Defining roles-based access control (rbac) – HP Insight Management-Software User Manual
Page 43
6.
Select the MAC address range type from the following options:
•
VCEM-defined
•
User-defined
•
Factory-default
NOTE:
You cannot change any of the range types after creating the VC Domain Group.
You can only select the User-Defined option for the MAC range type if a MAC custom range
is defined.
7.
Select the WWN address range type from the following options:
•
VCEM-defined
•
User-defined
•
Factory-default
You can only select the User-Defined option for the WWN range type if a WWN custom
range is defined.
8.
Select the Serial Number address range type from the following options:
•
Logical serial number
•
Factory-default
9.
Click OK. The message Virtual Connect Enterprise Manager is executing
the request
appears.
10. Click OK to go to the Jobs page and monitor job progress.
11. (Optional) After creating a VC Domain Group from the Systems Insight Manager User and
Authorization page, configure the user authorization privileges for that VC Domain Group.
“Defining Roles-Based Access Control (RBAC)” (page 43)
defines role-based authorization
privileges.
Defining Roles-Based Access Control (RBAC)
VCEM allows you to define role-based access control to VCEM resources. VCEM will restrict
operations based on the Systems Insight Manager user and their defined role within specific VC
Domain Groups.
NOTE:
•
Create the VC Domain Groups, then define VCEM access to authorized users.
•
By default the OS administrator user account has VCEM administrator rights to all VCEM VC
Domain Groups.
•
A user account can be associated with different VC Domain Groups and have different
privileges for each of the groups. Likewise, a VC Domain Group can have different users
associated with it who have different privilege levels. For example, user JohnSmith can have
“VCEM Domain Group Administrator” privileges for the “HP-UX” VC Domain Group but be
limited to “VCEM Group Limited Operator” privileges in the “Linux-Servers” VC Domain Group.
It is also possible to assign other users with different privileges to conduct operations on the
“HP-UX” VC Domain Group. This way user RachelGreen could be assigned “VCEM Domain
Group Operator” privileges and user AdamWood could be assigned “VCEM Group Limited
Operator” privileges allowing them to perform only subsets of management operations on the
“HP-UX” VC Domain Group.
Defining Roles-Based Access Control (RBAC)
43