Dell PowerEdge VRTX Chassis Management Controller Version 1.0 for Dell PowerEd - Page 97

Configuring User Accounts and Privileges, Types of Users

Page 97 highlights

9 Configuring User Accounts and Privileges You can setup user accounts with specific privileges (role-based authority) to manage your system with CMC and maintain system security. By default, CMC is configured with a local administrator account. The default user name is rootand the password is calvin. As an administrator, you can set up user accounts to allow other users to access the CMC. You can set up a maximum of 16 local users, or use directory services such as Microsoft Active Directory or LDAP to setup additional user accounts. Using a directory service provides a central location for managing authorized user accounts. CMC supports role-based access to users with a set of associated privileges. The roles are administrator, operator, read-only, or none. The role defines the maximum privileges available. Types of Users There are two types of users: • CMC users or chassis users • iDRAC users or server users (since the iDRAC resides on a server) CMC and iDRAC users can be local or directory service users. Except where a CMC user has Server Administrator privilege, privileges granted to a CMC user are not automatically transferred to the same user on a server, because server users are created independently from CMC users. In other words, CMC Active Directory users and iDRAC Active Directory users reside on two different branches in the Active Directory tree. To create a local server user, the Configure Users must log in to the server directly. The Configure Users cannot create a server user from CMC or vice versa. This rule protects the security and integrity of the servers. Table 10. User Types Privilege CMC Login User Chassis Configuration Administrator Description User can log in to CMC and view all the CMC data, but cannot add or modify data or execute commands. It is possible for a user to have other privileges without the CMC Login User privilege. This feature is useful when a user is temporarily not allowed to login. When that user's CMC Login User privilege is restored, the user retains all the other privileges previously granted. User can add or change data that: • Identifies the chassis, such as chassis name and chassis location. • Is assigned specifically to the chassis, such as IP mode (static or DHCP), static IP address, static gateway, and static subnet mask. • Provides services to the chassis, such as date and time, firmware update, and CMC reset. • Is associated with the chassis, such as slot name and slot priority. Although these properties apply to the servers, they are strictly chassis properties relating to the slots rather than the servers 97

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193

9
Configuring User Accounts and Privileges
You can setup user accounts with specific privileges (role-based authority) to manage your system with CMC and
maintain system security. By default, CMC is configured with a local administrator account. The default user name is
root
and the password is
calvin
. As an administrator, you can set up user accounts to allow other users to access
the CMC.
You can set up a maximum of 16 local users, or use directory services such as Microsoft Active Directory or LDAP to
setup additional user accounts. Using a directory service provides a central location for managing authorized user
accounts.
CMC supports role-based access to users with a set of associated privileges. The roles are administrator, operator,
read-only, or none. The role defines the maximum privileges available.
Types of Users
There are two types of users:
CMC users or chassis users
iDRAC users or server users (since the iDRAC resides on a server)
CMC and iDRAC users can be local or directory service users.
Except where a CMC user has
Server Administrator
privilege, privileges granted to a CMC user are not automatically
transferred to the same user on a server, because server users are created independently from CMC users. In other
words, CMC Active Directory users and iDRAC Active Directory users reside on two different branches in the Active
Directory tree. To create a local server user, the Configure Users must log in to the server directly. The Configure Users
cannot create a server user from CMC or vice versa. This rule protects the security and integrity of the servers.
Table 10. User Types
Privilege
Description
CMC Login User
User can log in to CMC and view all the CMC data, but cannot add or modify
data or execute commands.
It is possible for a user to have other privileges without the CMC Login User
privilege. This feature is useful when a user is temporarily not allowed to
login. When that user’s CMC Login User privilege is restored, the user retains
all the other privileges previously granted.
Chassis Configuration Administrator
User can add or change data that:
Identifies the chassis, such as chassis name and chassis location.
Is assigned specifically to the chassis, such as IP mode (static or
DHCP), static IP address, static gateway, and static subnet mask.
Provides services to the chassis, such as date and time, firmware
update, and CMC reset.
Is associated with the chassis, such as slot name and slot priority.
Although these properties apply to the servers, they are strictly
chassis properties relating to the slots rather than the servers
97