Tripp Lite B097016INT Owners Manual for B093- B097- and B098-Series Console Se - Page 46

Add and Edit Users

Page 46 highlights

4. Serial Port, Host, Device and User Configuration 4.2 Add and Edit Users The Administrator uses this menu selection to set up, edit and delete users, and define the access permissions for each of these users. Users can be authorized to access specified services, serial ports, power devices and specified network-attached hosts. These users can also be given full Administrator status (with full configuration, management and access privileges). To simplify user set up, they can be configured as members of Groups. With firmware V3.5.2 and later, there are six Groups set up by default (earlier versions only had admin and user by default): admin Provides users with unlimited configuration and management privileges. pptpd Group to allow access to the PPTP VPN server. Passwords for users in this group are stored in plain text. dialin Group to allow dial-in access via modems. Passwords for users in this group are stored in plain text. ftp Group to allow ftp access and file access to storage devices. pmshell Group to set default shell to pmshell. users Provides users with basic management privileges. Notes: 1. The admin group provides the admin user with full Administrator privileges. The admin user (Administrator) can access the console server using any of the services enabled in System: Services (e.g., if only HTTPS has been enabled, then the Administrator can only access the console server using HTTPS). However, once logged in, they can reconfigure the console server settings (e.g., to enabled HTTP/telnet for future access). They can also access any of the connected hosts or serial port devices using any of the services enabled for these connections. The Administrator can reconfigure the access services for any host or serial port. Only trusted users should have Administrator access. 2. The user group provides the general user with limited access to the console server, connected hosts and serial devices. These Users can access only the management section of the Management Console menu with no command line access to the console server. They also can only access those hosts and serial devices that have been checked for them. 3. If a user is set up with pptd, dialin, ftp or pmshell group membership, they will have restricted user shell access to the assigned managed devices but will not have any direct access to the console server itself. To add this function, the user must also be a member of the "users" or "admin" groups. 46

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288

46
4. Serial Port, Host, Device and User Configuration
4.2 Add and Edit Users
The Administrator uses this menu selection to set up, edit and delete users, and define the access permissions for each of
these users.
Users can be authorized to access specified services, serial ports, power devices and specified network-attached hosts. These
users can also be given full Administrator status (with full configuration, management and access privileges).
To simplify user set up, they can be configured as members of Groups. With firmware V3.5.2 and later, there are six Groups
set up by default (earlier versions only had admin and user by default):
admin
Provides users with unlimited configuration and management privileges.
pptpd
Group to allow access to the PPTP VPN server. Passwords for users in this group are stored in plain text.
dialin
Group to allow dial-in access via modems. Passwords for users in this group are stored in plain text.
ftp
Group to allow ftp access and file access to storage devices.
pmshell
Group to set default shell to pmshell.
users
Provides users with basic management privileges.
Notes:
1. The admin group provides the admin user with full Administrator privileges. The admin user (Administrator) can access the
console server using any of the services enabled in
System: Services
(e.g., if only HTTPS has been enabled, then the
Administrator can only access the console server using HTTPS). However, once logged in, they can reconfigure the console
server settings (e.g., to enabled HTTP/telnet for future access). They can also access any of the connected hosts or serial port
devices using any of the services enabled for these connections. The Administrator can reconfigure the access services for any
host or serial port. Only trusted users should have Administrator access.
2. The user group provides the general user with limited access to the console server, connected hosts and serial devices. These
Users can access only the management section of the Management Console menu with no command line access to the console
server. They also can only access those hosts and serial devices that have been checked for them.
3. If a user is set up with
pptd, dialin, ftp
or
pmshell
group membership, they will have restricted user shell access to the
assigned managed devices but will not have any direct access to the console server itself. To add this function, the user must
also be a member of the “users” or “admin” groups.