SANtricity 11 Manuals (CA08872-010)

to Japanese version

What do I need to know about mapping to storage system roles?

Before mapping groups to roles, review the guidelines.

The RBAC (role-based access control) capabilities include the following roles:

  • Storage admin
    Full read/write access to storage objects on the arrays, but no access to the security configuration.

  • Security admin
    Access to the security configuration in Access Management and Certificate Management.

  • Support admin
    Access to all hardware resources on storage systems, failure data, and MEL events. No access to storage objects or the security configuration.

  • Monitor
    Read-only access to all storage objects, but no access to the security configuration.

The Monitor role is required for all users, including the administrator.

If you are using an LDAP (Lightweight Directory Access Protocol) server and Directory Services, make sure that:

  • An administrator has defined user groups in the directory service.

  • You know the group domain names for the LDAP user groups.

SAML

If you are using the Security Assertion Markup Language (SAML) capabilities embedded in the storage system, make sure that:

  • An Identity Provider (IdP) administrator has configured user attributes and group membership in the IdP system.

  • You know the group membership names.

  • You know the attribute value for the group to be mapped. Regular expressions are supported. These special regular expression characters must be escaped with a backslash (\) if they are not part of a regular expression pattern:

    \.[]{}()<>*+-=!?^$|
  • The Monitor role is required for all users, including the administrator. Unified Manager will not operate correctly for any user without the Monitor role present.

Top of Page