HP 3PAR StoreServ 7400 2-node HP 3PAR Command Line Interface Administrator& - Page 19

Viewing Users, Managing HP 3PAR Virtual Domains, Roles and Rights

Page 19 highlights

NOTE: • The first HP 3PAR storage system user account created must have a role with the right to create additional users. If the first user created has limited rights, the ability to configure the system will be restricted. • The _set rights include the right to remove the object. For example, the vvset_set right includes the right to remove virtual volume sets. • If you are using HP 3PAR Virtual Domains for access control, you must assign users a domain you created in your system or the all domain. See "Managing HP 3PAR Virtual Domains" (page 58) for instructions on creating domains. For more information about domains, see the HP 3PAR StoreServ Concepts Guide. • To create a new user, issue the createuser -c|-e command, where: ◦ -c|-e is either a clear-text (-c) or encrypted (-e) password. A clear-text password must be between 6 and 8 characters in length. An encrypted password must be less than or equal to 31 characters in length. Encrypted passwords are generated by the system. If no password is specified using -c or -e, then you are prompted to enter a clear-text password. ◦ is the name of the CLI account user. The user name can be up to 31 characters long. Valid characters include alphanumeric characters, the period symbol (.), dash symbol (-), and underscore symbol (_). The first character must be alphanumeric or an underscore symbol for users connecting to the system with the HP 3PAR CLI application. To access the system with an SSH connection, the first character of the user name must be alphanumeric. ◦ is the name of the domain to which the user will belong. The domain name can be up to 31 characters long. If you are not using Virtual Domains, specify the all domain. If you are using virtual domains, specify the name of an existing domain in your system. NOTE: By default, users in systems not using virtual domains are in the all domain. Users in the all domain have rights over the entire system. The Super, Create, Basic Edit, 3PAR AO, and 3PAR RM roles cannot be restricted and always belong to the all domain. For more information about the all domain, see the HP 3PAR StoreServ Concepts Guide. ◦ is the role assigned to the user. Valid values include browse, edit, super, service, create, basic_edit, 3PAR_AO, and 3PAR_RM. The roles and rights assigned to the CLI user determine which tasks a user can perform with a system. For information about viewing the roles and rights defined on a system, see "Viewing User Roles and Rights" (page 17). To view a list of roles and all of the rights assigned to the roles, see "Mapping Roles and Rights" (page 185). You can verify the creation of a new user with the showuser command. Viewing Users If you are using Virtual Domains, users with the Super, Create, Basic Edit, 3PAR AO, and 3PAR RM roles can view all system users across all domains. If the user belongs to a specific domain, the user can only view other users within the same domain. If you are not using Virtual Domains, the output of the showuser command still displays a Domain column. By default, users in systems not using domains fall into the all domain. For additional details about domains, see the HP 3PAR StoreServ Storage Concepts Guide. Viewing Users 19

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204

NOTE:
The first HP 3PAR storage system user account created must have a role with the right to create
additional users. If the first user created has limited rights, the ability to configure the system
will be restricted.
The
<object_set>_set
rights include the right to remove the object. For example, the
vvset_set
right includes the right to remove virtual volume sets.
If you are using HP 3PAR Virtual Domains for access control, you must assign users a domain
you created in your system or the
all
domain. See
“Managing HP 3PAR Virtual Domains”
(page 58)
for instructions on creating domains. For more information about domains, see the
HP 3PAR StoreServ Concepts Guide
.
To create a new user, issue the
createuser -c|-e <password> <user_name>
<domain_name> <role>
command, where:
-c|-e <password>
is either a clear-text (
-c
) or encrypted (
-e
) password. A clear-text
password must be between 6 and 8 characters in length. An encrypted password must
be less than or equal to 31 characters in length. Encrypted passwords are generated by
the system. If no password is specified using
-c
or
-e
, then you are prompted to enter
a clear-text password.
<user_name>
is the name of the CLI account user. The user name can be up to 31
characters long. Valid characters include alphanumeric characters, the period symbol
(
.
), dash symbol (
-
), and underscore symbol (
_
). The first character must be alphanumeric
or an underscore symbol for users connecting to the system with the HP 3PAR CLI
application. To access the system with an SSH connection, the first character of the user
name must be alphanumeric.
<domain_name>
is the name of the domain to which the user will belong. The domain
name can be up to 31 characters long. If you are not using Virtual Domains, specify the
all
domain. If you are using virtual domains, specify the name of an existing domain
in your system.
NOTE:
By default, users in systems not using virtual domains are in the
all
domain.
Users in the all domain have rights over the entire system. The Super, Create, Basic Edit,
3PAR AO, and 3PAR RM roles cannot be restricted and always belong to the
all
domain.
For more information about the
all
domain, see the
HP 3PAR StoreServ Concepts Guide
.
<role>
is the role assigned to the user. Valid values include
browse
,
edit
,
super
,
service
,
create
,
basic_edit
,
3PAR_AO
, and
3PAR_RM
. The roles and rights
assigned to the CLI user determine which tasks a user can perform with a system. For
information about viewing the roles and rights defined on a system, see
“Viewing User
Roles and Rights” (page 17)
. To view a list of roles and all of the rights assigned to the
roles, see
“Mapping Roles and Rights” (page 185)
.
You can verify the creation of a new user with the
showuser
command.
Viewing Users
If you are using Virtual Domains, users with the Super, Create, Basic Edit, 3PAR AO, and 3PAR
RM roles can view all system users across all domains. If the user belongs to a specific domain,
the user can only view other users within the same domain.
If you are not using Virtual Domains, the output of the
showuser
command still displays a
Domain
column. By default, users in systems not using domains fall into the
all
domain. For additional
details about domains, see the
HP 3PAR StoreServ Storage Concepts Guide
.
Viewing Users
19