User account and password management
nsroot administrative user account.
-
System user account lockout
-
Lock system user account for management access
-
Unlock a locked system user account for management access
-
Disable management access for system user account
-
Force passwords change for
nsrootadministrative users -
Remove sensitive files in a system user account
-
Strong password configuration for system users
-
Enforce password rotation and password history for local accounts
System user account lockout
persistentLoginAttemptsparameter can be enabled.
set aaa parameter -maxloginAttempts <value> -failedLoginTimeout <value> -persistentLoginAttempts (ENABLED | DISABLED)
set aaa parameter -maxloginAttempts 3 -failedLoginTimeout 10 -persistentLoginAttempts ENABLED
aaa.user.login_attempts expression to take effect, you must disable the "Persistent Login Attempts" parameter.
unset aaa parameter -persistentLoginAttempts command to disable (if enabled) the persistent login attempts.
show aaaparameter
Configured AAA parameters
EnableStaticPageCaching: YES
EnableEnhancedAuthFeedback: NO
DefaultAuthType: LOCAL MaxAAAUsers: Unlimited
AAAD nat ip: None
EnableSessionStickiness : NO
aaaSessionLoglevel: INFORMATIONAL
AAAD Log Level: INFORMATIONAL
...
Persistent Login Attempts: DISABLED
Configure system user account lockout by using the GUI
-
Navigate to Configuration > Security > AAA-Application Traffic > Authentication Settings > Change authentication AAA Settings.
-
In the Configure AAA Parameter page, set the following parameters:
-
Max Login Attempts. The maximum number of logon attempts allowed for the user to try.
-
Failed Login Timeout. The maximum number of invalid logon attempts by the user.
-
Persistent Login Attempts. Persistent storage of unsuccessful user login attempts across reboots.
-
-
Click OK.

RBA Authentication Failure: maxlogin attempt reached for test. appears.
Lock system user account for management access
persistentLoginAttempts option in the aaa parameter.
set aaa parameter –persistentLoginAttempts DISABLED
lock aaa user test
Lock a system user account by using the GUI
-
Navigate to Configuration > Security > AAA-Application Traffic > Authentication Settings > Change authentication AAA Settings.
-
In Configure AAA Parameter, in the Persistent Login Attempts list, select DISABLED.
-
Navigate to System > User Administration > Users.
-
Select a user.
-
In the Select Action list, select Lock.

Unlock a locked system user account for management access
unlock aaa user test
Configure system user unlock by using the GUI
-
Navigate to System > User Administration > Users.
-
Select a user.
-
Click Unlock.

