Unsolved
This post is more than 5 years old
1 Rookie
•
115 Posts
0
2746
March 21st, 2013 15:00
user auth roles - access management
hi,
i added my account [ " sanadmin" storage member who needs to have full previlages ] to my new isilon and updated with required privileges group [ system admin & security admin ] but when i log in to Isilon GUI i didn't see the most tabs in cluster management or file system management like in built " admin " do. did i miss anything here.
nas-1% isi auth roles list
Name
-------------
SecurityAdmin
SystemAdmin
AuditAdmin
nas-1% isi auth roles view SystemAdmin
Name: SystemAdmin
Description: -
Members: admin
sanadmin
-
[ truncated ]
nas-1% isi auth roles view SecurityAdmin
Name: SecurityAdmin
Description: -
Members: admin
sanadmin
-
- [ truncated ]
thank you.


christopher_ime
6 Operator
•
2K Posts
0
March 21st, 2013 19:00
Raj,
You are correct. As one engineer put it, not all things in the GUI have been "RBACified". Therefore, even if you were to add yourself to each of the 3 pre-defined roles: SystemAdmin, SecurityAdmin, and AuditAdmin and/or if you created a separate role with all of the privileges: isi auth privileges, then associated that user or group to that role, you would not (at least currently) get the equivalent GUI access/visibility/permissions that the default local admin (or root of course) are afforded.
Raj_la
1 Rookie
•
115 Posts
0
March 22nd, 2013 09:00
So if i understand correct, there is no way that can any manual created user have access previlages like admin and root ?
and we just have to user inbuilt admin account for config related administration [ create dir , remove/add node ...etc ]
christopher_ime
6 Operator
•
2K Posts
0
March 22nd, 2013 17:00
You are correct. You will still need to use admin and root until all of the features have a privilege associated with it. Only then will you be able to use RBAC exclusively to manage the cluster. I will simply state though that engineering is already aware of the limitations.
Raj_la
1 Rookie
•
115 Posts
0
March 24th, 2013 18:00
Narahari1
2 Intern
•
127 Posts
0
August 12th, 2013 08:00
I'm also in the same boat to have RBACs configured for local users to manage the Array, but the "ISI_PRIV_XXXX" options are limited ( admin guide page 30) and I'm not finding a ways to grants privileges to handle "SyncIQ" and even the dashboard view. I have opened a case also to support and they are pinging Engineering team.
Does anyone know is there any issue in creating local user "nharik" which is same as "AD1\nharik" domain account ?
Rdamal
2 Intern
•
165 Posts
0
January 5th, 2014 18:00
Hi Narahari,
Just want to check with you on the RBAC privileges.
It was said that you opened the case. So any alternatives to the privileges for the local users ?
Thanks
Damal