Creating an Equal-Secret Account Group
Scenarios
During routine host management, you need to manage different accounts on the same host. For example, you can use the root account to perform operations through SSH and SFTP ports. However, even if the same account (for example, root) on the same host is used on different ports, the bastion host system considers the account as different resource accounts (for example, root@ssh and root@sftp). In this case, when a user changes the password of one account, the system cannot automatically identify and change the passwords of other related accounts. This causes inconvenience and security risks in account management. How to ensure the consistency and security of account passwords is important. To address this issue, we enable equal-secret account groups in the bastion host system. You can set the same accounts of different ports on the same host as an equal-secret account group to synchronize password changes. This function can simplify account management and improve system security and management efficiency.
Notes and Constraints
- Only host resource accounts whose protocol is SSH, SFTP, or SCP and login mode is automatic login or privilege escalation can be added to an equal-secret account group.
- The password change triggered by an equal-secret account group only changes the password saved in the bastion host. To change the actual password of the host, use a password change policy.
- If multiple accounts in the same equal-secret account group are in the same password change policy, the account with the SSH key is preferentially selected for password change. If the account has an SSH key, the SSH key is used for login. If the account does not have an SSH key, the password of the equal-secret account group is used for login.
- After an account is selected, other accounts in the same equal-secret account group will not be changed in the same password change policy. The password change result of the account is used as the password change result of the entire equal-secret account group in the same password change policy.
- Only instances of V3.3.66.0 or later support the equal-secret account group function.
Prerequisites
- You have the operation permissions for the Equal Secret Account Group module.
- Resource accounts that support equal-secret account groups already exist in the system.
Automatic Grouping (Only Admin Can Perform This Operation)
The system administrator admin can automatically group all resource accounts that meet the conditions in the bastion host system based on certain rules.
Grouping rules
- SSH, SCP, and SFTP accounts with the same host IP address, port number, and account name are grouped into the same group.
- Accounts that are already in an equal-secret account group will not be automatically grouped.
- If there are no same accounts, the accounts will not be automatically grouped.
- The name of an auto-grouped equal-secret account group is in the format of Account-IP.
- Application accounts cannot be added to any equal-secret account group.
- Privilege escalation accounts cannot be grouped.
Procedure
- Log in to your bastion host system.
- In the navigation pane on the left, choose . The equal-secret account group list page is displayed.
- Click Auto Group in the upper right corner of the list.
- Read the automatic grouping information in the dialog box carefully and click Start Group.
You can click
in the upper right corner to access the task center and view the automatic grouping result.
- During automatic grouping, you can manually group the resource accounts that are not automatically grouped. After manual grouping, the resource accounts will not be grouped during automatic grouping.
- After automatic grouping is complete, the new resource accounts will not be automatically grouped. You can manually group the resource accounts or perform automatic grouping again.
Manual Grouping
Method 1: Manually Creating an Equal-Secret Account Group
You can create only one equal-secret account group manually. Then, you need to group resource accounts as required. For details, see Adding Accounts to an Equal-Secret Account Group and Removing Accounts from an Equal-Secret Account Group.
- Log in to your bastion host system.
- In the navigation pane on the left, choose . The equal-secret account group list page is displayed.
- Click New.
- Enter the name and description of the equal-secret account group, and click OK.
You can view the created equal-secret account group in the equal-secret account group list.
Method 2: Batch Importing Equal-Secret Account Groups
You can group multiple resource accounts and import the accounts all at once to create multiple equal-secret account groups.
- Log in to your bastion host system.
- In the navigation pane on the left, choose . The equal-secret account group list page is displayed.
- Click
in the upper right corner of the list. - In the dialog box displayed, click Download template and download the template to your local PC.
- After filling in the template, upload the template.
- Click OK.
After the import is complete, you can view the imported equal-secret account groups in the equal-secret account group list.
Adding Accounts to an Equal-Secret Account Group
Notes and Constraints
- The password of the first account added to an equal-secret account group is used as the password of the equal-secret account group. The password of the equal-secret account group is used for all accounts added to the group. The first account added to an equal-secret account group cannot be an account with an empty password.
- Only host accounts can be added. The protocol must be SSH, SFTP, or SCP, and the login mode must be automatic login or privilege escalation login.
- When you add multiple accounts to an empty equal-secret account group for the first time, the system checks whether the names, IP addresses, ports, and passwords of the accounts for automatic login are the same. If the passwords are different, the accounts fail to be added and a message is displayed indicating that the addition fails.
- When you add multiple accounts to an empty equal-secret account group for the first time, the system checks whether the IP addresses, ports, and passwords of the privilege escalation accounts are the same. If the passwords are different, the accounts fail to be added and a message is displayed indicating that the addition fails.
- When you add multiple accounts to an empty equal-secret account group for the first time, the system verifies the automatic login accounts and privilege escalation accounts separately, and then checks whether the IP addresses, ports, and passwords of the two types of accounts are the same. If the passwords are different, the accounts fail to be added and a message is displayed indicating that the addition fails.
- When you add an account to an equal-secret account group that already has accounts added, the system checks whether the IP address and port of the new account are the same as those of the accounts already in the group. If the IP address and port are different, the account fails to be added and a message is displayed indicating that the addition fails.
- If different accounts are added to a non-empty equal-secret account group, the passwords of accounts that do not belong to the equal-secret account group may be lost. In this case, contact technical support to retrieve the passwords.
Procedure
- Log in to your bastion host system.
- In the navigation pane on the left, choose . The equal-secret account group list page is displayed.
- In the Operation column of the target equal-secret account group, click Add Account.
- In the Add Account dialog box, select the resource accounts you want to add to the equal-secret account group and click OK.
Removing Accounts from an Equal-Secret Account Group
If you remove an account from an equal-secret account group before changing the group password, the password of the account after the removal is the same as that before the account is added to the group. If an account is removed from an equal-secret account group after the group password is changed, the new group password will be used as the password of the account.
- Log in to your bastion host system.
- In the navigation pane on the left, choose . The equal-secret account group list page is displayed.
- In the Operation column of the target equal-secret account group, click Remove Account.
- In the Remove Account dialog box, select the resource accounts you want to remove from the equal-secret account group and click OK.
Follow-up Operations
For accounts in an equal-secret account group, if you manually change the password of an account, import the updated account password, or change the account password using a password change policy in the resource account module, the password of the equal-secret account group will be changed accordingly. For more details, see Managing Resource Accounts and Password Rules.
What is your overall rating for this page?
Thank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot