PowerMax: Ensure symauth user, and group role mappings are defined before enabling
Summary: Authentication issues will occur if symauth is enabled and daemons are restarted, before user and group role mappings are defined.
Symptoms
Authorization events are observed in the storevntd log after symauth has been enabled and SE* daemons that are restarted, before user and group role mappings have been defined:
storevntd log:
<Error> [20690 Listener] Aug-12 12:23:45.166 : [evtd_sympRegProducer] The Event Logger (running as user H:MGMT-0\storevntd) is not authorized to read the Symmetrix Audit Log (SID 000123456789).
<Error> [20690 Listener] Aug-12 12:23:45.166 : [evtd_sympRegProducer] Use the 'symauth' command to assign user H:MGMT-0\storevntd a role of AUDITOR or greater for SID 000123456789
<Error> [20690 Listener] Aug-12 12:23:45.166 : [evtd_logSetupRegs] Failure from event registration (evtRegister) -- Not authorized to register for this event type
Cause
symauth was enabled and SE daemons restarted, before user and group role mappings were defined.
Resolution
Page 45 of the Dell EMC Solutions Enabler Array Controls and Management CLI User Guide, user, and group role mappings should be defined before enabling authorization.
Additional Information
See page 45 of the Dell EMC Solutions Enabler Array Controls and Management CLI User Guide.
User authorization
User and group role mappings should be defined before enabling authorization. At a minimum, there must be one mapping for an individual to the Admin or Security Admin, as user authorization can only be enabled if there is an individual (as shown by symauth show -username command) mapped to a role of either Admin or SecurityAdmin roles. These roles allow authorization to control operations. Up to four roles can be assigned to a user group.
User and group authorization is disabled by default.
Any user can change the authorization control data, including creating and removing user and group role mappings.
Once authorization is enabled for an array, only users or groups with the Admin and SecurityAdmin role can change authorization control data.