HP BladeSystem c7000 HP BladeSystem Onboard Administrator User Guide - Page 231

Managing users, Users/Authentication, User roles and privilege levels, Role-based user accounts - firmware update procedure

Page 231 highlights

Managing users Users/Authentication This section explains the levels of user rights recognized by the HP BladeSystem Onboard Administrator and provides detailed procedures to configure the management functionalities provided by the Onboard Administrator. The Users/Authentication menu item cannot be selected and does not display overview information for user accounts or settings. Instead, select any of the sublevel menu items for specific settings. User roles and privilege levels Within the Users/Authentication category of HP BladeSystem Onboard Administrator, you can access the Local Users subcategory. In this subcategory, you can create user accounts that individuals use to log in to the HP Onboard Administrator, and have a username, password, and typically contact information. Users can have one of three privilege levels: • ADMINISTRATOR allows access to all aspects of the HP BladeSystem Onboard Administrator including configuration, firmware updates, user management, and resetting default settings. • OPERATOR allows access to all information, but only certain configuration settings can be changed. This account is used for individuals who might be required to periodically change configuration settings. • USER allows access to all information, but no changes can be made within HP BladeSystem Onboard Administrator. This account is used for individuals who need to see the configuration of the HP BladeSystem Onboard Administrator but do not need the ability to change settings. The privilege level approach of HP BladeSystem Onboard Administrator to user permissions facilitates the maintenance of server blade bays. This approach operates according to the following principles: • Users are assigned privilege levels in User Management. • A user can have access to any combination of device bays, interconnect bays, and Onboard Administrator bays. Access to a server blade by a user depends on the privilege level assigned to the user account. If you select a user with Administrator ACL or OA permission, the page will grey out and disable access to the blade and interconnect permissions and select them all. In cases where HP SIM is used, Onboard Administrator can integrate with HP SIM and use HP SIM users to facilitate a single login from HP SIM into Onboard Administrator. For more information, see HP SIM integration. Role-based user accounts Role-based user accounts on Onboard Administrator serve two purposes: to control the functions a user has access to on Onboard Administrator and to control permissions a temporary user account adopts on iLO when autologin is used. There are two major aspects of role-based user accounts on Onboard Administrator: bay permissions and a user privilege level. Bay permissions determine which bays the user is allowed to access. Bay permissions are selected during user account creation and allow access to specific device bays, interconnect bays, or Configuring the HP BladeSystem c7000 enclosure and enclosure devices 231

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318

Configuring the HP BladeSystem c7000 enclosure and enclosure devices
231
Managing users
Users/Authentication
This section explains the levels of user rights recognized by the HP BladeSystem Onboard Administrator and
provides detailed procedures to configure the management functionalities provided by the Onboard
Administrator.
The Users/Authentication menu item cannot be selected and does not display overview information for user
accounts or settings. Instead, select any of the sublevel menu items for specific settings.
User roles and privilege levels
Within the Users/Authentication category of HP BladeSystem Onboard Administrator, you can access the
Local Users subcategory. In this subcategory, you can create user accounts that individuals use to log in to the
HP Onboard Administrator, and have a username, password, and typically contact information. Users can
have one of three privilege levels:
ADMINISTRATOR
allows access to all aspects of the HP BladeSystem Onboard Administrator including
configuration, firmware updates, user management, and resetting default settings.
OPERATOR
allows access to all information, but only certain configuration settings can be changed.
This account is used for individuals who might be required to periodically change configuration
settings.
USER
allows access to all information, but no changes can be made within HP BladeSystem Onboard
Administrator. This account is used for individuals who need to see the configuration of the HP
BladeSystem Onboard Administrator but do not need the ability to change settings.
The privilege level approach of HP BladeSystem Onboard Administrator to user permissions facilitates the
maintenance of server blade bays. This approach operates according to the following principles:
Users are assigned privilege levels in User Management.
A user can have access to any combination of device bays, interconnect bays, and Onboard
Administrator bays.
Access to a server blade by a user depends on the privilege level assigned to the user account. If you select
a user with Administrator ACL or OA permission, the page will grey out and disable access to the blade and
interconnect permissions and select them all.
In cases where HP SIM is used, Onboard Administrator can integrate with HP SIM and use HP SIM users to
facilitate a single login from HP SIM into Onboard Administrator. For more information, see HP SIM
integration.
Role-based user accounts
Role-based user accounts on Onboard Administrator serve two purposes: to control the functions a user has
access to on Onboard Administrator and to control permissions a temporary user account adopts on iLO
when autologin is used.
There are two major aspects of role-based user accounts on Onboard Administrator: bay permissions and a
user privilege level. Bay permissions determine which bays the user is allowed to access. Bay permissions are
selected during user account creation and allow access to specific device bays, interconnect bays, or