OneCommand Manager Command Line Interface Version 10.4 User Manual P011032-01A Rev. A
1. Introduction
OneCommand Manager Secure Management
13
OneCommand Manager Secure Management
OneCommand Manager Secure Management gives system administrators the ability to
further enhance the active management security of their networks. Using Secure
Management, administrators can define each user's privileges for managing both local
and remote adapters. When running in Secure Management mode, users must specify
their user name and password to run the OneCommand Manager CLI. When users are
authenticated, only they can perform the functions allowed by the OneCommand
Manager user group to which they belong. If your systems are running in an LDAP or
Active Directory domain, the OneCommand Manager CLI will authenticate the user
with those defined in that domain. For Linux and Solaris systems this is done using
PAM.
Note: OneCommand Manager Secure Management is supported on Linux, Solaris,
and Windows, but is not supported on VMware hosts. For VMware hosts, the
CIM credentials are used.
Administrators set up user accounts such that a user belongs to one of the
OneCommand Manager user groups. The user groups define the management
capabilities for the user. Table 1-1, Secure Management User Privileges, on page 13
defines the OneCommand Manager user groups and each group's management
capabilities.
On Linux or Solaris systems, the unix “getent group” utility can be run on the target
host system’s command shell to verify the correct configuration of the groups. The
groups, and users within the groups, appear in the output of this command.
Note: Although a user may belong to the administrator group or be the root user, they
will not have full privileges to run the OneCommand Manager unless they are
also a member of the ocmadmin group. Otherwise, when secure management is
enabled, a root user or administrator can only manage local adapters (similar to
the ocmlocaladmin user).
Remote management operations between two machines is allowed or denied
depending on the OneCommand Manager secure management status of the machines,
and the domains to which the machines belong. The following tables, Table 1-2, Active
Commands: machines on same domain, on page 14, Table 1-3, Active Commands:
machines on different domain, on page 14, andTable 1-4, Passive Commands: machines
Table 1-1 Secure Management User Privileges
Group Name OneCommand Manager Capability
ocmadmin Allows full active management of local and remote adapters
ocmlocaladmin Permits full active management of local adapters only
ocmuser Permits read-only access of local and remote adapters
ocmlocaluser Permits read-only access of local adapters