HP Systems Insight Manager 5.3 Installation and Configuration Guide for Windows HP Part Number: 418812-005

3. Set the Default timeout and the Default retries. If some systems are managed over a WAN or satellite
link, use a longer time-out (for example, five seconds) with at least one retry. For a LAN, you can use
a shorter time-out. You can configure this setting on a single-system basis.
4. In the WBEM settings section, verify that Enable WBEM (the default) is selected to allow
WBEM
requests to be sent.
To access the Global Credentials page, select Go to the Global Credentials page to set global
WBEM certificates.
OpenWBEM is not supported.
5. In the HTTP settings section, select Enable HTTP and HTTPS if you need web-based agents and
other HTTP port scans to be identified. HP recommends leaving this option enabled for proper
management and discovery of systems.
6. In the SNMP settings section, verify that Enable SNMP (the default) is selected and specify values for
Default time out and Default retries. For systems managed over a WAN or satellite link, use a larger
time-out (for example, five seconds) with at least one retry. For a LAN, a shorter time-out can be used.
You can configure these settings on a single-system basis.
To access the Global Credentials page, select Go to the Global Credentials page to set global
SNMP community strings.
7. In the Read community string field, enter up to 10 read community strings. This value is case-sensitive.
The identification process attempts communication with a system, using each of these communities in
succession until a successful response is obtained. Future SNMP requests then use the community string
that provided a successful response.
If you have SNMP systems and no read community string that match the systems entered into HP SIM
through Global Protocol Settings or System Settings, the systems are not discovered.
8. In the WS-MAN settings section, verify that WS-MAN is enabled and enter a Default identity timeout.
9. In the SSH settings section, select Enable SSH to enable SSH identification to run on managed
systems.
10. (Optional) In the DMI settings section, select Enable DMI, to enable DMI identification to run on
managed systems. DMI is used to manage some older desktops, HP-UX 11.0 servers, and some third-party
servers. If you do not need to manage these kinds of systems, you can disable DMI to improve discovery
performance. DMI is not enabled by default.
DMI is not currently supported on Linux systems and does not appear in the user interface.
If DMI is disabled and some systems no longer have a correct system type or product name, re-enable
DMI.
11. Click OK to accept the settings.
Users and authorizations
NOTE:
Users
that have been added to the
Central Management Server
(CMS) cannot view or manage
systems until
authorizations
have been configured for them.
NOTE: HP-UX and Linux-provided command line tools, such as ls and df, are run as root by default. For
security reasons, you might want them to run as a specific user to avoid permitting unintended capabilities
to a user.
HP Systems Insight Manager (HP SIM) enables you to configure authorizations for specific users or user
groups. Authorizations give the user access to view and manage systems. Each authorization specifies a
user or user group, a toolbox, and a system or system group. The specific set of tools that can be run against
a system is specified in the assigned toolbox.
It is important that you plan which systems each user is going to manage and which specific set of
tools
the
users are authorized to execute against the managed systems. A user with no toolbox authorizations on a
system cannot view or manage that system.
Authorizations are additive. If a user is authorized on Toolbox1 on a system and is also authorized for
Toolbox2 on the same system, the user is authorized for all tools in both Toolbox1 and Toolbox2 on that
system. Similarly, a user authorized for the All Tools toolbox needs no other toolbox authorization on that
system because the All Tools toolbox always includes all tools.
Users and authorizations 53