Article
A Forum reader recently asked:
"Now that I have Storage Manager installed and running, I don't see any way to delegate authority to container
administrators. It seems that anyone logged into the Management Interface gets rights via the NSMProxy users (supervisor to root) and can administer all servers and users in the tree. Is there any RBS equivalent for NSM
where I can delegate rights only to specific containers for specific users?"
Solution
Setting up a delegated Admin in NSM has several steps:
1. Create a group in eDirectory that you can use for creating a membership of the users that you want to be able to log in via the NSMAdmin interface.
2. Set up a container-based administrative user, if not already done.
3. Open NSMAdmin and log in with a user that has Supervisor rights to the server object where NSM (FSFENGIN.NLM) is running.
4. Click Configure Options and Interfaces.
5. Click Management Interface.
6. Check the checkbox next to the "Security Equivalent to the following object" option.
7. Click Browse and select the group that you created in
step 1. Make sure that your overall admin user is in the group as a minimum.
8. Click OK.
9. Log out of NSMAdmin and log back in as one of the delegated admin users that you added to the group created in step 1.
Testing:
1. Try to create a policy outside the container where the user has rights. Access should be denied.
2. Try to create a policy inside the container where the user has rights. The policy should be created.
Disclaimer: As with everything else at Cool Solutions, this content is definitely not supported by Novell (so don't even think of calling Support if you try something and it blows up).
It was contributed by a community member and is published "as is." It seems to have worked for at least one person, and might work for you. But please be sure to test, test, test before you do anything drastic with it.
Related Articles
User Comments
Granular Management in AD for Storage Manager?
Submitted by HutcH on 7 May 2008 - 7:51am.
Is there a similar method to do this in AD?
- Be the first to comment! To leave a comment you need to Login or Register


1