Users Guide

Table Of Contents
Security roles and permissions
The OpenManage Integration for VMware vCenter stores user credentials in an encrypted format. It does not provide any
passwords to client applications to avoid any improper requests. The backup database is fully encrypted by using custom
security phrases, and hence data cannot be misused.
By default, users in the Administrators group have all the privileges. The Administrators can use all the functions of the
OpenManage Integration for VMware vCenter within VMware vSphere web client. If you want a user with necessary privileges
to manage the product, do the following:
1. Create a role with necessary privileges
2. Register a vCenter server by using the user
3. Include both the Dell roles, Dell operational role and Dell infrastructure deployment role.
Topics:
Data integrity
Access control authentication, authorization, and roles
Dell Operational role
Dell Infrastructure Deployment role
About privileges
Data integrity
The communication between the OpenManage Integration for VMware vCenter, Administration Console, and vCenter is
accomplished by using SSL/HTTPS. The OpenManage Integration for VMware vCenter generates an SSL certificate that is
used for trusted communication between vCenter and the appliance. It also verifies and trusts the vCenter server's certificate
before communication and the OpenManage Integration for VMware vCenter registration. The console tab of OpenManage
Integration for VMware vCenter uses security procedures to avoid improper requests while the keys are transferred back and
forth from the Administration Console and back-end services. This type of security causes cross-sites request forgeries to fail.
A secure Administration Console session has a 5-minutes idle time-out, and the session is only valid in the current browser
window and/or tab. If you try to open the session in a new window or tab, a security error is prompted that asks for a valid
session. This action also prevents the user from clicking any malicious URL that can attack the Administration Console session.
Figure 3. Security error message
Access control authentication, authorization, and
roles
To perform vCenter operations, OpenManage Integration for VMware vCenter uses the current user session of web client and
the stored administration credentials for the OpenManage Integration. The OpenManage Integration for VMware vCenter uses
the vCenter server's built-in roles and privileges model to authorize user actions with the OpenManage Integration and the
vCenter managed objects (hosts and clusters).
14
Security roles and permissions 109