
VMware, Inc. 33
5
Securityoperationsareoftenmanagedbymultipleindividuals.Managementoftheoverallsystemis
delegatedtodifferentpersonnelaccordingtosomelogicalcategorization.However,permissiontocarryout
tasksislimitedonlytouserswithappropriaterightstospecificresources.FromtheUserssection,youcan
delegatesuchresourcemanagementto
usersbygrantingapplicablerights.
UsermanagementinthevShieldManageruserinterfaceisseparatefromusermanagementintheCLIofany
vShieldcomponent.
Thischapterincludesthefollowingtopics:
“ManagingUserRights”onpage 33
“A d d aUser”onpage 34
“A s s i g n aRoleandRightstoaUser”onpage 34
“EditaUserAccount”onpage 34
“DeleteaUserAccount”onpage 35
Managing User Rights
WithinthevShieldManageruserinterface,auser’srightsdefinetheactionstheuserisallowedtoperformon
agivenresource.Rightsdeterminetheuser’sauthorizedactivitiesonthegivenresource,ensuringthatauser
hasaccessonlytothefunctionsnecessarytocompleteapplicableoperations.Thisallowsdomaincontrol
over
specificresources,orsystem‐widecontrolifyourrightencompassestheSystemresource.
Thefollowingrulesareenforced:
Ausercanonlyhaveonerighttooneresource.
Ausercannotaddtoorremoveassignedrightsandresources.
User Management
5
Table 5-1. vShield Manager User Rights
Right Description
RReadonly
CRUD ReadandWrite
Table 5-2. vShield Manager User Resources
Resource Description
System AccesstoentirevShieldsystem
Datacenter Accesstoaspecifieddatacenterresource
Cluster Accesstoaspecifiedclusterresource
None Accesstonoresources
Comentarios a estos manuales