CHAPTER 6: SETTING UP THE D400
CREATING ADMINISTRATOR-LEVEL USER ACCOUNTS
D400 SUBSTATION GATEWAY USER’S MANUAL
GENERAL
87
NOTE
You may also have to modify your local network connection on your PC if you want to
plug directly into the D400’s front network port. The PC connecting to the front
Ethernet port of the D400 must be configured to be on the same network as Net1 (slot
11) and the host ID must be unique to the network.
Creating administrator-level user accounts
Since you cannot use the root user account to access the D400 remotely, you must create
administrator-level user accounts for this purpose. This must be done for the first time
through the D400’s front serial communications port.
To create a new
administrator-level
user account:
1.
Connect to the front maintenance port. See “Connecting to the D400 for the first time”
on page 83.
2.
At the
D400#>>
prompt, type
d400cfg
and press
Enter
.
3.
Type
1
and press
Enter
to select
1. Configure Authentication
.
4.
Type
6
and press
Enter
to select
6. Administrator Group Users
.
5.
Complete the on screen prompts as required to create a new administrator-level user.
You may now use this user account to access the D400 remotely through TELNET or
SSH.
NOTE
By default, the D400 is configured to restrict access to various command line services like
TELNET and SSH to administrator-level users only. You can use the
Configure
Administrator Only Logins
setting under
Secure Access
to change this parameter and
allow both administrator- and supervisor-level access.
Setting up secure web access
The D400 provides security features to authenticate its identity and to maintain the privacy
of information between the D400 and your computer when communicating over the
Internet. The D400 makes use of digital signatures and secure Web access to ensure this
security.
Secure Web access to the D400 is provided using the Secure Sockets Layer (SSL) protocol
over a 128-bit connection. To support the D400's secure Web access features, you need to
obtain and install a security certificate and a private key on the D400.
Prerequisites
You will need the following items to set up secure Web access for the D400:
•
Approved IP address, host name and fully qualified domain name for the D400
•
Security certificate and private key
Requesting a certificate
Security certificates are issued by independent certification authorities (CAs). Your Web
browser must host the certificate for the CA you choose to use. Refer to your browser's
configuration to find out which certification authorities are supported. Optionally, you can
install a CA's certificate if it doesn't exist in your browser.