I am not 100% sure my assumptions are correct, but this is what I have expirienced 🙂 So please correct me if wrong!
@SmartConsole R80.10 with multiple login options (clients supportet see sk111583):
user base can be configured in the login option (automatic might be same as for older versions, but have not testet yet)
@SmartConsole R77 or legacy clients with R80.10:
1. local users are always taken first -> they get authenticated according to the setting in the user propiertes for authentication
2. LDAP is searched as second stage -> authentication happens based on setting in account unit
3. external user profiles -> authentication and userbase are taken from the authentication configured in the external user profile
@Gaia:
Order is as follows:
- users with pw are authenticated locally
- users wihout pw (* as password-hash) are authenticated according to aaa but settings like shell are taken from local config
- non-existing users are also authenticated according to aaa