Assigning Administrative Privileges to Users

By default, the root user has privileges to perform all operations available from the SAM-QFS Manager software.

You can assign other users full access to all SAM-QFS Manager operations, or access to only a subset of operations. The following table lists the five levels of privileges that you can assign to SAM-QFS Manager users.

Table 9 Administrative Privileges

Administrative Privilege Level

Privileges

com.sun.netstorage.fsmgr.config

Unlimited.

com.sun.netstorage.fsmgr.operator.media

Import, export, and assign volumes.

com.sun.netstorage.fsmgr.operator.sam.control

Perform operations relating to faults and jobs; generate SAM reports; and start, stop, and idle the archiving function.

com.sun.netstorage.fsmgr.operator.file

Perform staging and restoring operations.

com.sun.netstorage.fsmgr.operator.filesystem

Mount and unmount file systems, and check and repair file systems.

These privilege levels and the functions assigned to each level are defined in the /etc/security/auth_attr file.


Caution - For proper system operation, do not edit the /etc/security/auth_attr file.


Because multiple users with the same privilege level can be logged in to the software concurrently, there is a risk of one user’s changes overwriting another user’s previous changes. To prevent this, develop policies about who can make changes and how to notify others.