Dell Version 7.3 manual Setup And Administration, Role-Based Access Control, User Privileges

Page 12

2

Setup And Administration

Dell OpenManage Server Administrator provides security through role- based access control (RBAC), authentication, and encryption for both the Web-based and command line interfaces.

Role-Based Access Control

RBAC manages security by determining the operations that can be executed by persons in particular roles. Each user is assigned one or more roles, and each role is assigned one or more privileges that are permitted to users in that role. With RBAC, security administration corresponds closely to an organization's structure.

User Privileges

Server Administrator grants different access rights based on the user's assigned group privileges. The four user privilege levels are: User, Power User, Administrator, and Elevated Administrator.

Table 2. User Privileges

User Privilege

 

Access

Description

Level

 

Type

 

 

 

 

 

 

View

Manage

 

User

Yes

No

Users can view most information.

Power User

Yes

Yes

Power Users can set warning threshold values and configure

 

 

 

which alert actions are to be performed when a warning or failure

 

 

 

event occurs.

Administrator

Yes

Yes

Administrators can configure and perform shutdown actions,

 

 

 

configure Auto Recovery actions in case a system has a non-

 

 

 

responsive operating system, and clear hardware, event, and

 

 

 

command logs. Administrators can also configure the system to

 

 

 

send e-mails.

Elevated

Yes

Yes

Elevated Administrators can view and manage information.

Administrator

 

 

 

(Linux only)

 

 

 

Privilege Levels to Access Server Administrator Services

The following table summarizes the users who have privileges to access and manage Server Administrator services.

Server Administrator grants read-only access to users logged in with User privileges, read and write access to users logged in with Power User privileges, and read, write, and administrator access to users logged in with Administrator

and Elevated Administrator privileges.

Table 3. Privileges Required To Manage Server Administrator Services

Service

User Privilege Level Required

 

 

View

Manage

12

Image 12
Contents Dell OpenManage Server Administrator Version 7.3 Users Guide Dell Inc Contents Server Administrator Services Working With Remote Access ControllerServer Administrator Logs Setting Alert ActionsTroubleshooting Frequently Asked QuestionsInstallation Updating Individual System Components IntroductionStorage Management Service Instrumentation ServiceRemote Access Controller What Is New In This ReleaseSystems Management Standards Availability Availability On Supported Operating Systems Server Administrator Home Other Documents You May Need Operating System Accessing Documents From Dell Support Site Serviceability Tools Obtaining Technical Assistance Contacting DellOMConnectionsEnterpriseSystemsManagement Setup And Administration Role-Based Access ControlUser Privilege Access Description Level Type View Manage Service User Privilege Level Required ViewAuthentication Microsoft Windows AuthenticationVMware ESX Server 4.X Authentication VMware ESXi Server 5.X AuthenticationEncryption Assigning User PrivilegesAdding Users To a Domain On Windows Operating Systems Creating Users With Power User Privileges Creating Users Creating Users With User PrivilegesUserName HostName Rights Best Practices While Using The Omarolemap File Configuring The Snmp Agent Select Account is disabled and click OKOpen the Computer Management window Snmp Service Properties window appears Changing The Snmp Community NameSnmp Agent Access Control Configuration Snmp Service Configuration window appearsEnabling Snmp Set Operations Server Administrator Snmp Agent Install Actions Sever Administrator Snmp Install Actions Enabling Snmp Access From Remote HostsTo configure the Snmp agent To enable VMWare Snmp service, run the following command Page Firewall Configuration Using Server Administrator Server Administrator Local System LoginLogging In And Out Central Web Server Login Click SubmitUsing The Active Directory Login Single Sign-OnEnabling The Use Of Client-Side Scripts On Internet Explorer Enabling The Use Of Client-Side Scripts On Mozilla FirefoxGUI Field Name Sample Server Administrator Home Page Non-Modular System Features Modular System System/Server Module Component Status Indicators Global Navigation BarSystem Tree Action WindowGauge Indicators Task ButtonsUnderlined Items Using The Online Help Using The Preferences HomeServer Administrator Web Server Preferences Setting User And System PreferencesManaged System Preferences Click General Settings Secure Port SystemCertificate Management Click X.509 CertificateUsing The Server Administrator Command Line Interface Server Administrator Web Server Action TabsServer Administrator Services Managing Your SystemServer Administrator Home Page System Tree Objects Managing System/Server Module Tree ObjectsModular Enclosure Accessing And Using Chassis Management Controller System/Server Module PropertiesModular Enclosure object Tab Properties Subtab Information Licensing Subtabs Information LicensingSubtabs Hardware Alert Command ShutdownLogs Alert ManagementMain System Chassis/Main System Session ManagementSubtabs Session Main System Chassis/Main System Properties Properties and Setup Subtab Information Setup Subtab BiosBatteries Properties Subtab InformationFans FirmwareHardware Performance Intrusion MemoryProperties Subtab Intrusion Properties Subtab MemoryPower Management NetworkPorts Subtab Information PropertiesPower Supplies Management Subtabs Budget ProfilesAlert Management Properties Subtab Elements Remote Access ProcessorsAlert Management Subtabs Alert Actions Temperatures Subtab Temperature Probes PropertiesRemovable Flash Media SlotsVoltages SoftwareOperating System Properties Subtab Voltage ProbesManaging Preferences Home Page Configuration Options General SettingsStorage Server Administrator Subtabs Access Configuration Snmp Configuration PreferencesWorking With Remote Access Controller Modular Enclosure Modular system Server Modules Main SystemRemote Access Device Viewing Basic InformationSystem Main System ChassisIPv4 Address IPv6 AddressVlan ID Click Apply ChangesClick Serial Port Serial Port Configuration window appears Click Apply Changes Click Terminal Mode SettingsAdditional Configuration For iDRAC Configuring Remote Access Device UsersClick Additional Configuration Setting Platform Event Filter Alerts None Reboot SystemPower Off System Power Cycle SystemSetting Platform Event Alert Destinations Server Administrator Logs Integrated FeaturesServer Administrator Logs Log Window Task ButtonsHardware Log Alert LogMaintaining The Hardware Log StatusCommand Log Setting Alert Actions Example 1 ps -ef /tmp/psout.txt 2&1Setting Alert Action Execute Application In Windows Server BMC/iDRAC Platform Events Filter Alert MessagesEvent Description Troubleshooting Connection Service FailureLogin Failure Scenarios Opt/dell/srvadmin/sbin/dsmomconnsvcdOpenManage Server Administrator Services Service Name Description Impact of FailureSeverity Dsmsadatamgr Frequently Asked Questions Are there other ports users can use apart from 1311?Port ITA communicating with Linux systems