Account authentication, Partition management capabilities, Local users – HP Integrity Superdome 2 Server User Manual

Page 15

Advertising
background image

Bays selected for
this account

Account name/privilege
level

Capabilities

Account classification

own account

•

Can 'show' CLI commands

Partition management capabilities

User access to commands for managing the partition configuration and the partitions themselves
can be controlled through the Parcon_Admin access right and partition access assignments using
the ASSIGN PARCON_ADMIN and ASSIGN PARTITION commands. Access to ALL (current and
future) or individual partitions by partition ID may be assigned. The following table identifies the
operations accounts may use on assigned partitions based on privilege level.

Parcon_Admin
assigned

Account name/privilege
level

Partition capabilities

Account classification

Yes

Administrator/administrator

•

All commands available to Parcon
Administrator accounts

Administrator

Yes

user name/administrator

Parcon Administrator

•

Manage the partition configuration
(create, modify, delete partitions)

•

All partition operations available to
Partition Administrator accounts

•

Access is always available to ALL
partitions

No

user name/administrator

Partition Administrator

•

Restart the complex

•

Update partition firmware

•

All partition operations available to
Partition Operator accounts

No

user name/operator

Partition Operator

•

Partition power and reset commands

•

Clear console logs

•

All partition operations available to
Partition User accounts

No

user name/user

Partition User

•

View partition and event logs

•

Connect to partition consoles

•

View partition status and info

Account authentication

Local users

•

This is the default setting. Local user accounts are directly authenticated against a password
for each account stored on the active Onboard Administrator.

•

Account modifications are automatically synchronized between both Onboard Administrator
modules if two are present.

•

Local users might be disabled if LDAP is enabled, leaving the Administrator account as the
only local account that cannot be disabled.

Access level and privileges

15

Advertising