HP ProLiant DL380G5-WSS 3.7.0 HP StorageWorks HP Scalable NAS File Serving Sof - Page 227

Tips for specifying accounts, View effective rights

Page 227 highlights

Form. Specify whether you entered a name or an ID for the account. Tips for specifying accounts When specifying accounts for a role, you should be aware of the following: • To simplify Role-Based Security administration, specify groups instead of users wherever possible. • Specify groups that are valid for all servers in the cluster. NOTE: HP Scalable NAS will not prevent you from adding users or groups that are not valid on all nodes. For example, you can add local users or groups to a role, but these users and groups have the permissions of the role only on the local server and are not valid role members on the other servers. View effective rights The My Rights tab on the Role-Based Security Control Panel lists the effective rights that you have on the cluster. Effective rights are the sum of the rights provided by all of the roles to which you belong. Allowed operations are indicated by a checkmark. Denied operations are indicated by an X. The Role memberships pane at the bottom of the My Rights tab shows the roles to which you belong. Roles that are disabled appear in italics. In the following example, the user has logged on as a member of the local Administrators group and is therefore a member of the default System Administrator role. This group is allowed to perform all cluster operations. However, the user also belongs to the Deny Storage group, which disallows the ability to perform storage operations. Because the deny right overrides the allow right provided to the System Administrator group, this user is denied the ability to perform storage tasks. The Security resource is a special case. All members of the System Administrator role are allowed to perform Security tasks, even if they belong to another role that denies that right. If you belong to the role because you are a member of group that is either directly or indirectly assigned to the role, that group will be listed under the Assigned Group column in the Role memberships pane. In this example, the user belongs to a group that is a member of the default System Administrator role. For the Deny Storage role, HP Scalable NAS File Serving Software administration guide 227

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435

Form.
Specify whether you entered a name or an ID for the account.
Tips for specifying accounts
When specifying accounts for a role, you should be aware of the following:
To simplify Role-Based Security administration, specify groups instead of users
wherever possible.
Specify groups that are valid for all servers in the cluster.
NOTE:
HP Scalable NAS will not prevent you from adding users or groups that are not
valid on all nodes. For example, you can add local users or groups to a role, but
these users and groups have the permissions of the role only on the local server and
are not valid role members on the other servers.
View effective rights
The My Rights tab on the Role-Based Security Control Panel lists the effective rights
that you have on the cluster. Effective rights are the sum of the rights provided by all
of the roles to which you belong. Allowed operations are indicated by a checkmark.
Denied operations are indicated by an X.
The Role memberships pane at the bottom of the My Rights tab shows the roles to
which you belong. Roles that are disabled appear in italics. In the following example,
the user has logged on as a member of the local Administrators group and is therefore
a member of the default System Administrator role. This group is allowed to perform
all cluster operations. However, the user also belongs to the Deny Storage group,
which disallows the ability to perform storage operations. Because the deny right
overrides the allow right provided to the System Administrator group, this user is
denied the ability to perform storage tasks.
The Security resource is a special case. All members of the System Administrator role
are allowed to perform Security tasks, even if they belong to another role that denies
that right.
If you belong to the role because you are a member of group that is either directly
or indirectly assigned to the role, that group will be listed under the Assigned Group
column in the Role memberships pane. In this example, the user belongs to a group
that is a member of the default System Administrator role. For the Deny Storage role,
HP Scalable NAS File Serving Software administration guide
227