1 module o-ran-usermgmt {
3 namespace "urn:o-ran:user-mgmt:1.0";
4 prefix "o-ran-usermgmt";
6 import ietf-netconf-acm {
9 "RFC 8341: Network Configuration Access Control Model";
12 organization "O-RAN Alliance";
18 "This module defines the user management model for the O-RAN Equipment.
20 Copyright 2019 the O-RAN Alliance.
22 THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS 'AS IS'
23 AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
24 IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
25 ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE
26 LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
27 CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
28 SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
29 INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
30 CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
31 ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
32 POSSIBILITY OF SUCH DAMAGE.
34 Redistribution and use in source and binary forms, with or without
35 modification, are permitted provided that the following conditions are met:
37 * Redistributions of source code must retain the above copyright notice,
38 this list of conditions and the above disclaimer.
39 * Redistributions in binary form must reproduce the above copyright notice,
40 this list of conditions and the above disclaimer in the documentation
41 and/or other materials provided with the distribution.
42 * Neither the Members of the O-RAN Alliance nor the names of its
43 contributors may be used to endorse or promote products derived from
44 this software without specific prior written permission.";
46 revision "2019-07-03" {
50 1) change name leaf to type nacm:user-name-type
51 2) added account-type to qualify when password is required ";
53 reference "ORAN-WG4.M.0-v01.00";
56 revision "2019-02-04" {
60 1) imported model from xRAN
61 2) changed namespace and reference from xran to o-ran";
63 reference "ORAN-WG4.M.0-v01.00";
66 typedef password-type {
69 pattern "[a-zA-Z0-9!$%\\^()\\[\\]_\\-~{}.+]*" {
70 error-message "Password content does not meet the requirements";
74 "The password for this entry. This shouldn't be in clear text
75 The Password must contain at least 2 characters from
76 each of the following groups:
77 a) Lower case alphabetic (a-z)
78 b) Upper case alphabetic (A-Z)
80 d) Special characters Allowed !$%^()[]_-~{}.+
81 Password must not contain Username.";
88 "The list of local users configured on this device.";
90 type nacm:user-name-type;
92 "The user name string identifying this entry.
94 NOTE: o-ran-usermgmt:user-profile/user/name is
95 identical to nacm:nacm/groups/group/user-name
96 but the current schema is preserved for backwards
102 description "the user-name is for password based authentication";
105 description "the user-name is for certificate based authentciation";
112 nacm:default-deny-all;
115 "The password for this entry.
117 This field is only valid when account-type is NOT set to CERTIFICATE,
118 i.e., when account-type is NOT present or present and set to
124 "Indicates whether an account is enabled or disabled.";
130 must "user/enabled='true'" {
131 error-message "At least one account needs to be enabled.";
133 //TAKE NOTE - any configuration with zero enabled users is invalid.
134 //This will typically be the case when using a simulated NETCONF Server
135 //and so this constraint should be removed when operating in those scenarios
137 //The config data base of the O-RAN equipment should ensure that the user
138 //default account is enabled on factory restart
140 description "list of user accounts";
145 nacm:default-deny-all;
147 leaf currentPassword {
151 "provide the current password";
157 "provide a new password";
159 leaf newPasswordConfirm {
163 "re-enter the new password ";
178 "Successful or Failed";
180 leaf status-message {
183 "Gives a more detailed reason for success / failure";