<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SimpliVity User Access and RBAC in HPE SimpliVity</title>
    <link>https://community.hpe.com/t5/hpe-simplivity/simplivity-user-access-and-rbac/m-p/7181131#M3800</link>
    <description>&lt;P&gt;Hi BJST&lt;/P&gt;&lt;P&gt;I've currently a similar issue with RBAC and restore.&lt;/P&gt;&lt;P&gt;My goal is to have the local ISRs in a role without "remove/delete" rights, so that they can no screw up their site.&lt;/P&gt;&lt;P&gt;It looks acutally as if ther is a bug. Even if I assign the group to a role (with nearly all rights) the plugin (SVT actions) requests the Admin role. ...&lt;BR /&gt;Ive tested id and gave global perm to a user with a manually created admin role (all flags checked). also added the user with the PS commant (wich is a pain) and still no success....changing the admin role to the built in admin role works immediately..&lt;/P&gt;&lt;P&gt;So I created a case at HPE...i will post stuff asap ...&lt;/P&gt;&lt;P&gt;cheers&lt;/P&gt;</description>
    <pubDate>Thu, 19 Jan 2023 11:05:35 GMT</pubDate>
    <dc:creator>egoqed</dc:creator>
    <dc:date>2023-01-19T11:05:35Z</dc:date>
    <item>
      <title>SimpliVity User Access and RBAC</title>
      <link>https://community.hpe.com/t5/hpe-simplivity/simplivity-user-access-and-rbac/m-p/7181035#M3796</link>
      <description>&lt;P&gt;Hej,&lt;/P&gt;&lt;P&gt;I got the situation that a customer has several SimpliVity Clusters in one Federation spread over several locations (countries).&lt;/P&gt;&lt;P&gt;We want to limit the access of the local operator to their specific cluster. This is no problem for all Vmware related operations but they also should be able to to restores and backups out of the simpliVity. It looks like there is no problem related to the RBAC as restores work perfectly IF they have access to the actual OVC holding the connection to the plugin. Due to the accessright in VCenter this is only given if this OVC is in their location (as they don't have access to other locations).&lt;/P&gt;&lt;P&gt;1. What access rights are required in minimum on the OVC to get the plugin running?&lt;/P&gt;&lt;P&gt;2. If I plan to deploy a MVA (which would make it easier as long as it is runnning) what is the needed access there&lt;/P&gt;&lt;P&gt;rgds&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jan 2023 05:41:27 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-simplivity/simplivity-user-access-and-rbac/m-p/7181035#M3796</guid>
      <dc:creator>BJST</dc:creator>
      <dc:date>2023-01-20T05:41:27Z</dc:date>
    </item>
    <item>
      <title>Re: SimpliVity User Access and RBAC</title>
      <link>https://community.hpe.com/t5/hpe-simplivity/simplivity-user-access-and-rbac/m-p/7181039#M3797</link>
      <description>&lt;P style="margin: 0;"&gt;Hello BJST&lt;BR /&gt;&lt;BR /&gt;You may refer the following link:&lt;BR /&gt;&lt;BR /&gt;&lt;A&gt;1.&lt;STRIKE&gt;https://support.hpe.com/hpesc/public/docDisplay?docId=sf000069884en_us&lt;/STRIKE&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P style="margin: 0;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0;"&gt;&lt;FONT size="2"&gt;[&lt;U&gt;Moderator edit&lt;/U&gt;: Removed the broken link. You may refer to&amp;nbsp;&lt;A href="https://support.hpe.com/" target="_blank"&gt;https://support.hpe.com/&lt;/A&gt;]&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 06:33:29 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-simplivity/simplivity-user-access-and-rbac/m-p/7181039#M3797</guid>
      <dc:creator>support_s</dc:creator>
      <dc:date>2024-08-23T06:33:29Z</dc:date>
    </item>
    <item>
      <title>Re: SimpliVity User Access and RBAC</title>
      <link>https://community.hpe.com/t5/hpe-simplivity/simplivity-user-access-and-rbac/m-p/7181040#M3798</link>
      <description>&lt;P&gt;Thank you for the link but (of course I know that):&lt;/P&gt;&lt;P&gt;1. it's outdated as with OVC-Code higher than 4.1 RBAC must be set with powershell (svt-rbac... is no longer available). And there is no problem with rbac this works fine.&lt;/P&gt;&lt;P&gt;2. the role of the specific user in the VMware environment can NOT be administrator and of course not global-Administrator in this case. This is not acceptable as described&lt;/P&gt;&lt;P&gt;The problem is that the connection OVC-Plugin is only available on one OVC and this may not be in the cluster a specific user has access to. So what accessright is in minimum needed to see the simplivity plugin functions if the user is in clusterA and the related OVC in ClusterB&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jan 2023 10:26:30 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-simplivity/simplivity-user-access-and-rbac/m-p/7181040#M3798</guid>
      <dc:creator>BJST</dc:creator>
      <dc:date>2023-01-18T10:26:30Z</dc:date>
    </item>
    <item>
      <title>Re: SimpliVity User Access and RBAC</title>
      <link>https://community.hpe.com/t5/hpe-simplivity/simplivity-user-access-and-rbac/m-p/7181131#M3800</link>
      <description>&lt;P&gt;Hi BJST&lt;/P&gt;&lt;P&gt;I've currently a similar issue with RBAC and restore.&lt;/P&gt;&lt;P&gt;My goal is to have the local ISRs in a role without "remove/delete" rights, so that they can no screw up their site.&lt;/P&gt;&lt;P&gt;It looks acutally as if ther is a bug. Even if I assign the group to a role (with nearly all rights) the plugin (SVT actions) requests the Admin role. ...&lt;BR /&gt;Ive tested id and gave global perm to a user with a manually created admin role (all flags checked). also added the user with the PS commant (wich is a pain) and still no success....changing the admin role to the built in admin role works immediately..&lt;/P&gt;&lt;P&gt;So I created a case at HPE...i will post stuff asap ...&lt;/P&gt;&lt;P&gt;cheers&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 11:05:35 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-simplivity/simplivity-user-access-and-rbac/m-p/7181131#M3800</guid>
