3PAR InForm® OS 2.3.1 CLI Reference (320-200166 Rev B, March 2010)

21.11
InForm OS Version 2.3.1 Command Line Interface Reference
The matching of a user's groups with the mapping rules is done in the order of the
mapping parameters provided previously. When there are multiple matches, the first match
determines the user's privilege level.
Domain names found with the use of domain-name-attr and domain-name-prefix
are only potential domains and a user will only have privileges in those if they are actually
existing domains. The
showdomain command will list existing domains.
The showauthparam command displays authentication parameter settings and the
checkpassword command can be used to see how the parameters are used to bind with
an LDAP server and search for data to determine the user's privilege level.
When 3PAR Domains are enabled, you can only have Super or Service privilege levels for
the domain all. Any other domain names are ignored for Super or Service level users. You
can only have the Service privilege level when no other domains match for levels other
than Super or Service. If other such domains match, the Service level match is ignored.