HP StorageWorks 2/16V HP StorageWorks Fabric OS 5.3.x administrator guide (569 - Page 59

Managing user accounts, Overview, Accessing the management channel

Page 59 highlights

3 Managing user accounts This chapter provides information and procedures on managing authentication and user accounts. Overview Fabric OS provides two options for authenticating users-remote RADIUS services and/or the local switch user database. Both options allow users to be centrally managed using the following methods: • Local user database: Manually synchronize the local user database using the distribute command to push a copy of the switch's local user database to all other Fabric OS 5.2.x and higher switches in the fabric. • Remote RADIUS servers: Users are managed in a remote RADIUS server, all switches in the fabric can be configured to authenticate against the centralized remote database. Accessing the management channel The total number of sessions on a switch may not exceed 32. Table 8 shows the number of simultaneous login sessions allowed for each role. Table 8 Maximum number of simultaneous sessions Role name Maximum sessions User 4 Operator 4 SwitchAdmin 4 ZoneAdmin 4 FabricAdmin 4 BasicSwitchAdmin 4 SecurityAdmin 4 Admin 2 Using role-based access control (RBAC) Fabric OS 5.3.0 uses Role-Based Access Control (RBAC) to determine which commands a user can run. Assign one of the Fabric OS predefined roles to a user, as shown in Table 9. Table 9 Fabric OS 5.3.0 roles Role name Version Duties Description Admin SwitchAdmin All 5.0.x and higher All administration Local switch administration All administrative commands. Most switch (local) commands, excludes security, user management, and zoning commands. Operator SecurityAdmin 5.2x0 and higher 5.3.0 General switch administration Restricts security functions Routine switch maintenance commands. All switch security and user management functions ZoneAdmin FabricAdmin 5.2.x and higher 5.2.x and higher Zone administration Fabric and switch administration Zone management commands only. All switch and fabric commands, excludes user management and Administrative Domains commands. Fabric OS 5.3.0 administrator guide 61

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442
  • 443
  • 444
  • 445
  • 446
  • 447
  • 448
  • 449
  • 450
  • 451
  • 452
  • 453
  • 454
  • 455
  • 456
  • 457
  • 458
  • 459
  • 460
  • 461
  • 462
  • 463
  • 464
  • 465

Fabric OS 5.3.0 administrator guide
61
3
Managing user accounts
This chapter provides information and procedures on managing authentication and user accounts.
Overview
Fabric OS provides two options for authenticating users—remote RADIUS services and/or the local switch
user database. Both options allow users to be centrally managed using the following methods:
Local user database
: Manually synchronize the local user database using the distribute command
to push a copy of the switch’s local user database to all other Fabric OS 5.2.x and higher switches in
the fabric.
Remote RADIUS servers
: Users are managed in a remote RADIUS server, all switches in the fabric
can be configured to authenticate against the centralized remote database.
Accessing the management channel
The total number of sessions on a switch may not exceed 32.
Table 8
shows the number of simultaneous
login sessions allowed for each role.
Using role-based access control (RBAC)
Fabric OS 5.3.0
uses Role-Based Access Control (RBAC) to determine which commands a user can run.
Assign one of the Fabric OS predefined roles to a user, as shown in
Table 9
.
Table 8
Maximum number of simultaneous sessions
Role name
Maximum sessions
User
4
Operator
4
SwitchAdmin
4
ZoneAdmin
4
FabricAdmin
4
BasicSwitchAdmin
4
SecurityAdmin
4
Admin
2
Table 9
Fabric OS 5.3.0 roles
Role name
Version
Duties
Description
Admin
All
All administration
All administrative commands.
SwitchAdmin
5.0.x and higher
Local switch
administration
Most switch (local) commands,
excludes security, user management,
and zoning commands.
Operator
5.2x0 and higher
General switch
administration
Routine switch maintenance
commands.
SecurityAdmin
5.3.0
Restricts security
functions
All switch security and user
management functions
ZoneAdmin
5.2.x and higher
Zone administration
Zone management commands only.
FabricAdmin
5.2.x and higher
Fabric and switch
administration
All switch and fabric commands,
excludes user management and
Administrative Domains commands.