Hardware Management Console Best Practices
- 25 -
5.2 Task and Managed Resource Roles
As mentioned in the introduction to this section, a role is a way of grouping
access privileges. On the HMC, roles are divided into two classes: task roles and
managed resource roles.
A task role is a grouping of tasks, carried out either through WebSM or the
Command Line Interface (CLI.) A managed resource role, which is also referred
to as a resource role, is a grouping of resource types and/or resource instances,
e.g. managed frames, managed systems and logical partitions. When specific
partitions or servers are selected for a customized resource role, a user with this
role can view and affect only those managed system.
On the HMC console view, the managed system must be visible under Server
Management for specific partitions to be viewable to users with a specific role.
Resources are viewed hierarchically. Thus, in this example the CLI would allow
the managed system to be listed, but both the GUI and CLI would not allow any
tasks outside of property views to be executed on the managed system unless they
were authorized in the custom role definition. If a specific partition was selected
in the resource role, partition views would be restricted to that logical partition.
As mentioned in the previous section, when creating a user you must specify a
task role and one more resource roles. The HMC comes predefined with the
following five task roles:
• hmcsuperadmin - The super administrator acts as the root user, or manager,
of the HMC system. The super administrator has unrestricted authority to
access and modify most of the HMC system. This should not be confused with
user root.
• hmcservicerep - A service representative is generally someone physically at
the managed system location to install, configure or repair managed systems.
• hmcoperator - An operator is responsible for daily system operation.
• hmcpe - A product engineer assists in support situations (for both the managed
system and the HMC), but cannot access HMC user management functions. To
provide support with access for your system, you must create and administer
user IDs with the product engineer role; see section on Problem Determination.
• hmcviewer - A viewer can view HMC information, but cannot change any
configuration information.
In addition, the HMC comes predefined with the AllSystemResources resource
role. This is a dynamic resource role in that it is a container for all defined
resources at any instance; it is not a static grouping of resources. This name is
only defined for the graphical interface. It is not a recognized attribute by the
command line interface:
Komentáře k této Příručce