[ Applies to ] StorageGuard 9.x and later / HPE Alletra 6000 and Nimble storage systems / NimbleOS
StorageGuard collects configuration and security posture data from HPE Alletra 6000 and Nimble storage systems by running read-only REST API calls and, optionally, CLI commands on the storage system. This article describes the requirements and how to create the scan account.
In this article
Requirements
| Requirement | Details |
|---|---|
| System address | The network name or IP address of each HPE storage system. |
| Credentials | A read-only user account, either existing or dedicated to StorageGuard, with API access and optional CLI access. |
| Role and permissions | The Operator role is recommended. Examples of REST API calls used: GET /v1/arrays, GET /v1/groups, GET /v1/space_domains, and GET /v1/user_groups. |
| CLI access (optional) | Recommended. Enable CLI access over SSH so StorageGuard can also run CLI commands, such as group --info, partner --list, and userpolicy --info. |
| Network access | HTTPS (port 5392 by default) from the StorageGuard server to each system, and SSH (port 22) if you enable CLI access. |
Create a scan account
StorageGuard needs a user account with read-only access. We recommend the Operator role:
| Role | What it allows |
|---|---|
| Operator (recommended) | Read-only access to system, configuration, and security settings; REST API GET calls; and non-privileged CLI commands, if SSH is enabled. Checks that rely on user administration APIs can't run. |
| Administrator | All checks, including those that rely on user administration APIs. |
Note: User administration APIs are available only to administrator users, so some checks run only with administrator privileges.
Create the user with either the CLI or the Management UI.
Option 1: Create the user with the CLI
- Log in to the storage system over SSH as an administrator.
-
Create a local user with the Operator role. The example uses the user name
sguard; you can use any user name:useradmin --add sguard --role operator --full_name "<Full Name>"
| Parameter | Description |
|---|---|
--add |
The unique user name for the new account. |
--role operator |
Assigns the read-only Operator role. |
--full_name |
Optional. The display name for the user. |
Option 2: Create the user in the Management UI
- Log in to the HPE Nimble / Alletra Management UI as an administrator.
- Go to Administration > Security > Users and Groups.
- Click Add.
- Enter the Username and Full Name.
- From the Role list, select Operator.
- Set and confirm a password.
- Click Save.
[ Still need help? ]
Our support team is here for you. Submit a request
Comments
0 comments
Please sign in to leave a comment.