Start a Conversation

Unsolved

This post is more than 5 years old

2410

August 17th, 2010 05:00

Navisphere CLI user roles

Hi,

some questions raise up regarding Navisphere's user roles. As I understand there are 3 roles, Administrator, Manager and Monitor.

Having a look in the CLI Reference Guide it only tells that, i.e. Monitor can not add, change or delete anything.

Is there a description what actions a certain user role can perform exactly? E.g. break and restore MirrorView sessions?

Thanks and regards,

Dieter

116 Posts

August 17th, 2010 06:00

See if this helps ..

Additionally, each role can be assigned global or local privileges.  Each global username must be unique within the storage domain; each local username must be unique within the storage system. Role privileges are as follows:

Anyone Logged in as

Can View

Can Add, Modify, or Delete

Global Administrator

Note that local accounts on a storage system can be viewed only when one is logged into that storage system.

All storage-system settings and global and local accounts (but cannot delete the last global administrator account)

Local Administrator

Local storage system settings and local user accounts

Currently, the following global and local security administrator roles are supported only on CX and CX3 series  storage systems running FLARE version 02.26.xxx.yyy.zzz or higher.

Global Security Administrator

All security features. Cannot see or manage storage-system features

Local Security Administrator

Local security features. Cannot see or manage local storage-system features

Global Manager

All storage system information

Local Manager

Local storage system information

Global Monitor

Nothing

Local Monitor

Nothing

116 Posts

August 18th, 2010 05:00

Here is the Roles for Release 29 ... A Monitor User can only view .. See below where "Can Add Modify and Delete" Follow that coluim down to Local Monitor and you will see they have nothing ...

About user accounts 

Note  If you have a CX4 seriesCX3-series , CX-series storage system , or an AX4-5 series storage system with FLARE version 02.23.050.5.5xx, and you will be using Navisphere CLI to configure the storage system, see the Using Navisphere CLI to add privileged users entry in the Table of Contents.                                

The privilege of monitoring, managing, and creating accounts on systems in a domain depends on the type of account used when you log in. A user (that is, someone who needs to view or manage storage system operation) can have one of the following roles:

Administrator
Security Administrator
Manager Manager

Monitor Monitor

Additionally, you can increase security and limit access privileges for third-party service personnel who perform replication operations, by granting the following replication roles:

Local Replication Only
Replication

Replication and Recovery

Those with these replication roles can view, but not manage non-replication features, such as creating a LUN.

The Administrator, Security Administrator, Manager, and Monitor roles can each be assigned global or local privileges.  Each global username must be unique within the storage domain; each local username must be unique within the storage system. Role privileges are as follows:

Anyone Logged in as

Can View

Can Add, Modify, or Delete

Global Administrator

Note that local accounts on a storage system can be viewed only when one is logged into that storage system.

All storage-system settings and global and local accounts (but cannot delete the last global administrator account)

Local Administrator

Local storage system settings and local user accounts

Currently, the following global and local security administrator roles are supported only on CX and CX3 series  storage systems running FLARE version 02.26.xxx.yyy.zzz or higher.

Global Security Administrator

All security features. Cannot see or manage storage-system features

Local Security Administrator

Local security features. Cannot see or manage local storage-system features

Global Manager

All storage system information

Local Manager

Local storage system information

Global Monitor

Nothing

Local Monitor

Nothing

Note  Anyone logged in with a global administrator account can view all user accounts, both global to the domain and local to the current storage system.  Anyone logged in as a local administrator can view and manage only user accounts on the local storage system.

Usernames and Passwords

Usernames can be 1 to 32 letters (case sensitive), numbers, and/or underscores, and must start with a letter.

Passwords can be 1 to 32 letters (case sensitive) and/or numbers.

Manager stores all local username, password, and related security data encrypted, in files in a secure part of the storage system. Global user information is stored encrypted on all management-server storage systems in the domain.

Important  If the person who manages a storage-system installation cannot log in as a global administrator (perhaps because he or she forgot the password), then global management of the installation will be impossible. Any local administrators and managers retain their local management privileges. However, eventually, an EMC engineer will need to recreate a global administrative account. So you should make sure that people who will manage the system keep a good record of this password

Initial Global Administrator Account

When the storage-system hardware is installed, initialize security on the storage system by creating the initial global administrator account, complete with username and password .  Once a global administrator account exists,  the security software automatically creates a domain of one with SP A as the domain master. No one can delete the last remaining global administrator account.

After storage-system initialization, anyone with global administrative privileges can log in to any connected management server storage system, and then add management servers or create, modify, or delete other global or local administrator, manager, and monitor accounts.

Any user can modify his or her own password and view the systems on which he or she has an account.

59 Posts

August 18th, 2010 05:00

Hi,

that's what I found in the documents.

My questions goes more in the direction which actions are exactly possible, e.g. is a mirror split possible for a monitor user?

59 Posts

August 18th, 2010 06:00

Thank you, this helps! I'll have a closer look at the FLARE 29 documentation.

Best regards

Dieter

No Events found!

Top