NetWorker:ローカルREST API専用ユーザーを作成する方法

Summary: 次の手順に従って、REST API用のNetWorkerユーザー アカウントを作成できますが、NMCにはアクセスできません。REST APIユーザーは、ユーザーに割り当てられたNetWorkerロールに応じて、NetWorker Webユーザー インターフェイス(NWUI)にアクセスできます。NWUIアクセスは「NSRユーザー グループ」に依存します。これらは、REST API権限を定義するために使用されるのと同じロールです。REST APIユーザーの作成はオプションであり、NetWorkerサーバーでREST API操作を実行するためには必要ありません。 ...

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Instructions

  1. NetWorkerサーバーで、rootシェル(Linux)または管理者コマンド プロンプト(Windows)を開きます。
  2. 次のコマンド構文を使用して、REST APIユーザー アカウントを作成します。
authc_mgmt -u Administrator -p 'NETWORKER_ADMINISTRATOR_PASSWORD' -e add-user -D user-name="RESTAPI_USERNAME" -D user-password='USER_PASSWORD' -D user-enabled
Example:
[root@nsr ~]# authc_mgmt -u Administrator -p '!Password1' -e add-user -D user-name="RESTAPI" -D user-password='!Password1' -D user-enabled
User RESTAPI is created successfully.
[root@nsr ~]#
  1. REST APIユーザーの「ユーザーDN」を取得します。
authc_mgmt -u Administrator -p 'NETWORKER_ADMINISTRATOR_PASSWORD' -e find-all-users
authc_mgmt -u Administrator -p 'NETWORKER_ADMINISTRATOR_PASSWORD' -e find-user -D user-id=USER-ID
Example:
[root@nsr ~]# authc_mgmt -u Administrator -p '!Password1' -e find-all-users
The query returns 7 records.
User Id User Name
1000    administrator
1001    svc_nmc_nsr
...
1038    RESTAPI

[root@nsr ~]# authc_mgmt -u Administrator -p '!Password1' -e find-user -D user-id=1038
User Id        : 1038
User Name      : RESTAPI
User Domain    :
User First Name:
User Last Name :
User Email     :
User Details   :
User DN        : cn=RESTAPI,cn=Users,dc=nsr,dc=amer,dc=lan
User Enabled   : true
User Groups    : []
  1. NetWorkerサーバーに対するユーザー権限を付与します。
NetWorker管理者権限の場合は、次のコマンドを実行します。
nsraddadmin -e cn=RESTAPI_USERNAME,cn=users,cn=NSR_SERVERNAME,dc=DOMAIN_VALUE1,dc=DOMAIN_VALUE2
Example:
[root@nsr ~]# nsraddadmin -e cn=RESTAPI,cn=users,cn=nsr,dc=amer,dc=lan
134751:nsraddadmin: Added role 'cn=RESTAPI,cn=users,cn=nsr,dc=amer,dc=lan' to the 'Security Administrators' user group.
134751:nsraddadmin: Added role 'cn=RESTAPI,cn=users,cn=nsr,dc=amer,dc=lan' to the 'Application Administrators' user group.
メモ: ユーザーに管理者権限を持たせたくない場合は、NSRロールのいずれかのusersフィールドにユーザーを追加できます。これは、NMC (NetWorker Management Console)、NWUI (NetWorker Web User Interface)、または nsradmin コマンド プロンプト:

構文:user=USERNAME,host=NSR_SERVERNAME

NetWorkerサーバー上のOperatorsユーザー グループにREST APIユーザーを追加する例:

[root@nsr ~]# nsradmin
NetWorker administration program.
Use the "help" command for help, "visual" for full-screen mode.
nsradmin> show name;comment
nsradmin> p type: nsr usergroup
                        name: Users;
                     comment: \
Members of this group can back up to and recover from NetWorker.;

                        name: Database Administrators;
                     comment: \
Members of this group are typically database administrators that can partially administer NetWorker.;

                        name: Database Operators;
                     comment: \
Members of this group are typically database operators that can operate NetWorker.;

                        name: Auditors;
                     comment: \
Members of this group can audit the NetWorker security logs.;

                        name: Operators;
                     comment: Members of this group can operate NetWorker.;

                        name: Application Administrators;
                     comment: \
Members of this group can perform the application administration of NetWorker.;

                        name: Security Administrators;
                     comment: \
Members of this group can administer the security settings of NetWorker.;

                        name: Monitors;
                     comment: \
Members of this group can monitor the NetWorker application.;

