Understanding user authorization
User authorization is a tool for restricting the management operations users can perform on a storage system.
By default, user authorization is enabled for Unisphere users, regardless of whether it is enabled on the storage system.
When configuring user authorization, an Administrator or SecurityAdmin maps individual users or groups of users to specific roles on storage systems and these roles determine the operations that the users can perform. These user-to-role-to-storage system mappings (known as authorization rules) are maintained in the symauth users list file that is stored on the host or storage system, depending on the storage operating environment.
NOTE: If the
symauth file contains one or more users, users who are not listed in the file are unable to access or even see storage systems from the Unisphere console.
|