2.0

Table Of Contents
VMware, Inc. 203
Chapter 10 Managing Roles and Permissions
Managing Users
AuserisanindividualauthorizedtologintoVMwareServer.Userscanaccess
VMwareServerusingVIWebAccess,thevmruncommand,theVIXAPI,ora
thirdpartyclient.
Tocreate,remove,ormodifyusersonaVMwareServersystem,usethemechanisms
providedbythehostoperating
system.UsersremovedfromaVMwareServerhostlose
accesstoallVMwareServerobjectsandarenotabletologonagain.Usersthatare
loggedinwhentheyareremovedfromthehostretaintheirVMwareServer
permissionsonlyuntilthenextvalidationperiod(thedefaultisevery
24hours).
VIWebAccessdisplaysalistofexistingusersthatyoucanselectfromwhenyou
configurepermissions.
Managing Groups
Agroupisacollectionofusersthatyouwanttomanagethroughacommonsetofrules.
Youcanefficientlymanageusersthatrequirethesameprivilegesbycreatinggroups.
Usinggroupscansignificantlyreducethetimeittakestoconfigureyourpermissions
model.
Tocreate,remove,ormodifygroups
onaVMwareServersystem,usethemechanisms
providedbythehostoperatingsystem.Groupmembershipischeckedeachtimeauser
logsin.ThegroupsareretrievedeitherfromtheWindowsdomain(forVMwareServer
runningonWindows)orfromtheLinuxoperatingsystemgrouplist(forVMware
Server
runningonLinux).Removingagroupdoesnotaffectthepermissionsgranted
individuallytotheusersinthatgroup,orthosegrantedaspartofinclusioninanother
group.
Whenyouassignaroletoagroup,itappliestoalltheusersinthegroup.VI WebAccess
displaysalist
ofexistinggroupsthatyoucanselectfromwhenyouconfigure
permissions.
Managing Roles
Aroleisanamedcollectionofprivileges.VMwareServergrantsaccesstoobjectsonly
tousersthathaveprivilegesfortheobject.Bypairingauserorgroupwitharole,you
granttheuserorgroupaccessrightstotheobject.
VMwareServerprovidesbuiltinsystemroles.The
privilegesassociatedwithsystem
rolescannotbechanged.