                        name: Archive Users;
                     comment: Members of this group can archive local data;

                        name: VMware FLR Users;
                     comment: \
Members of this group can perform VMware file level recovery operations from NetWorker.;

nsradmin> show
Will show all attributes

nsradmin> . type: nsr usergroup; name: operators
Current query set
nsradmin> update users: user=RESTAPI,host=nsr.amer.lan
                       users: user=RESTAPI,host=nsr.amer.lan;
Update? y
updated resource id 125.0.90.20.0.0.0.0.196.80.99.102.192.168.9.150(4)
nsradmin> show
Will show all attributes
nsradmin> print
                        type: NSR usergroup;
                        name: Operators;
                     comment: Members of this group can operate NetWorker.;
              external roles: ;
                       users: user=RESTAPI,host=nsr.amer.lan;
                  privileges: Remote Access All Clients,
                              View Application Settings, Operate NetWorker,
                              Monitor NetWorker,
                              Operate Devices and Jukeboxes,
                              Recover Local Data, Recover Remote Data,
                              Backup Local Data, Backup Remote Data,
                              Archive Data;
nsradmin> q
[root@nsr ~]#
  1. NetWorker認証の信頼関係がローカルauthcインスタンスで確立されていることを確認します。
nsrauthtrust -H NSR_SERVERNAME -P 9090
nsraddadmin -H NSR_SERVERNAME -P 9090
  1. REST APIは、次を使用してテストできます。 
curl -ik GET -u RESTAPI_USERNAME:'USERPASSWORD' -H "Content-Type: application/json" https://NSR_SERVERNAME:9090/nwrestapi/v3/global/
Example:
[root@nsr ~]# curl -ik GET  -u RESTAPI:'!Password1' -H "Content-Type: application/json" https://nsr.amer.lan:9090/nwrestapi/v3/global/
curl: (6) Could not resolve host: GET
HTTP/1.1 200
Content-Security-Policy: frame-ancestors 'none';script-src' 'self';object-src 'self'
Strict-Transport-Security: max-age=31536000
X-XSS-Protection: 1; mode=block
X-Frame-Options: DENY
X-Content-Type-Options: nosniff
Date: Thu, 11 Jul 2024 18:22:58 GMT
Cache-Control: no-cache,no-store,must-revalidate
Pragma: no-cache
Expires: 0
Content-Type: application/json
Transfer-Encoding: chunked
Server: NSR SERVICES for Authentication

