3PAR InForm® OS 2.2.4 Concepts Guide (320-200085 Rev B, March 2009)

3.3
LDAP Users
InForm OS Version 2.2.4 3PAR InForm OS Concepts Guide
have privileges. Thus, a domain user’s assigned user class is applicable only within the domain
to which the user has privileges.
Table 3-2. User Class Privileges by Domain Type
For detailed information about 3PAR Domains and domain users, see Chapter 5, 3PAR Virtual
Domains. For instructions on creating a domain user, refer to the InForm OS CLI Administrator’s
Manual.
3.4 LDAP Users
Whereas local users are authenticated and authorized directly on the InServ Storage Server,
LDAP users are authenticated and authorized using information from an LDAP server. If
multiple InServ Storage Servers are configured to use the same LDAP server in the same way, a
user that can access one of the InServ servers can access all of them with the same privileges.
LDAP users’ privileges within the system are tied to the groups to which the users belong. This
User Class Privileges in Domain “All” Privileges in Domain “Specified”
Browse Browse all objects in the system.
Review the system event log.
Review system alerts.
Browse all physical system
objects.
Browse basic and derived domain
objects in the user’s specified
domain.
Edit All Browse user class privileges.
Create hosts.
Modify hosts.
Create CPGs.
Create VVs.
Create VLUNs.
Create Remote Copy links and
settings.
All Browse user class privileges.
Create VVs using CPGs in the
user’s specified domain.
Modify, grow, update, and
remove VVs.
Create and promote snapshots.
Create physical copies of VVs.
Create and assign VVs to Remote
Copy domains.
Create and remove host sees and
matched set VLUNs.
Modify hosts properties.