HP BL680c HP Virtual Connect Enterprise Manager User Guide - Page 81

Removing an external manager account

Page 81 highlights

11 Removing an external manager account For VCEM to manage VC Domains (using the Virtual Connect Manager, the embedded software in a Virtual Connect Ethernet module) VCEM uses programmatic interfaces with each Virtual Connect Manager. VCEM automatically creates an external manager account in each Virtual Connect Manager for subsequent authentication. NOTE: VCEM uses a Secure Sockets Layer (SSL) connection provided by HP SIM. For more information about the available cipher suites and how to enable or disable them, see the Understanding HP SIM security white paper at http://h18013.www1.hp.com/products/servers/management/hpsim/infolibrary.html. VCEM creates a local account on each Virtual Connect Manager it manages. To prevent inadvertent modification, this account is not visible from the user-interface on the Virtual Connect Manager associated with the VC Domain being managed by VCEM. This account has full privileges to the Virtual Connect Manager and the credentials are used for SOAP interfaces with the Virtual Connect Manager, using a connection over Secure Sockets Layer (SSL). These credentials are securely stored on the Central Management Server (CMS) used to run VCEM. Each Virtual Connect Manager managed by VCEM has a unique, randomly generated password. Removing the external manager account removes Virtual Connect Manager from VCEM control. Remove the account using the following methods: • Preferred method-Uses the VCEM user-interface and removes the account from the Virtual Connect Manager and the credential store from VCEM. • Remove the VC Domain from the VC Domain Group • Secondary method-Uses the Virtual Connect Manager command line interface to remove the account from the Virtual Connect Manager. If the preferred method is not possible, then the Virtual Connect Manager supports command line interfaces that allow the external manager account to be deleted from the Virtual Connect Manager and allow a Virtual Connect Manager to be removed from VCEM control. To remove the external manager account: 1. Telnet in to the Virtual Connect Manager using an SSH connection such as SSH [email protected], where xxx is the VC Domain IP address. 2. To determine the username of the external manager account, from the Virtual Connect Manager command prompt, enter show external-manager. For this example, assume the username returned was xyz. 3. To disable the account, from the Virtual Connect Manager command prompt, enter set external-manager Username=xyz Enabled=false If VC Domain firmware is 2.0x, perform the following: • To remove the account and release the VC Domain from VCEM control, from the Virtual Connect Manager command prompt, enter remove external-manager Username=xyz mactype= MacStart= MacEnd= wwnType= WwnStart= WwnEnd= serverIdType= serverIdStart= serverIdEnd= NOTE: "-quiet" is an option to suppress user confirmation prompts. This option is useful for scripting operations. This option is available for VC firmware 2.0x for the disable account, remove the account, and release ranges commands. For more information, see the HP Virtual Connect Manager Command Line Interface User Guide. 81

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111

11 Removing an external manager account
For VCEM to manage VC Domains (using the Virtual Connect Manager, the embedded software in a Virtual
Connect Ethernet module) VCEM uses programmatic interfaces with each Virtual Connect Manager. VCEM
automatically creates an external manager account in each Virtual Connect Manager for subsequent
authentication.
NOTE:
VCEM uses a Secure Sockets Layer (SSL) connection provided by HP SIM. For more information
about the available cipher suites and how to enable or disable them, see the
Understanding HP SIM security
white paper at
ht
tp://h1
80
1
3
.w
w
w1
.hp
.com/pr
oduc
ts/ser
v
ers/manag
em
ent/hpsim/inf
olibr
ar
y
.html
.
VCEM creates a local account on each Virtual Connect Manager it manages. To prevent inadvertent
modification, this account is not visible from the user-interface on the Virtual Connect Manager associated
with the VC Domain being managed by VCEM. This account has full privileges to the Virtual Connect
Manager and the credentials are used for SOAP interfaces with the Virtual Connect Manager, using a
connection over Secure Sockets Layer (SSL). These credentials are securely stored on the Central Management
Server (CMS) used to run VCEM. Each Virtual Connect Manager managed by VCEM has a unique, randomly
generated password.
Removing the external manager account removes Virtual Connect Manager from VCEM control. Remove
the account using the following methods:
Preferred method—Uses the VCEM user-interface and removes the account from the Virtual Connect
Manager and the credential store from VCEM.
Remove the VC Domain from the VC Domain Group
Secondary method—Uses the Virtual Connect Manager command line interface to remove the account
from the Virtual Connect Manager.
If the preferred method is not possible, then the Virtual Connect Manager supports command line
interfaces that allow the external manager account to be deleted from the Virtual Connect Manager
and allow a Virtual Connect Manager to be removed from VCEM control.
To remove the external manager account:
1.
Telnet in to the Virtual Connect Manager using an SSH connection such as SSH
Administrator@
xxx.xxx.xxx.xxx
, where
xxx
is the VC Domain IP address.
2.
To determine the username of the external manager account, from the Virtual Connect Manager
command prompt, enter
show external-manager
. For this example, assume the username
returned was
xyz
.
3.
To disable the account, from the Virtual Connect Manager command prompt, enter
set external-manager Username=xyz Enabled=false
If VC Domain firmware is 2.0x, perform the following:
To remove the account and release the VC Domain from VCEM control, from the Virtual
Connect Manager command prompt, enter
remove external-manager Username=xyz
mactype=<Factory-Default/User-Defined> MacStart=<> MacEnd=<>
wwnType=<Factory-Default/User-Defined> WwnStart=<> WwnEnd=<>
serverIdType=<Factory-Default/User-Defined> serverIdStart=<>
serverIdEnd=<>
NOTE:
"-quiet" is an option to suppress user confirmation prompts. This option is useful for scripting
operations. This option is available for VC firmware 2.0x for the disable account, remove the account,
and release ranges commands.
For more information, see the
HP Virtual Connect Manager Command Line Interface User Guide
.
81