{"links":[{"href":"https://nsr.amer.lan:9090/nwrestapi/v3/global/alerts","title":"List of alert messages"},{"href":"https://nsr.amer.lan:9090/nwrestapi/v3/global/auditlogconfig","title":"Audit log configuration"},{"href":"https://nsr.amer.lan:9090/nwrestapi/v3/global/auditlogconfigs","title":"Audit log configurations"},{"href":"https://nsr.amer.lan:9090/nwrestapi/v3/global/backups","title":"List of backups"},{"href":"https://nsr.amer.lan:9090/nwrestapi/v3/global/clients","title":"List of clients"},{"href":"https://nsr.amer.lan:9090/nwrestapi/v3/global/cloudboostappliances","title":"List of cloudboost appliances"},{"href":"https://nsr.amer.lan:9090/nwrestapi/v3/global/datadomainsystems","title":"List of data domain systems"},{"href":"https://nsr.amer.lan:9090/nwrestapi/v3/global/dddevicereplication","title":"DD device replication"},{"href":"https://nsr.amer.lan:9090/nwrestapi/v3/global/devices","title":"List of storage devices"},{"href":"https://nsr.amer.lan:9090/nwrestapi/v3/global/directives","title":"List of backup directives"},{"href":"https://nsr.amer.lan:9090/nwrestapi/v3/global/inspect","title":"Inspect remote/local server"},{"href":"https://nsr.amer.lan:9090/nwrestapi/v3/global/jobgroups","title":"List of job groups"},{"href":"https://nsr.amer.lan:9090/nwrestapi/v3/global/jobindications","title":"List of job indications"},{"href":"https://nsr.amer.lan:9090/nwrestapi/v3/global/jobs","title":"List of jobs"},{"href":"https://nsr.amer.lan:9090/nwrestapi/v3/global/jukeboxes","title":"List of jukeboxes"},{"href":"https://nsr.amer.lan:9090/nwrestapi/v3/global/labels","title":"List of volume label templates"},{"href":"https://nsr.amer.lan:9090/nwrestapi/v3/global/licenseconfig","title":"Server license configuration"},{"href":"https://nsr.amer.lan:9090/nwrestapi/v3/global/licenses","title":"List of license templates"},{"href":"https://nsr.amer.lan:9090/nwrestapi/v3/global/lockbox","title":"Lockbox resource"},{"href":"https://nsr.amer.lan:9090/nwrestapi/v3/global/mediaconfig","title":"Server media configuration"},{"href":"https://nsr.amer.lan:9090/nwrestapi/v3/global/mobilestorageunits","title":"Mobile storage units"},{"href":"https://nsr.amer.lan:9090/nwrestapi/v3/global/nasdevices","title":"List of NAS devices"},{"href":"https://nsr.amer.lan:9090/nwrestapi/v3/global/notifications","title":"List of notification settings"},{"href":"https://nsr.amer.lan:9090/nwrestapi/v3/global/nsrcloneconfig","title":"NSR Clone Configuration"},{"href":"https://nsr.amer.lan:9090/nwrestapi/v3/global/pools","title":"List of pools"},{"href":"https://nsr.amer.lan:9090/nwrestapi/v3/global/probes","title":"List of probes"},{"href":"https://nsr.amer.lan:9090/nwrestapi/v3/global/protectiongroups","title":"List of protection groups"},{"href":"https://nsr.amer.lan:9090/nwrestapi/v3/global/protectionpolicies","title":"List of protection policies"},{"href":"https://nsr.amer.lan:9090/nwrestapi/v3/global/recoverapps","title":"List of recovery applications"},{"href":"https://nsr.amer.lan:9090/nwrestapi/v3/global/recovers","title":"List of recover resources"},{"href":"https://nsr.amer.lan:9090/nwrestapi/v3/global/rules","title":"List of rules"},{"href":"https://nsr.amer.lan:9090/nwrestapi/v3/global/schedules","title":"List of schedules"},{"href":"https://nsr.amer.lan:9090/nwrestapi/v3/global/securityconfig","title":"Server security configuration"},{"href":"https://nsr.amer.lan:9090/nwrestapi/v3/global/serverconfig","title":"Server configuration"},{"href":"https://nsr.amer.lan:9090/nwrestapi/v3/global/servermessages","title":"List of server messages"},{"href":"https://nsr.amer.lan:9090/nwrestapi/v3/global/serverstatistics","title":"Server statistics"},{"href":"https://nsr.amer.lan:9090/nwrestapi/v3/global/sessions","title":"List of save/recover sessions"},{"href":"https://nsr.amer.lan:9090/nwrestapi/v3/global/storagenodes","title":"List of storage nodes"},{"href":"https://nsr.amer.lan:9090/nwrestapi/v3/global/tenants","title":"Restricted data zone protection"},{"href":"https://nsr.amer.lan:9090/nwrestapi/v3/global/timepolicies","title":"List of Time Policies"},{"href":"https://nsr.amer.lan:9090/nwrestapi/v3/global/unconfiguredlibraries","title":"List of unconfigured libraries"},{"href":"https://nsr.amer.lan:9090/nwrestapi/v3/global/usergroups","title":"List of user groups"},{"href":"https://nsr.amer.lan:9090/nwrestapi/v3/global/vmware","title":"View of VMware objects"},{"href":"https://nsr.amer.lan:9090/nwrestapi/v3/global/volumes","title":"List of volumes"}]}[root@nsr ~]#
メモ: 一部のWindowsシステムでは curl インストールされており、コマンドはWindowsコマンドプロンプトから実行することもできます。REST URLは、Webブラウザー内で指定することもできます。

REST APIユーザー パスワードを90日ごとに期限切れにしたくない場合(デフォルト)、次の手順に従います。NetWorker:NetWorkerアカウントのパスワードの有効期限を無効にする方法。

複数のNetWorkerサーバーが存在する場合は、各サーバーでこのプロセスを繰り返して、ローカルREST APIユーザーの整合性がデータゾーン全体で維持されるようにします。ユーザーが作成された単一のNetWorker認証サーバーを使用している場合は、適切な認証のためにREST API機能に追加のヘッダーを追加します。これにより、REST API機能に対して、ヘッダーで定義されているNetWorker認証サーバーを使用して認証を行うよう指示します。詳細については、NetWorker REST API: RESTAPIリクエストを処理するときにリモートAUTHCサーバーを使用するにはどうすればよいですか?

Affected Products

NetWorker

Products

NetWorker
Article Properties
Article Number: 000020534
Article Type: How To
Last Modified: 12 Jun 2025
Version:  8
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.