Dell DX6004S DX Object Storage Administration Guide - Page 20

Security Privileges for Administrative Operations, Operation, Privilege required

Page 20 highlights

4.3. Security Privileges for Administrative Operations The following table shows the privileges required to perform administrative operations in a domain, bucket, or in the objects contained by them. Operation Create tenants Manage realms (that is, user lists) Privilege required CAStor administrator only. This realm is defined by the administrators parameter in your node or cluster configuration file. For more information, see Section 6.2, "Managing DX Storage Administrators and Users". put, post, or change in the domain or bucket. The user list for the domain is administered by the domain manager. Create buckets in a domain. User lists for buckets are administered by authorized users in the domain. post in the domain. The Admin Console enables you to set post permissions as "protection settings" for the domain. Create named objects in a bucket Each protection setting is specified as a Castor-Authorization header in the form: Castor-Authorization: domain-name/ _administrators, post=domain-name, where the domain in post=domain-name is blank if you choose the "all users" protection setting. post in the bucket Copyright © 2010 Caringo, Inc. All rights reserved 15 Version 5.0 December 2010

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74

Copyright © 2010 Caringo, Inc.
All rights reserved
15
Version 5.0
December 2010
4.3. Security Privileges for Administrative Operations
The following table shows the privileges required to perform administrative operations in a domain,
bucket, or in the objects contained by them.
Operation
Privilege required
Create tenants
CAStor administrator
only. This realm is defined by
the
administrators
parameter in your node or cluster
configuration file. For more information, see
Section 6.2,
“Managing DX Storage Administrators and Users”
.
Manage realms (that is, user lists)
put
,
post
, or
change
in the domain or bucket.
The user list for the domain is administered by the domain
manager.
User lists for buckets are administered by authorized
users in the domain.
Create buckets in a domain.
post
in the domain.
The Admin Console enables you to set
post
permissions
as "protection settings" for the domain.
Each protection setting is specified as a
Castor-Authorization
header in the form:
Castor-Authorization:
domain-name
/
_administrators, post=
domain-name
, where the
domain in
post=
domain-name
is blank if you choose
the "all users" protection setting.
Create named objects in a bucket
post
in the bucket