Quick Reference Guide
156 CMC Property Database Group and Object Definitions
cfgLDAPRoleGroup
NOTE: Use this object with the config or getconfig subcommands.
NOTE: To use this object property, you must have Chassis Configuration
Administrator privilege.
NOTE: You can configure any setting that is not preceded by the hash sign (#) in
the output. To modify a configurable object, use the -o option.
Description
Configures Generic LDAP Role group definitions. This object defines the
CMC privileges that LDAP-authenticated users are granted.
cfgLDAPRoleGroup is indexed, containing instances numbered from 1 to 5.
Each object instance consists of a pair of properties:
• cfgLDAPRoleGroupDN: an LDAP distinguished name (DN)
• cfgLDAPRoleGroupPrivilege: a CMC privilege map
Each LDAP-authenticated user assumes the total set of CMC privileges
assigned to the matching LDAP distinguished names that the user belongs to.
That is, if the user belongs to multiple role group DNs, the user receives all
associated privileges for those DNs.
cfgLDAPRoleGroupDN
Configures the LDAP distinguished name (DN) for the role group instance.
Example
racadm getconfig -g cfgLDAPRoleGroup -o
cfgLDAPRoleGroupDN -i 1 cn=everyone,ou=groups,dc=
openldap,dc=com
cfgLDAPRoleGroupPrivilege
Configures the CMC privilege mask (see cfgUserAdminPrivilege) for the role
group instance.
Example
racadm getconfig -g cfgLDAPRoleGroup -o
cfgLDAPRoleGroupPrivilege -i 1 0x0