Setup Guide
Broadcom OCM-CLI-LPE-UG124-100
10
Emulex OneCommand Manager Command Line Interface User Guide
1.2 OneCommand Manager Secure Management
OneCommand Manager Secure Management enables system administrators to further enhance the active management
security of their networks. Using Secure Management, administrators can define each user's privileges for managing both
local and remote adapters. When running in Secure Management mode, users must specify their user name and password
to run the OneCommand Manager CLI. When users are authenticated, only they can perform the functions allowed by the
OneCommand Manager user group to which they belong. If your systems are running in an LDAP or Active Directory
domain, the OneCommand Manager CLI will authenticate the user with those defined in that domain. For Linux and Solaris
systems, this is accomplished using PAM.
NOTE: OneCommand Manager Secure Management is supported on Linux, Solaris, and Windows, but it is not supported
on VMware hosts. For VMware hosts, the CIM credentials are used.
Administrators set up user accounts such that a user belongs to one of the OneCommand Manager user groups. The user
groups define the management capabilities for the user. Tab le 1 defines the OneCommand Manager user groups and each
group's management capabilities.
QSFP quad small form-factor pluggable
RHEL Red Hat Enterprise Linux
Rx receive
SAN storage area network
SCSI Small Computer Systems Interface
SFCB Small Footprint CIM Broker
SFP small form-factor pluggable
SLES SUSE Linux Enterprise Server
TCP Transmission Control Protocol
Tx transmit
UEFI Unified Extensible Firmware Interface
VLAN virtual local area network
VLAN ID VLAN identifier
VPD vital product data
vPort virtual port
WWN World Wide Name
WWNN World Wide Node Name
WWPN World Wide Port Name
XML Extensible Markup Language
Table 1: Secure Management User Privileges
Group Name OneCommand Manager Capability
ocmadmin Allows full active management of local and remote adapters
ocmlocaladmin Permits full active management of local adapters only
ocmuser Permits read-only access of local and remote adapters
ocmlocaluser Permits read-only access of local adapters