Users Guide

Table Of Contents
Security roles and permissions
The OpenManage Integration for VMware vCenter stores user credentials in an encrypted format. It does not provide any passwords to
client applications to avoid any improper requests. The backup database is fully encrypted by using custom security phrases, and hence
data cannot be misused.
By default, users in the Administrators group have all the privileges. The Administrators can use all the functions of the OpenManage
Integration for VMware vCenter within VMware vSphere web client. If you want a user with necessary privileges to manage the product,
do the following:
1. Create a role with necessary privileges
2. Register a vCenter server by using the user
3. Include both the Dell roles, Dell operational role and Dell infrastructure deployment role.
Topics:
Data integrity
Access control authentication, authorization, and roles
Dell Operational role
Dell Infrastructure Deployment role
About privileges
Data integrity
The communication between the OpenManage Integration for VMware vCenter, Administration Console, and vCenter is accomplished by
using SSL/HTTPS. The OpenManage Integration for VMware vCenter generates an SSL certificate that is used for trusted
communication between vCenter and the appliance. It also verifies and trusts the vCenter server's certificate before communication and
the OpenManage Integration for VMware vCenter registration. The console tab of OpenManage Integration for VMware vCenter uses
security procedures to avoid improper requests while the keys are transferred back and forth from the Administration Console and back-
end services. This type of security causes cross-sites request forgeries to fail.
A secure Administration Console session has a 5-minutes idle time-out, and the session is only valid in the current browser window and/or
tab. If you try to open the session in a new window or tab, a security error is prompted that asks for a valid session. This action also
prevents the user from clicking any malicious URL that can attack the Administration Console session.
Figure 3. Security error message
Access control authentication, authorization, and
roles
To perform vCenter operations, OpenManage Integration for VMware vCenter uses the current user session of web client and the stored
administration credentials for the OpenManage Integration. The OpenManage Integration for VMware vCenter uses the vCenter server's
built-in roles and privileges model to authorize user actions with the OpenManage Integration and the vCenter managed objects (hosts
and clusters).
14
108 Security roles and permissions