Steve's Power Systems BlogPower BlogContactLog inRegister
  • Power Blog
  • Contact

  • Register

IBM Power Systems Blog

Power Systems
  • Front Page
  • Categories
  • Archives
  • Latest comments
  • « AIX NIM Server Tuning Part 1
  • VIOS SEA Adapter Setting: adapter_reset and LACP (8023ad Link Aggregation) »

Role Based Authentication on the VIO Servers

Posted by steve on 18 Apr 2016 in VIO Server Tips

I needed to setup Role Based Authentication on the VIO Servers to allow the storage team to allocate storage to LPARs but I did not want to allow them full access.  VIOS Role Based Authentication was the solution and I finally got it working once I discovered the need to run the setkst command once roles and users were created.  The setkst command updates the running kerel tables that allow roles to work.

The following is just an example for setting up role based authentication.  A full list of roles and options is avaiable at the IBM web site.    IBM Role Base Authentication

 

# Create the role.

mkrole authorizations=vios.device,vios.oemsetupenv,vios.system.config.hostname STGAdmin

vios.system.config.hostname was added to allow the PS1 prompt to display the VIO Server hostname.

vios.device allows the user to update, create or remove devices.  As this is a parent authorization, the user also gets access to the child roles, vios.device.config and vios.device.manage.  vios.device.config allows the user to run cfgdev, while vios.device.config allows rmdev and/or mkdev commands.

vios.oemsetupenv allows the user to run the oem_setup_env command, as this was needed to access EMC PowerPath software.


# Create the user.

mkuser  -attr roles=STGadmin default_roles=STGadmin stguser1

 

# Reload the Kernel Tables.

setkst

Successfully updated the Kernel Authorization Table.
Successfully updated the Kernel Role Table.
Successfully updated the Kernel Command Table.
Successfully updated the Kernel Device Table.
Successfully updated the Kernel Object Domain Table.
Successfully updated the Kernel Domains Table.

Tags: RBACVIO ServerVIOS

No feedback yet


Form is loading...

July 2026
Mon Tue Wed Thu Fri Sat Sun
    1 2 3 4 5
6 7 8 9 10 11 12
13 14 15 16 17 18 19
20 21 22 23 24 25 26
27 28 29 30 31    
 << <   > >>

IBM Power Systems Blog

IBM Power Systems - Administration, Tuning and Optimisation. These posts are my own personal opinions and comments only.

Search

Categories

  • All
  • AIX Tips
  • AIX Tuning
  • Command Line Tips
  • HMC Tips
  • LPM Information
  • NIM Tips
  • Performance Testing
  • Power System Affinity
  • PowerHA Tips
  • SRIOV and vNIC
  • Scripts and One Liners
  • VIO Server Tips

Recent Posts

  • AIX NIM Hints and Tips
  • Finding Multiple Install Sources for AIX
  • PowerHA and EMC Busy Devices
  • AIX Random Password Generation
  • VIO Server 3.1.0 and ssh host keys
  • VIO Server 3.1.0 Items to Review
  • Just when you thought you understood idle CPU time!!
  • 40Gbit Adapter Performance Testing
  • LPM Copy Time Statistics
  • IBM HMC Upgrades

Recent Comments

  • steve on How to configure IBM SRIOV Adapters
  • Howard Coles on How to configure IBM SRIOV Adapters
  • steve on AIX mpstat and lssrad part 1
  • Charin Kumjudpai on AIX mpstat and lssrad part 1
  • Gagandeep on LPM and multiple vSwitches
  • Fant Steele on VIO Server 3.1.0 and ssh host keys
  • steve on AIX NIM Hints and Tips
  • alan wilcox on AIX NIM Hints and Tips
  • steve on AIX buf_mode attribute for Virtual Ethernet Adapters
  • Bernhar on AIX buf_mode attribute for Virtual Ethernet Adapters
  • Gery on Reading VLANs from the SEA Adapter
  • steve on Reading VLANs from the SEA Adapter
  • patrice on Reading VLANs from the SEA Adapter
  • steve on Reading VLANs from the SEA Adapter
  • steve on AIX buf_mode attribute for Virtual Ethernet Adapters
  • Chris K. on AIX buf_mode attribute for Virtual Ethernet Adapters
  • jovi on AIX or VIOS Errors: 29FA8C20 and 7BFEEA1F
  • steve on AIX or VIOS Errors: 29FA8C20 and 7BFEEA1F
  • jovi on AIX or VIOS Errors: 29FA8C20 and 7BFEEA1F
  • steve on Creating EtherChannel Devices from Command Line

This collection ©2026 by Stephen Diwell • Contact • Help • Social CMS engine

b2evolution CMS
Cookies are required to enable core site functionality.