmt-role-name, --first-name, --mgmt-role-id

--help

Display this help and exit

--id

The ID that identifies the user in the system. Required unless "--name" is specified

--last-name

The user’s last name. Required unless any of the following is specified: --data-access-role-remove, --enable, --public-key, --data-access-role-clear, --last-name-clear, --public-key-clear, --mgmt-role-clear, --uid-clear, --data-access-role-add, --disable, --email, --first-name-clear, --mgmt-role-name, --first-name, --gid-clear, --mgmt-role-id

--last-name-clear

Clear the last name. Required unless any of the following is specified: --data-access-role-remove, --enable, --public-key, --data-access-role-clear, --public-key-clear, --mgmt-role-clear, --uid-clear, --data-access-role-add, --disable, --email, --first-name-clear, --last-name, --mgmt-role-name, --first-name, --gid-clear, --mgmt-role-id

--mgmt-role-clear

Clear the management role. Required unless any of the following is specified: --data-access-role-remove, --enable, --public-key, --data-access-role-clear, --last-name-clear, --public-key-clear, --uid-clear, --data-access-role-add, --disable, --email, --first-name-clear, --last-name, --mgmt-role-name, --first-name, --gid-clear, --mgmt-role-id

--mgmt-role-id

The management role ID to apply to the user (that includes the user’s management permissions). Required unless any of the following is specified: --data-access-role-remove, --enable, --public-key, --data-access-role-clear, --last-name-clear, --public-key-clear, --mgmt-role-clear, --uid-clear, --data-access-role-add, --disable, --email, --first-name-clear, --mgmt-role-name, --last-name, --first-name, --gid-clear

--mgmt-role-name

The management role name to apply to the user (that includes the user’s management permissions). Required unless any of the following is specified: --data-access-role-remove, --enable, --public-key, --data-access-role-clear, --last-name-clear, --public-key-clear, --mgmt-role-clear, --uid-clear, --data-access-role-add, --disable, --email, --first-name-clear, --last-name, --first-name, --gid-clear, --mgmt-role-id

--name

The username that identifies the user in the system. Required unless "--id" is specified

--password

Password to assign to user being updated. Required if adding SMB data access role. Passwords must be 8-20 characters long and contain at least one each of: lower case letter, upper case letter, digit and non-alphanumeric

--public-key

The user’s public encryption key. Required unless any of the following is specified: --data-access-role-remove, --enable, --data-access-role-clear, --last-name-clear, --public-key-clear, --mgmt-role-clear, --uid-clear, --data-access-role-add, --disable, --email, --first-name-clear, --last-name, --mgmt-role-name, --first-name, --gid-clear, --mgmt-role-id

--public-key-clear

Clear the public key. Required unless any of the following is specified: --data-access-role-remove, --enable, --public-key, --data-access-role-clear, --last-name-clear, --mgmt-role-clear, --uid-clear, --data-access-role-add, --disable, --email, --first-name-clear, --last-name, --mgmt-role-name, --first-name, --gid-clear, --mgmt-role-id

--uid

User identifier

--uid-clear

Clear the user identifier. Required unless any of the following is specified: --data-access-role-remove, --enable, --public-key, --data-access-role-clear, --last-name-clear, --public-key-clear, --mgmt-role-clear, --data-access-role-add, --disable, --email, --first-name-clear, --last-name, --mgmt-role-name, --first-name, --gid-clear, --mgmt-role-id