Unsolved

This post is more than 5 years old

1 Rookie

 • 

115 Posts

2746

March 21st, 2013 15:00

user auth roles - access management

hi,

i added my account [ " sanadmin"  storage member who needs to have full previlages ] to my new isilon and updated with required privileges group [ system admin & security admin ] but when i log in to Isilon GUI i didn't see the most tabs in cluster management or file system management like in built " admin " do.  did i miss anything here.

nas-1% isi auth roles list

Name

-------------

SecurityAdmin

SystemAdmin

AuditAdmin

nas-1% isi auth roles view SystemAdmin

       Name: SystemAdmin

Description: -

    Members: admin

                   sanadmin

-

[ truncated ]

nas-1% isi auth roles view SecurityAdmin

       Name: SecurityAdmin

Description: -

    Members: admin

                   sanadmin

-

- [ truncated ]

thank you.

1 Attachment

6 Operator

 • 

2K Posts

March 21st, 2013 19:00

Raj,

You are correct.  As one engineer put it, not all things in the GUI have been "RBACified".  Therefore, even if you were to add yourself to each of the 3 pre-defined roles: SystemAdmin, SecurityAdmin, and AuditAdmin and/or if you created a separate role with all of the privileges: isi auth privileges, then associated that user or group to that role, you would not (at least currently) get the equivalent GUI access/visibility/permissions that the default local admin (or root of course) are afforded.

1 Rookie

 • 

115 Posts

March 22nd, 2013 09:00

So if i understand correct, there is no way that can any manual created user have access previlages like admin and root  ?

and we just have to user inbuilt admin account for config related administration [ create dir , remove/add node ...etc ]

6 Operator

 • 

2K Posts

March 22nd, 2013 17:00

You are correct.  You will still need to use admin and root until all of the features have a privilege associated with it.  Only then will you be able to use RBAC exclusively to manage the cluster.  I will simply state though that engineering is already aware of the limitations.

1 Rookie

 • 

115 Posts

March 24th, 2013 18:00

hmmm..thanks for the info

2 Intern

 • 

127 Posts

August 12th, 2013 08:00

I'm also in the same boat to have RBACs configured for local users to manage the Array, but the "ISI_PRIV_XXXX" options are limited ( admin guide page 30) and I'm not finding a ways to grants privileges to handle "SyncIQ" and even the dashboard view. I have opened a case also to support and they are pinging  Engineering team.

Does anyone know is there any issue in creating local user "nharik" which is same as "AD1\nharik" domain account ?

2 Intern

 • 

165 Posts

January 5th, 2014 18:00

Hi Narahari,

Just want to check with you on the RBAC privileges.

It was said that you opened the case. So any alternatives to the privileges for the local users ?

Thanks

Damal

No Events found!

Top