LPAR manager operations from the LPAR manager screen
You can use LPAR manager from the LPAR manager screen by logging in to
the CLI console of the management module.
If user authentication of the LP CLI is enabled, the LPAR manager screen is
also subject to role-based access control. The role that is assigned to the
management module user always applies, because the LPAR manager screen
does not support login to LPAR manager. If the role has not been assigned
the LPAR manager security permission, LPAR manager security operations will
be prohibited.
Configuration example
If roles and access permissions are configured as shown below, only the user
who logs in as "Local user A" can perform LPAR manager security operations.
Item
Value
User authentication of the LP
CLI
Enabled
Types of roles
LPAR manager security permission
Administrators role
Have privilege
Users role
Do not have privilege
User category
Operation
User authenticated by LPAR
manager
Local user A
(security administrator)
Administrators role
Local user B
(general administrator)
Users role
User authenticated by LDAP
Users role
User authenticated by RADIUS Users role
Management module user
Users role
Notes on access permissions
The following are notes on access permissions:
•
At least one local user of LPAR manager must be assigned the
Administrators role.
You cannot delete a local user with the Administrators role if that user is
the only user with this role.
•
If user authentication of the LP CLI is disabled, you cannot disable the
LPAR manager security permission of the management module user.
If the management module user does not have the LPAR manager
security permission, user authentication of the LP CLI cannot be disabled.
High Reliability Functions
3-17
Hitachi Compute Blade 500 Series Logical partitioning manager User's Guide