HP 3PAR StoreServ 7400 2-node HP 3PAR StoreServ Storage Concepts Guide (OS 3.1 - Page 19

Local User Authentication and Authorization, Domain User Access, local users

Page 19 highlights

Table 2 HP 3PAR OS User Roles (continued) User Roles 3PAR AO 3PAR RM Rights Assigned to Roles Rights are limited to internal use by HP for Adaptive Optimization operations. Rights are limited to internal use by HP for Recovery Manager operations. Local User Authentication and Authorization Users accessing the HP 3PAR storage system with the HP 3PAR CLI client or Secure Shell (SSH) connections are authenticated and authorized directly on the system. These users are referred to as local users. The information used to authenticate and authorize a local user is stored on the system. For instructions on creating a local user, refer to the HP 3PAR Command Line Interface Administrator's Manual and the HP 3PAR Management Console Online Help. LDAP User Authentication and Authorization An LDAP user is authenticated and authorized using information from a Lightweight Directory Access Protocol (LDAP) server. If multiple systems are configured to use the same LDAP server, a user that can access one system can access all systems with the role and rights assigned to the LDAP group. Local user roles and rights are associated with an individual, LDAP user roles and rights are the same for all members of the group. If you want to authenticate and authorize LDAP users with different roles, you must create an LDAP group for each role. For detailed information about LDAP users and LDAP connections, see "Lightweight Directory Access Protocol" (page 20). For instructions on setting up an LDAP connection, refer to the HP 3PAR Command Line Interface Administrator's Manual. Domain User Access A domain user is a user with access to a specific domain. Local users belonging to a system using HP 3PAR Virtual Domains Software are domain users. In addition to the user's roles and rights, a domain users' activities are also limited to the domains to which they have access. A domain user's assigned user role is applicable only within the domain to which the user has access. For detailed information about virtual domains and domain users, see "HP 3PAR Virtual Domains" (page 24). For instructions on creating a domain user, refer to the HP 3PAR Command Line Interface Administrator's Manual and the HP 3PAR Management Console Online Help. NOTE: Virtual domains require an HP 3PAR Virtual Domains Software license. For additional information about the license, see "HP 3PAR Software" (page 9). Local User Authentication and Authorization 19

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95

Table 2 HP 3PAR OS User Roles
(continued)
Rights Assigned to Roles
User Roles
Rights are limited to internal use by HP for Adaptive
Optimization operations.
3PAR AO
Rights are limited to internal use by HP for Recovery
Manager operations.
3PAR RM
Local User Authentication and Authorization
Users accessing the HP 3PAR storage system with the HP 3PAR CLI client or Secure Shell (SSH)
connections are authenticated and authorized directly on the system. These users are referred to
as
local users
. The information used to authenticate and authorize a local user is stored on the
system.
For instructions on creating a local user, refer to the
HP 3PAR Command Line Interface
Administrator’s Manual
and the HP 3PAR Management Console Online Help.
LDAP User Authentication and Authorization
An
LDAP user
is authenticated and authorized using information from a Lightweight Directory
Access Protocol (LDAP) server. If multiple systems are configured to use the same LDAP server, a
user that can access one system can access all systems with the role and rights assigned to the
LDAP group.
Local user roles and rights are associated with an individual, LDAP user roles and rights are the
same for all members of the group. If you want to authenticate and authorize LDAP users with
different roles, you must create an LDAP group for each role.
For detailed information about LDAP users and LDAP connections, see
“Lightweight Directory Access
Protocol” (page 20)
. For instructions on setting up an LDAP connection, refer to the
HP 3PAR
Command Line Interface Administrator’s Manual
.
Domain User Access
A
domain user
is a user with access to a specific domain. Local users belonging to a system using
HP 3PAR Virtual Domains Software are domain users. In addition to the user’s roles and rights, a
domain users’ activities are also limited to the domains to which they have access. A domain user’s
assigned user role is applicable only within the domain to which the user has access.
For detailed information about virtual domains and domain users, see
“HP 3PAR Virtual Domains”
(page 24)
. For instructions on creating a domain user, refer to the
HP 3PAR Command Line Interface
Administrator’s Manual
and the HP 3PAR Management Console Online Help.
NOTE:
Virtual domains require an HP 3PAR Virtual Domains Software license. For additional
information about the license, see
“HP 3PAR Software” (page 9)
.
Local User Authentication and Authorization
19