Skip to main content

developerWorks >  SOA and Web services  >  Forums  >  IBM WebSphere DataPower SOA Appliance  >  developerWorks

how to grant CLI command for id other than admin to switch domain    Point your RSS reader here for a feed of the latest messages in this thread


     

 
 

My developerWorks
 Welcome, Guest
Sign in or register
Permlink Replies: 2 - Pages: 1 - Last Post: Nov 12, 2009 8:37 PM Last Post By: kjloh99
kjloh99

Posts: 23
Registered: Nov 24, 2008 01:17:25 AM
how to grant CLI command for id other than admin to switch domain
Posted: Nov 08, 2009 08:30:21 PM
Click to report abuse...   Click to reply to this thread Reply
Hi Dear all,

I need to use create a limited access user group and allow to switch domain using CLI. it does not seems I can do it. Is there any kind advise how to do that? What kind of access required to give to the group?

best regards,
Kok Jien
IBM employee or contractor RCW

Posts: 134
Registered: Apr 18, 2008 07:59:49 AM
Re: how to grant CLI command for id other than admin to switch domain
Posted: Nov 09, 2009 06:39:01 AM   in response to: kjloh99 in response to: kjloh99's post
Click to report abuse...   Click to reply to this thread Reply
Hi,

what you might be looking for are the CLI command Groups in the Manage User Group Configuration.

The common commands Group includes the switch domain command.

Here the different CLI command Groups and what they include:

Command Group

Select the functional command groups to which the user group has access from the CLI. Use the selection box with the Add and Delete buttons to define access. For information about command groups, click the Info . button.

This setting is superceded by an existing access policy if the system-wide Role Based Management is configured to apply to the CLI. To configure RBM access, use Access Profile on the Main tab.

AAA Policy: Provides access to the commands for configuring AAA Policy (aaapolicy in Global mode), Processing Metadata (metadata in Global mode), and XACML Policy Decision Point (xacml-pdp in Global mode).

Access Control List: Provides access to the commands for configuring Access Control List (acl in Global mode).

Common commands: Provides access to the majority of the show commands and the disable (Global mode) and switch domain (Global mode) commands.

Compile Options: Provides access to the commands for configuring Compile Options Policy (compile-options in Global mode).

Configuration Management: Provides access to the commands for configuring Import Package (import-package in Global mode), Include Configuration (include-config in Global mode), and Peer Group (peer-group in Global mode)

Configuration: Provides access to the commands for configuring MTOM Policy (mtom in Global mode), the command for defining CLI shell scripts (alias in Global mode), the command for pinging a remote server (ping in Global mode), the command for restarting an application domain (restart-domain in Global mode), the command for saving error reports (save error-report in Global mode), the command for sending error report (send error-report in Global mode), the command for viewing statistics (statistics in Global mode), and the command for testing a TCP connection (test tcp-connection in Global mode).

CRL: Provides access to the commands for configuring CRL (crl in Global mode).

Cryptography: Provides access to commands for configuring cryptographic operations (crypto in Global mode), Crypto Certificates (certificates in Crypto mode), Crypto Identification Credentials (idcred in Crypto mode), Crypto Key (key in Crypto mode), Crypto Profile (profile in Crypto mode), Crypto Shared Secret Key (sskey in Crypto mode), Kerberos KDC Server (kerberos-kdc in Crypto mode), Kerberos Keytab (kerberos-keytab in Crypto mode), SSL Proxy Profile (sslproxy in Global mode), the command for generating a crypto certificate (keygen in Crypto mode), the command for generating a key (key in Crypto mode), the command for exporting crypto objects (crypto-export in Crypto mode), the command for importing crypto objects (crypto-import in Crypto mode), and the command for cloning an HSM key wrapping key, when using an HSM-enabled device (hsm-clone-kwk in Crypto mode).

Device Management: Process access to commands for configuring SSH (ssh in Global mode), Telnet service (telnet in Global mode), Web Management Service (web-mgmt in Global mode), and XML Management Interface (xml-mgmt in Global mode).

Diagnostics: Provides access to commands used for diagnostics of failures for serviceability

Document Crypto Map: Provides access to commands for configuring Document Crypto Map (document-crypto-map in Global mode).

Domain: Process access to commands for configuring Application Domain (domain in Global mode).

Failure Notification: Provides access to commands for configuring Failure Notification (failure-notification in Global mode).

File Management: Provides access to commands for configuring NFS Dynamic Mounts (nfs-dynamic-mounts in Global mode) and NFS Static Mounts (nfs-static-mounts in Global mode).
Firewall Credentials: Provides access to commands for configuring Crypto Firewall Credentials (fwcred in Global mode).

