Hardware Management Console Best Practices
- 27 -
406-
520*10007CA|IBMHSC_Partition,lpar:root/ibmhscS1_0|3*9
406-
520*10007CA|IBMHSC_Partition,lpar:root/ibmhscS1_0|6*9
406-
520*10007CA|IBMHSC_Partition,lpar:root/ibmhscS1_0|2*9
406-
520*10007CA|IBMHSC_Partition,lpar:root/ibmhscS1_0|10*
9406-
520*10007CA|IBMHSC_Partition,lpar:root/ibmhscS1_0|9*9
406-
520*10007CA|IBMHSC_Partition,lpar:root/ibmhscS1_0|5*9
406-
520*10007CA|IBMHSC_Partition,lpar:root/ibmhscS1_0|1*9
406-
520*10007CA|IBMHSC_Partition,lpar:root/ibmhscS1_0|8*9
406-
520*10007CA|IBMHSC_Partition,lpar:root/ibmhscS1_0|4*9
406-520*10007CA|IBMHSC_Partition"
• lsaccfg -t taskrole shows a list of accessible (by this role) tasks
separated by a ‘+’ following the resource type they operate on.
You can create customized HMC roles by modifying predefined HMC roles.
Creating customized HMC roles is useful for restricting or granting specific task
privileges to a certain user. Through the GUI this can be accomplished when you
add or copy a managed resource or task role. Through the restricted shell, you
can use the mkaccfg or chaccfg commands. These tasks can only be
performed by a user with an hmcsuperadmin role. Note that this does not
mean a user with the just the hmcsuperadmin task role, but any user whose
task role is a customized one with hmcsuperadmin as the parent task role with
the appropriate GUI and CLI tasks grouped in.
Below are some examples of using the mkaccfg command:
# create a resource role for LPAR ID 9
# note the ‘\’ escape character preceding a ‘|’
hscroot@myhost:~> mkaccfg -t resourcerole -i
"name=hscroot_group_orig,resources=lpar:root/ibmhscS1_
0\|9*9406-520*10007CA\|IBMHSC_Partition"
# create a resource role for a managed system
hscroot@myhost:~> mkaccfg -t resourcerole -i
"name=nonhscroot_group,resources=cec:root/ibmhscS1_0\|
9406-520*10007CA\|IBMHSC_ComputerSystem
Komentáře k této Příručce