Function
User authentication is involved authentication mode management and user management.
Authentication Mode Management
When a user attempts to log in to the system, the eSight automatically authenticates the user based on the user information. The eSight provides four authentication modes:
- Local authentication
When a user enters a user name and password for login, the eSight server verifies and authenticates the user login information.
- RADIUS authentication
When a user enters a user name and password for a login, a security process of the eSight server sends the user name and password to the RADIUS server for login information verification and authentication.
In RADIUS authentication mode, the RADIUS server manages users. The eSight does not manage users but only manages roles and assigns rights to roles.
- LDAP authentication
When a user enters a user name and password for a login, a security process of the eSight server sends the user name and password to the LDAP server for login information verification and authentication.
In LDAP authentication mode, the LDAP server manages users. The eSight does not manage users but only manages roles and assigns rights to roles.
- SSO authentication
When a user enters a user name and password for a login, the eSight server uses the SSO server to verify and authenticate the login information.
User management
User management includes managing user rights, querying online user information, setting personal information, and managing security policy. User management:
- Supports user authentication. The security administrator can assign different rights to different user roles based on the service plan, improving O&M efficiency and enhancing system security.
- Allows a user to query online user information and enters the single-user mode.
- Allows a user to set personal information such as changing a password and modifying contact information.
- Provides security policies such as account setting policies, password policies, IP address based access control policies, and login time policies.
- Account policy setting
Account policies are policies on the minimum user name length and related to user login. An appropriate account policy can enhance system access security.
- Password policy setting
Password policies define the password complexity, update period, and character constraints. An appropriate user password policy can prevent users from setting quite simple passwords or retaining passwords for a long term, enhancing system access security.
- Setting of IP address based access control policies
Set the IP address range from which the eSight can be logged in. A user bound to this IP address range can log in to the eSight only from IP addresses in this range.
- Login time policy setting
Set the time during which the eSight can be logged in. A user bound to this login time policy can log in to the eSight only in the time specified in the policy.
- Account policy setting