chapuser

Manages account names and passwords that are used to locally authenticate host (iSCSI initiator) access to volumes.

CHAP (Challenge Handshake Authentication Protocol) can be used to restrict host (iSCSI initiator) access to volumes and snapshots (iSCSI targets). Local CHAP is generally used if you have only a few CHAP users. Performance may be adversely affected if you have more than 100 local CHAP users.

Notes: You can also use an external RADIUS server for initiator authentication, as described in grpparams radius-auth-list. This is recommended if you have more than 100 local CHAP users.

If you want to also enable target authentication in which the target is authenticated by the initiator, see grpparams target-auth-password and grpparams target-auth-username for more information.

Format

chapuser subcommand

Subcommands  

create

Creates a CHAP account.

delete

Deletes a CHAP account.

rename

Renames a CHAP account.

select

Enables, disables, or displays the selected CHAP account.

show

Displays all CHAP accounts or the details of a specific account.