HP Adaptive Infrastructure Solution Security for BladeSystem Matrix

The All Tools toolbox contains all tools installed in the CMS.
The Monitor Tools toolbox contains tools that display the state of the managed systems but not tools
that change the state of the managed systems. For example, the Monitor Tools toolbox permits
viewing installed software but does not permit installing software. This toolbox is be used by the
operator role.
The Full Rights toolbox contains the tools used to perform administrative tasks on the CMS.
The Limited Rights toolbox contains tools that create, modify and delete all reports, and a limited
number of tools on the CMS.
A trusted administrator authorized to use the All Tools or Full Rights toolboxes can create additional
toolboxes or modify existing sets. HP SIM supports up to 32 toolbox definitions. A set of specified
users and a set of systems to be managed can then be associated with each HP SIM toolbox resulting
in HP SIM authorizations. The HP SIM authorization mechanism provides the specified user with the
ability to perform actions through HP SIM. An HP SIM user can only see systems authorized for that
user, and can only perform the specific actions (tools) that have been authorized for specific systems.
Figure 3: A restricted user authorized for monitor tools on ‘BMW’ only has a limited view
To administer a managed system, HP SIM ensures that only appropriately privileged administrators
can perform a given tasks on a given system. In fact, the HP SIM graphical user interface will only
display the tasks that are allowed for the current user. For HP SIM to accomplish its privileged tasks, a
trust relationship is defined between HP SIM and the managed systems. Typically a managed system
fully trusts HP SIM. HP SIM running on the CMS determines and enforces what a particular user can
do on a managed device. With appropriate authorizations configured in HP SIM, the user does not
need to login into accounts on each managed system to perform administrative tasks. Rather HP SIM
14