User's Manual

Table Of Contents
2
Dell Management Plug-in Configuration
The following sections provide step-by-step instructions for the Dell Management Plug-in initial configuration and
compliance. Upgrade, uninstallation, and security role information are also covered in the following sections.
Security Roles And Permissions
The Dell Management Plug-in encrypts and stores sensitive user credential information. It does not provide any
passwords to client applications to avoid any improper requests that could lead to issues. The database back-ups are
fully encrypted using custom security phrases, and therefore the data cannot be misused.
Data Integrity
Communication between the Dell Management Plug-in, virtual appliance, administration console, and vCenter is
accomplished using SSL/HTTPS. The Dell Management Plug-in generates an SSL certificate used for trusted
communication between vCenter and the appliance. It also verifies and trusts the vCenter server's certificate before
communication and the Dell Management Plug-in registration. The Dell Administration Portal uses security procedures
to avoid improper requests while the keys are transferred back and forth from the administration console and back-end
services. This type of security causes cross-site request forgeries to fail.
A secure administration console session has a five minute idle timeout, and the session is only valid in the current
browser window and/or tab. If the user tries to open the session in a new window or tab, a security error is created that
asks for a valid session. This action also prevents the user from clicking any malicious URL that could try to attack the
administration console session.
Figure 2. Error Message
Access Control Authentication, Authorization, And Roles
The Dell Management Plug-in uses the vSphere Client's current user session and the stored administration credentials
for the virtual appliance to perform vCenter operations. The administration and the virtual appliance consoles are also
accessible by using a strong administration password. The Dell Management Plug-in uses the vCenter server's built-in
roles and privileges model to authorize user actions with the virtual appliance and the vCenter managed objects (hosts
and clusters).
11