Preetam's profileVirtualization = > VMWar...BlogListsNetwork Tools Help

Blog


    February 21

    VirtualCenter Security Model

    Now that we have installed virtual center, next steps would be assigning permission to all those people who are responsible for managing managing VMware Infra 3.0. In order to do that we need to understand how the permissioning works. There are two elements in this, First is ESX host and other is Virtual Center. Permissioning on both these element is seperate and cannot be mix with eachother. For simple reason, one is Linux and other is Windows.

    Security Model explained.

    Let take user Greg, who works in first line support and need maximum rights to shutdown VM in case it hangs or user request.

    Greg ------->Needs to Reset VM's ------->To achieve this we need to assign permission

    [ User ]                [ROLE ]                                      [Priviliges]

     

    1. Needs to Reset VM's = TASK [ROLE]
    2. In order to do the TASK=Need to assign Permissions
    3. USER

    All three makes Permissions in VMWare and in all security model. However to little bit more to it, permission is also a combination of user account, Role,priviliges and position in the inventory to which the user/role applies.

    Now Greg can be restricted to do Datacenter, VM. We can decide whether we need same permissions to flown across the datacenter or to specific folder. This is called as propogations of permissions. VMware has come with pre-defined roles, these roles are can been seen when you assign permission. You have the option of selecting the pre-defined roles or create one for yourself. But these pre-defined roles are again differ from ESX and Virtual Center perspective.

    Predefined ESX Servers Roles:

    1. No Access
    2. Read-Only
    3. Administrator

    Predefined Virtual Center Roles:+ Predefined ESX Servers Roles

    1. VM Administrator
    2. Datacenter Administrator
    3. Virtual Machine Power User
    4. Virtual Machine User
    5. Resource Pool Administrator

    But customs roles can be created for both ESX aswell VC.

     

     

    Virtual Center Security Model:

    Virtual center security model includes accounts created in Windows which could be local or domain account. This account is again assigned role which is again decided at what heirarchy you apply this role. Default permission for VC is assigned to local Administrators groups of Windows 2003 server at the top level in the inventry.

    ESX Security Model:

    ESX security model includes user account created on ESX Server which is basically a linux user account. This account is again assigned role which is again decided at what heirarchy you apply this role. By default vpxuser and root are already created and assigned to administrator roles. Vpxuser is used for interacting ESX server. Root is admin account and performs task  assigned by virtual center.

     

    Step-by-Step process of assigning permissions:

    Select object on which you wish to apply permisison.

    Expand the inventory

    Right the click object, select add permission

    Select role to be select from predefined list or select custom roles

    Select if you wish to propogate the permission to child objects

    Select user (Local/Domain) user

    Add the user to users or group fields

     In order to create custom roles, go to the admin tab, right anywhere

    Name the role and select priviliges you wish to give it to the role

    There is lot in permissioning, I will update that later on

    Comments (4)

    Please wait...
    Sorry, the comment you entered is too long. Please shorten it.
    You didn't enter anything. Please try again.
    Sorry, we can't add your comment right now. Please try again later.
    To add a comment, you need permission from your parent. Ask for permission
    Your parent has turned off comments.
    Sorry, we can't delete your comment right now. Please try again later.
    You've exceeded the maximum number of comments that can be left in one day. Please try again in 24 hours.
    Your account has had the ability to leave comments disabled because our systems indicate that you may be spamming other users. If you believe that your account has been disabled in error please contact Windows Live support.
    Complete the security check below to finish leaving your comment.
    The characters you type in the security check must match the characters in the picture or audio.

    To add a comment, sign in with your Windows Live ID (if you use Hotmail, Messenger, or Xbox LIVE, you have a Windows Live ID). Sign in


