
8 Manage users and groups
Use the information in this chapter to learn how to configure user authentication, either locally or
using an enterprise directory, and to define user privileges based on job responsibilities, or role,
in using this software. See also Troubleshooting users and groups (page 146).
About user roles
User roles enable you to assign permissions and privileges to users based on their job
responsibilities. You can assign full privileges to a user, or you can assign a subset of permissions
to view, create, edit, or remove resources managed by the appliance.
NOTE: If you are using an external authentication directory service such as LDAP in the
CloudSystem Console, the role assignment is made to the group, rather than to individual users.
However, in the CloudSystem Portal, roles are assigned to users per project, and groups are not
recognized.
See the HP CloudSystem 8.0 Release Notes for information and limitations when mapping roles
in the CloudSystem Console to the CloudSystem Portal. This document is available at the Enterprise
Information Library.
Table 3 Appliance and resource management roles
NotesAssociated permissions or privilegesType of userRole
An Infrastructure administrator (Full role)
created in the CloudSystem Console can view
View, create, edit, or remove resources
managed by the appliance, including
Infrastructure
administrator
Full
and manage all resources in the CloudSystem
Console.
management of the appliance itself through
the UI or command line.
Using the same username and password, the
Infrastructure administrator can log into the
An Infrastructure administrator can also
manage information provided by the
CloudSystem Portal in the Admin role, with full
access to the Administrator project.
appliance in the form of activities,
notifications, and logs.
See also Table 4 (page 53).An Infrastructure administrator can add
CloudSystem Foundation license keys.
A Read only user created in the CloudSystem
Console can view all resources in the
View only access, with the exception of
license keys. Users with this role see a
Read onlyRead
only
CloudSystem Console but cannot create, edit,
or delete resources.
message that they are not authorized to view
license information.
A Read only user can log into the CloudSystem
Portal if the user is a member or admin of a
non-Administrator project.
A Read only user is not restricted to Read only
privileges in the CloudSystem Portal. This user
has either full member or full administrator
privileges depending on their user
configuration in the CloudSystem Portal .
No backup functions are provided in the
CloudSystem Console. Information about
NOTE: Users with this role cannot log into
the CloudSystem Console or CloudSystem
Portal user interface.
Backup
administrator
Specialized
backing up and restoring CloudSystem
Foundation is provided in a white paper
available at Enterprise Information Library.
52 Manage users and groups
Commentaires sur ces manuels