nsroot administrator must use the CLI.
Disable management access for system user account
set system parameter localAuth <ENABLED|DISABLED>
set system parameter localAuth DISABLED
Disable management access to system user by using the GUI
-
Navigate to Configuration > System > Settings > Change Global System Settings.
-
In Command Line Interface (CLI) section, unselect the Local Authentication checkbox.
Force passwords change for administrative users
nsroot secured authentication, NetScaler prompts the user to change the default password to a new one if the forcePasswordChange option is enabled in the system parameter. You can change your nsroot password either from CLI or GUI, on your first login with the default credentials.
set system parameter -forcePasswordChange ( ENABLED | DISABLED )
ssh nsroot@1.1.1.1
Connecting to 1.1.1.1:22...
Connection established.
To escape to local shell, press Ctrl+Alt+].
###############################################################################
WARNING: Access to this system is for authorized users only #
Disconnect IMMEDIATELY if you are not an authorized user! #
###############################################################################
Please change the default NSROOT password.
Enter new password:
Please re-enter your password:
Done
Remove sensitive files in a system user account
removeSensitiveFiles option. The commands that remove sensitive files when the system parameter is enabled are:
-
rm cluster instance
-
rm cluster node
-
rm high availability node
-
clear config full
-
join cluster
-
add cluster instance
set system parameter removeSensitiveFiles ( ENABLED | DISABLED )
set system parameter -removeSensitiveFiles ENABLED
Strong password configuration for system users
-
One lower case character
-
One upper case character
-
One numeric character
-
One special character
set system parameter -strongpassword <value> -minpasswordlen <value>
Strongpassword. After enabling strong password (enable all / enablelocal) all the passwords or sensitive information must have the following:
-
At least 1 lower case character
-
At least 1 upper case character
-
At least 1 numeric character
-
At least 1 special character
enablelocal is - NS_FIPS, NS_CRL, NS_RSAKEY, NS_PKCS12, NS_PKCS8, NS_LDAP, NS_TACACS, NS_TACACSACTION, NS_RADIUS, NS_RADIUSACTION, NS_ENCRYPTION_PARAMS. So no Strong Password checks are performed on these ObjectType commands for the system user.
enableall, enablelocal, disabled Default value: disabled
minpasswordlen. Minimum length of the system user password. When the strong password is enabled by default, the minimum length is 4. User entered value can be greater than or equal to 4. The default minimum value is 1 when the strong password is disabled. The maximum value is 127 in both cases.
set system parameter -strongpassword enablelocal -minpasswordlen 6
Enforce password rotation and password history for local accounts
-
Force users to change their passwords regularly
-
Remember previous passwords to prevent users from reusing old ones
-
Set how often passwords must be changed
Configuration and applicability
passwordhistorycontrol parameter in system settings is enabled. After you enable this feature, the following default values are applied to system parameters:
-
Daystoexpire: 30 (Number of days before the password expires)
-
Warnpriorndays: 5 (Number of days before password expiration when users are warned)
-
pwdhistoryCount: 6 (Number of passwords retained in the history)
-
DaystoexpireandWarnpriorndayscan be configured for system groups and can be set or unset whenPasswordhistorycontrolis enabled. -
Once
Passwordhistorycontrolis enabled,Daystoexpire,Warnpriorndays, andpwdhistoryCountvalues in the system parameters cannot be unset. -
These values cannot be set or unset in system groups or system parameters when the
passwordhistorycontroloption is disabled.
Important notes for applying changes
-
To apply changes after enabling
Passwordhistorycontrol, you must save the configuration. -
Once saved, the current user password history is recorded for each partition.
-
After users are required to change their passwords, the new passwords must also be saved to update the password history.
-
If the configuration is saved while
Passwordhistorycontrolis disabled, all previous user password history is erased.
Limitation
How to configure and use the password rotation and history feature
Configuration by using the CLI
set system parameter -passwordhistorycontrol ENABLED
passwordhistorycontrol is ENABLED, daystoexpire, warnpriorndays, and pwdhistorycount parameters are updated with their default values (30, 5, and 6 respectively).
set system parameter -daystoexpire <days> -warnpriorndays <days> -pwdhistorycount <count>
set system parameter -daystoexpire 60 -warnpriorndays 10 -pwdhistorycount 3
passwordhistorycontrol is ENABLED, daystoexpire, warnpriorndays, and pwdhistorycount values in the system parameters cannot be unset. These values cannot be set or unset when passwordhistorycontrol is DISABLED.
add system group <group_name> -daystoexpire <days> -warnpriorndays <days>
add system group sg -daystoexpire 45 -warnpriorndays 15
set system group <group_name> -daystoexpire <days> -warnpriorndays <days>
set system group sg -daystoexpire 30 -warnpriorndays 10
sh system user
-
If a user's password is about to expire, a warning message is displayed upon login.
-
Once a user's password has expired, they are forced to change their password during login.
-
If a password being set is a reuse of a previous password (within the history count), a password reuse error message is returned.
-
Upon a successful password change, the user can log in to the command prompt.
set system parameter -passwordhistorycontrol DISABLED
Configuration by using the GUI
-
Navigate to Configuration > System > Settings.
-
Click Change Global System Settings.
-
In the Other Settings section, enable Passwordhistorycontrol.
-
After enabling
Passwordhistorycontrol, configure the following parameters in the Other Settings section:-
Days to Expire
-
Warn Prior N Days
-
Password History Count
-
-
Click OK.
-
Save the configuration.
-
Navigate to Configuration > System > User Administration > Groups.
-
Click Add to create a new group, or Edit to modify an existing one.
-
Configure the Days to Expire and Warn Prior N Days for the group.
-
Click Create or OK.
-
Navigate to Configuration > System > User Administration > Users.
-
Scroll to the right to find details under Password Expiration Parameters Inherited From.
-
If a user's password has expired, they are forced to change the password from the GUI during login.
-
If the new password is a reuse of a previous one, the user is redirected to the same page with a password reuse error.
-
Once the new password is accepted, the GUI login is successful.
-
Navigate to Configuration > System > Settings.
-
Click Change Global System Settings.
-
In the Other Settings section, select DISABLED for Passwordhistorycontrol.
-
Click OK.
Default user account
nsrecover user account is used by the administrator to recover the NetScaler appliance. You can log on to NetScaler using nsrecover if the default system users (nsroot) are unable to log in due to any unforeseen issues. The nsrecover login is independent of user configurations and lets you access the shell prompt directly. You are always allowed to log in through the nsrecover irrespective of whether the maximum configuration limit is reached.