HP 2x1Ex16 HP IP Console Viewer User Guide - Page 210

The Group Container, Group Container Mask, and Target Mask fields are only used for Group Attribute

Page 210 highlights

The Query Parameters tab specifies which query method is used to authenticate and authorize the user. It also specifies the parameters associated with each query method. The console switch performs two different types of queries. Query Mode (Console Switch) is used to authenticate administrators attempting to access the console switch itself. Query Mode (Server) is used to authenticate users who are attempting to access attached servers. Additionally, each type of query has three modes that utilize certain types of information to determine whether a user has access to a console switch connected servers, or both. The Query Mode (Console Switch) parameters are used to determine whether an HP IP Console Viewer has Console Switch Administrator or Administrator access to the console switch. The Query Mode (Server) parameters are used to determine whether a user of the HP IP Console Viewer has user access to servers attached to a console switch. The Query Mode (Server) cannot be used to grant Console Switch Administrator access to a console switch. The Group Container, Group Container Mask, and Target Mask fields are only used for Group Attribute query modes and are required when performing a Console Switch or Server Group Attribute query. The Group Container field specifies the OU created in the Active Directory by the administrator as the location for group objects. Group Container is used when Query Mode is set to Group Attribute. Each group object, in turn, is assigned members to associate with a particular access level for member objects (people, console switches, and target servers). Setting the value of an attribute in the group object configures the access level associated with a group. The Access Control Attribute field defines which field in the Directory schema is used to assign access rights. For example, if the Notes property in the group object is used to implement the access control attribute, the Access Control Attribute field in the Query Parameters tab should be set to info, because the schema name of the Notes field is info. Setting the Notes property to: • KVM Appliance Admin causes the members of that group to have administration access to the console switches and access to target servers that are connected to the KVM switches as a user. • KVM User causes the members of that group to have access to any target servers in the group. • Serial User causes the members of that group to have access to the serial port that is named the same as the server that is a member of that group. • Serial Appliance Admin causes the members of that group to have appliance administrator rights to the serial console switches that are members of that group. • Serial User Admin causes the members of that group to have rights to add, delete, or modify user accounts in the serial console switch internal user database. Using directory services integration 210

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339

Using directory services integration
210
The Query Parameters tab specifies which query method is used to authenticate and authorize the user. It
also specifies the parameters associated with each query method.
The console switch performs two different types of queries. Query Mode (Console Switch) is used to
authenticate administrators attempting to access the console switch itself. Query Mode (Server) is used to
authenticate users who are attempting to access attached servers.
Additionally, each type of query has three modes that utilize certain types of information to determine
whether a user has access to a console switch connected servers, or both.
The Query Mode (Console Switch) parameters are used to determine whether an HP IP Console Viewer
has Console Switch Administrator or Administrator access to the console switch.
The Query Mode (Server) parameters are used to determine whether a user of the HP IP Console Viewer
has user access to servers attached to a console switch. The Query Mode (Server) cannot be used to grant
Console Switch Administrator access to a console switch.
The Group Container, Group Container Mask, and Target Mask fields are only used for Group Attribute
query modes and are required when performing a Console Switch or Server Group Attribute query.
The Group Container field specifies the OU created in the Active Directory by the administrator as the
location for group objects. Group Container is used when Query Mode is set to Group Attribute. Each
group object, in turn, is assigned members to associate with a particular access level for member objects
(people, console switches, and target servers). Setting the value of an attribute in the group object
configures the access level associated with a group. The Access Control Attribute field defines which field
in the Directory schema is used to assign access rights. For example, if the Notes property in the group
object is used to implement the access control attribute, the Access Control Attribute field in the Query
Parameters tab should be set to info, because the schema name of the Notes field is info.
Setting the Notes property to:
KVM Appliance Admin causes the members of that group to have administration access to the
console switches and access to target servers that are connected to the KVM switches as a user.
KVM User causes the members of that group to have access to any target servers in the group.
Serial User causes the members of that group to have access to the serial port that is named the
same as the server that is a member of that group.
Serial Appliance Admin causes the members of that group to have appliance administrator rights to
the serial console switches that are members of that group.
Serial User Admin causes the members of that group to have rights to add, delete, or modify user
accounts in the serial console switch internal user database.