HP 3PAR StoreServ Concepts Guide: HP 3PAR OS 3.1.3
Table 2 HP 3PAR OS User Roles (continued)
Rights Assigned to RolesUser Roles
Rights are limited to internal use by HP for Adaptive
Optimization operations.
3PAR AO
Rights are limited to internal use by HP for Recovery
Manager operations.
3PAR RM
Local User Authentication and Authorization
Users accessing the HP 3PAR storage system with the HP 3PAR CLI client or Secure Shell (SSH)
connections are authenticated and authorized directly on the system. These users are referred to
as local users. The information used to authenticate and authorize a local user is stored on the
system.
For instructions on creating a local user, see the HP 3PAR Command Line Interface Administrator’s
Manual and the HP 3PAR Management Console Online Help.
LDAP User Authentication and Authorization
An LDAP user is authenticated and authorized using information from a Lightweight Directory
Access Protocol (LDAP) server. If multiple systems are configured to use the same LDAP server, a
user who can access one system can access all systems with the role and rights assigned to the
LDAP group.
Local user roles and rights are associated with an individual; LDAP user roles and rights are the
same for all members of the group. If you want to authenticate and authorize LDAP users with
different roles, you must create an LDAP group for each role.
For detailed information about LDAP users and LDAP connections, see “Lightweight Directory Access
Protocol” (page 21). For instructions on setting up an LDAP connection, see the HP 3PAR Command
Line Interface Administrator’s Manual.
Domain User Access
A domain user is a user with access to a specific domain. Local users who belong to a system that
uses HP 3PAR Virtual Domains software are domain users. In addition to the user’s roles and rights,
a domain user’s activities are also limited to the domains to which they have access. A domain
user’s assigned user role is applicable only within the domain to which the user has access.
For detailed information about virtual domains and domain users, see “HP 3PAR Virtual Domains”
(page 25). For instructions on creating a domain user, see the HP 3PAR Command Line Interface
Administrator’s Manual and the HP 3PAR Management Console Online Help.
NOTE: Virtual domains require an HP 3PAR Virtual Domains Software license. For additional
information about the license, see “HP 3PAR Software” (page 10).
20 HP 3PAR Storage System Users