      <dc:creator>egoqed</dc:creator>
      <dc:date>2023-01-19T11:05:35Z</dc:date>
    </item>
    <item>
      <title>Re: SimpliVity User Access and RBAC</title>
      <link>https://community.hpe.com/t5/hpe-simplivity/simplivity-user-access-and-rbac/m-p/7181661#M3805</link>
      <description>&lt;P&gt;&lt;a href="https://community.hpe.com/t5/user/viewprofilepage/user-id/2018834"&gt;@BJST&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Don't deploy a MVA. Support from HPE does not recommend it anymore.&lt;/P&gt;&lt;P&gt;BTW. still working on my case but it seems quite different. cause some of the AD groups are working and some not.&lt;/P&gt;&lt;P&gt;if i get more info i will post an update&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2023 13:40:13 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-simplivity/simplivity-user-access-and-rbac/m-p/7181661#M3805</guid>
      <dc:creator>egoqed</dc:creator>
      <dc:date>2023-01-26T13:40:13Z</dc:date>
    </item>
    <item>
      <title>Re: SimpliVity User Access and RBAC</title>
      <link>https://community.hpe.com/t5/hpe-simplivity/simplivity-user-access-and-rbac/m-p/7194731#M4289</link>
      <description>&lt;P&gt;Is there any further inovation taking place on RBAC?&lt;/P&gt;&lt;P&gt;have a new issue that I want to have users accessing the Vcenter read only but (due the lack of roles) give them access to the SimplIvity as administrator.&lt;/P&gt;&lt;P&gt;This fails always in a manner that the OVC denies the access to this group. As soon as I add the users (domain users) to the administrators group in vsphere.local access works.&lt;/P&gt;&lt;P&gt;For me it looks like RBAC is still unusable!&lt;/P&gt;&lt;P&gt;So maybe the development team starts to think about security in these days...&lt;/P&gt;&lt;P&gt;It would be great to have access to the OVC as well for all svt-...-show commands for such users..&lt;/P&gt;</description>
      <pubDate>Tue, 22 Aug 2023 16:00:24 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-simplivity/simplivity-user-access-and-rbac/m-p/7194731#M4289</guid>
      <dc:creator>BJST</dc:creator>
      <dc:date>2023-08-22T16:00:24Z</dc:date>
    </item>
    <item>
      <title>Re: SimpliVity User Access and RBAC</title>
      <link>https://community.hpe.com/t5/hpe-simplivity/simplivity-user-access-and-rbac/m-p/7223448#M4941</link>
      <description>&lt;P&gt;We have the same issue. It seems as the user must be administrator in the topmost object in vcenter in order to see the content (backups) in the Simplivity Plugin otherwise the backups are not displayed. We've followed the guide&amp;nbsp;&lt;A href="https://support.hpe.com/hpesc/public/docDisplay?docId=sd00004275en_us&amp;amp;page=GUID-5CC8F9B5-E483-40C6-B853-1D7C983EA713.html" target="_blank"&gt;Assign vCenter Server groups to HPE OmniStack roles | HPE OmniStack 5.0.0 for vSphere Administration Guide&lt;/A&gt;&amp;nbsp;but cannot get it running without having to assign high privileges to the user.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Sep 2024 09:09:31 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-simplivity/simplivity-user-access-and-rbac/m-p/7223448#M4941</guid>
      <dc:creator>mataew</dc:creator>
      <dc:date>2024-09-16T09:09:31Z</dc:date>
    </item>
    <item>
      <title>Re: SimpliVity User Access and RBAC</title>
      <link>https://community.hpe.com/t5/hpe-simplivity/simplivity-user-access-and-rbac/m-p/7223549#M4944</link>
      <description>&lt;P&gt;&lt;SPAN class=""&gt;&lt;A href="https://community.hpe.com/t5/user/viewprofilepage/user-id/2336177" target="_self"&gt;&lt;SPAN class=""&gt;Hej mataew,&lt;/SPAN&gt;&lt;/A&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;It's a pitty but the only way you can manage that (which at least worked for me):&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;RBAC is based on the &lt;STRONG&gt;Role name&lt;/STRONG&gt; used in the VCenter. So there are only two possibilities. Administrator and BackupUser&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;I created a Role named BackupUser and gave alle the needed permissions for the Vcenter, ESX and VMs to that role (basically Operator Roles and the defined Roles to use Simplivity backups). This Role I mapped to the SimpliVity RBAC BackupUser.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Then these users can do all SimpliVity actions except: creating Datastores, shutdown controller, login to CLI and similar administrative tasks. For most of my customers that is fine as these are not the daily business tasks.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;I also had a request open to HPe that in our time this is not a usefull manner how to make role based access as there must be a more granular set of permissions. Easiest but already helpfull would be to a&lt;STRONG&gt;ssign Groups to the Role&lt;/STRONG&gt; then different VCenter Groups could have the same Simplivity Role (as well administrator). But this is out of their interesst at it looks like.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Hope this helps&lt;/P&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Fri, 23 Aug 2024 07:00:11 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-simplivity/simplivity-user-access-and-rbac/m-p/7223549#M4944</guid>
      <dc:creator>BJST</dc:creator>
      <dc:date>2024-08-23T07:00:11Z</dc:date>
    </item>
  </channel>
</rss>