    Don't have a Windows Live ID? Sign up

    No namewrote:
    http://www.toplaptopbatteries.com/asus/a42-m6.htm asus a42-m6 battery
    http://www.toplaptopbatteries.com/asus/m6000.htm asus m6000 battery
    http://www.toplaptopbatteries.com/mitac/bp-8050.htm mitac bp-8050 battery
    http://www.toplaptopbatteries.com/sony/pcga-bp2t.htm sony pcga-bp2t battery
    http://www.toplaptopbatteries.com/asus/a42-a2.htm asus a42-a2 battery
    http://www.toplaptopbatteries.com/asus/a2000.htm asus a2000 battery
    http://www.toplaptopbatteries.com/asus/a4000.htm asus a4000 battery
    http://www.toplaptopbatteries.com/asus/a42-v6.htm asus a42-v6 battery
    http://www.toplaptopbatteries.com/asus/v6000.htm asus v6000 battery
    http://www.toplaptopbatteries.com/uniwill/un223.htm uniwill un223 battery
    http://www.toplaptopbatteries.com/uniwill/223-3s4000-f1p1.htm uniwill 223-3s4000-f1p1 battery
    http://www.toplaptopbatteries.com/uniwill/258-4s4400-s1p1.htm uniwill 258-4s4400-s1p1 battery
    http://www.toplaptopbatteries.com/uniwill/258-4s4400-s2m1.htm uniwill 258-4s4400-s2m1 battery
    http://www.toplaptopbatteries.com/hp/mini-1000.htm hp mini 1000 battery
    http://www.toplaptopbatteries.com/hp/zt3300.htm hp zt3300 battery
    http://www.toplaptopbatteries.com/acer/aspire-9300.htm acer aspire 9300 battery
    http://www.toplaptopbatteries.com/acer/travelmate.htm acer travelmate battery
    http://www.toplaptopbatteries.com/acer/5100-aspire-7000.htm acer 5100 aspire 7000 battery
    http://www.toplaptopbatteries.com/acer/aspire-7100.htm acer aspire 7100 battery
    http://www.toplaptopbatteries.com/toshiba/pa3366u-1brs.htm toshiba pa3366u-1brs battery
    http://www.toplaptopbatteries.com/toshiba/satellite-a30-921.htm toshiba satellite a30-921 battery
    http://www.toplaptopbatteries.com/toshiba/pa3285u-1bas.htm toshiba pa3285u-1bas battery
    http://www.toplaptopbatteries.com/toshiba/pa3285u-1brs.htm toshiba pa3285u-1brs battery
    http://www.toplaptopbatteries.com/toshiba/pa3285u-3bas.htm toshiba pa3285u-3bas battery
    http://www.toplaptopbatteries.com/acer/batcl50l4.htm acer batcl50l4 battery
    http://www.toplaptopbatteries.com/acer/travelmate-290.htm acer travelmate 290 battery
    http://www.toplaptopbatteries.com/apple/a1045.htm apple a1045 battery
    http://www.toplaptopbatteries.com/asus/a42-a4.htm asus a42-a4 battery
    http://www.toplaptopbatteries.com/asus/a4.htm asus a4 battery
    http://www.toplaptopbatteries.com/compaq/383510-001.htm compaq 383510-001 battery
    http://www.toplaptopbatteries.com/dell/latitude-d810.htm dell latitude d810 battery
    http://www.toplaptopbatteries.com/dell/1210.htm dell 1210 battery
    http://www.toplaptopbatteries.com/hp/dv8200.htm hp dv8200 battery
    http://www.toplaptopbatteries.com/acer/batecq60.htm acer batecq60 battery
    http://www.toplaptopbatteries.com/hp/dv9600.htm hp dv9600 battery
    http://www.toplaptopbatteries.com/acer/lcbtp03003.htm acer lcbtp03003 battery
    http://www.toplaptopbatteries.com/compaq/nx9020.htm compaq nx9020 battery
    http://www.toplaptopbatteries.com/toshiba/pa3689u-1bas.htm toshiba pa3689u-1bas battery
    http://www.toplaptopbatteries.com/toshiba/satellite-p205.htm toshiba satellite p205 battery
    http://www.toplaptopbatteries.com/acer/um08a71.htm acer um08a71 battery
    http://www.toplaptopbatteries.com/acer/um08a72.htm acer um08a72 battery
    http://www.toplaptopbatteries.com/dell/m1530.htm dell m1530 battery
    http://www.toplaptopbatteries.com/gateway/s62066l.htm gateway s62066l battery
    Oct. 27
    No namewrote:

    Hi,Do you have used LCDs, second hand LCDs, used flat screens and used LCD monitors? Please go here:www.sstar-hk.com(Southern Stars).We are constantly buying re-usable LCD panels and working for LCD recycling.The re-usable panels go through strictly designed process of categorizing, checking, testing, repairing and refurbishing before they are re-used to make remanufactured LCD displays and TV sets.Due to our recent breakthrough in testing and repairing technology of LCD, we can improve the value for your LCD panels. website:www.sstar-hk.com[baigchaedgihgfj]

    Oct. 25
    No namewrote:

    Hi,Do you need advertising displays, screen advertisings, digital sign, digital signages and LCDs? Please go Here:www.amberdigital.com.hk(Amberdigital).we have explored and developed the international market with professionalism. We have built a widespread marketing network, and set up a capable management team dedicated to provide beyond-expectation services to our customers.

    amberdigital Contact Us

    website:www.amberdigital.com.hk
    alibaba:amberdigital.en.alibaba.com[gbcghiaaedjbjh]

    Sept. 29
    No namewrote:

    Hi,Do you have used LCDs, used flat screens and secondhand LCDs? Please go here:www.sstar-hk.com(Southern Stars).We are constantly buying re-usable LCD panels and working for LCD recycling.The re-usable panels go through strictly designed process of categorizing, checking, testing, repairing and refurbishing before they are re-used to make remanufactured LCD displays and TV sets.Due to our recent breakthrough in testing and repairing technology of LCD, we can improve the value for your LCD panels.

    Contact Us

    E-mail:sstar@netvigator.com
    website:www.sstar-hk.com

    Sept. 11

    Trackbacks

    The trackback URL for this entry is:
    http://esxvmware.spaces.live.com/blog/cns!ED5F1BBA39EF2CC1!241.trak
    Weblogs that reference this entry
    • None