Hardware manual

Group Administration Group security
4–8
You want to create a volume administrator account. You must specify the EQL-Admin attribute, the EQL-
Pool-Access
attribute, and (optionally) the EQL-Replication-Site-Access attribute.
You want to create a read-only account. You must specify the
EQL-Admin attribute and the EQL-Admin-
Account-Type
attribute.
You plan to select the
Require vendor-specific RADIUS attribute option when you configure the
group to use a RADIUS authentication server. You must specify the
EQL-Admin attribute.
Table 4-6 describes the Dell vendor-specific attributes for RADIUS
attributes, and lists their possible values.
Table 4-6: Vendor-Specific Attributes
Attribute Field Required Value
EQL-Admin-Privilege
Specifies that the account is a group administrator account or a
pool adm
inistrator account.
The RADIUS server must return the value of this attribute to
the
group in the Access-Accept message.
VSA vendor ID 12740
VSA number 6
VSA syntax Decimal (0 fo
r gro
up administrator;
1 for pool administrator; 2 for pool
administrator with read access to the
entire group; 3 for volume
administrator).
To create a read-only account, set the
EQL-
Admin
attribute to 0 and the
EQL-Admin-Account-Type
attribute to RO.
Admin-Pool-Access
Specifies the pools to which the pool administrator account has
access
and, for volume
administrators, the account’s storage
within that pool.
Required if the value of the EQL-Admin at
tri
bute is 1 (pool
administrator account) or 3 (volume administrator account).
The quota for volume administration accounts is expressed as
PoolName Quota
, with gb and mb appended to the quota
representing GB and MB, respectively.
For example: Pool1 25gb sets the qu
ota for Pool
1 to 25GB,
and Pool1 500mb sets a quota of 500MB. Use
unlimited to set an unlimited quota for the pool, e.g.
Pool1 unlimited. If no unit is specified, the default
capacity unit is MB.
VSA vendor ID 12740
VSA number 7
VSA syntax String (comma-separated list of
pools; 3 to 247
characters
)
Admin-Repl-Site-Access
Specifies the sites to which the volume administrator can
replicate volumes. Required if th
e value of the EQL-Admin
attribute is 3 (volume administrator account). Used only for
volume administrators.
VSA vendor ID 12740
VSA number 8
VSA syntax String (comma-separated list of sites;
3 to 249
characters)
Admin-Account
-Type
Specifies whether the account is read-only (RO) or
read-write
(RW):
VSA vendor ID 12740
VSA number 9
VSA syntax RO or RW
Admin-Full-Name
(Optional) Name of the administrator using the account.
VSA vendor ID 12740
VSA number 1
VSA syntax String (3 to 247 characters)