Flash: Provides access to configuring and managing the Flash (flash in Global mode).
HTTP Service: Provides access to commands for configuring HTTP Service (httpserv in Global mode).
Input Conversion Map: Provides access to commands for configuring HTTP Input Conversion Map (input-conversion-map in Global mode).

Interface: Provides access to commands for configuring Interface (interface in Global mode) and the command for starting and stopping a packet capture (packet-capture in Global mode).
Load Balancer: Provides access to commands for configuring Load Balancer (loadbalancer-group in Global mode).

Logging: Provides access to commands for configuring Logging Category (logging category in Global mode), Logging Target (logging target in Global mode), and the command for generating a log event (test logging in Global mode).

Matching: Provides access to commands for configuring Matching Rule (matching in Global mode).

Messages: Provides access to commands for configuring Message Matching (message-matching in Global mode) and Message Type (message-type in Global mode).

Monitors: Provides access to commands for configuring Message Count Monitor (monitor-count in Global mode), Message Duration Monitor (monitor-duration in Global mode), and Message Filter Action (monitor-action in Global mode). Does not provide access to configuring Web Service Monitor. For access to these commands, select Web Service Monitor.
Multi-Protocol Gateway: Provides access to commands for configuring Multi-Protocol Gateway (mpgw in Global mode), Application Security Policy (application-security-policy in Global mode), Error Policy (webapp-error-handling in Global mode), FTP Poller Front Side Handler (source-ftp-poller in Global mode), FTP Server Front Side Handler (source-ftp-server in Global mode), HTTP Front Side Handler (source-http in Global mode), HTTPS Front Side Handler (source-https in Global mode), MQ Front Side Handler (source-mq in Global mode), Name-Value Profile (webapp-gnvc in Global mode), NFS Poller Front Side Handler (source-nfs-poller in Global mode), Rate Limiter (simple-rate-limiter in Global mode), Session Management Policy (webapp-session-management in Global mode), Stateful Raw XML Handler (source-stateful-tcp in Global mode), Stateless Raw XML Handler (source-raw in Global mode), TIBCO EMS Front Side Handler, if licensed on XI50 only (source-tibems in Global mode), TIBCO EMS Server, if licensed on XI50 only (tibems-server in Global mode), Web Application Firewall (web-application firewall in Global mode), Web Request Profile (webapp-request-profile in Global mode), Web Response Profile (webapp-response-profile in Global mode), WebSphere JMS Front Side Handle, XI50 only (source-wasjms in Global mode), and WebSphere JMS Server, XI50 only (wasjms-server in Global mode).

MQ Host: Provides access to commands for configuring WebSphere MQ Host (mq-host in Global mode) and WebSphere MQ Proxy (mq-proxy in Global mode).

MQ Gateway: Provides access to commands for configuring WebSphere MQ Gateway (mq-node and mq-gateway in Global mode).

MQ Queue Manager: Provides access to commands for configuring WebSphere MQ Queue Manager (mq-qm in Global mode) and WebSphere Queue Manager Group (mq-qm-group in Global mode).
Network: Provides access to commands for configuring DNS Settings (dns in Global mode), Host Alias (host-alias in Global mode), Network Settings (network in Global mode), and NTP Service (ntp in Global mode).

RADIUS: Provides access to commands for configuring RADIUS (radius in Global mode).

RBM: Provides access to commands for configuring RBM Settings (rbm in Global mode).
Schema Exception Map: Provides access to commands for configuring Schema Exception Map (schema-exception-map in Global mode).
Web Service Monitor: Provides access to commands for configuring Web Service Monitor (service-monitor in Global mode).

SNMP Settings: Provides access to commands for configuring SNMP Settings (snmp in Global mode).

SQL Data Source: Provides access to commands for configuring SQL Data Source (sql-source in Global mode).

SSL Proxy Service: Provides access to commands for configuring SSL Proxy Service (sslforwarder in Global mode).

Processing Action: Provides access to commands for configuring Processing Actions (action in Global mode).

Processing Policy: Provides access to commands for configuring Processing Policy (stylepolicy in Global mode) and

Web Service Processing Policy (wsm-stylepolicy in Global mode).

Processing Rule: Provides access to commands for configuring Processing Rule (rule in Global mode) and Web Service

Processing Rule (wsm-rule in Global mode).

System: Provides access to commands for configuring Crypto Certificate Monitor (cert-monitor in Global mode), NFS Client Settings (nfs-client in Global mode), System Settings (system in Global mode), Throttle Settings (throttle in Global mode), Timezone (timezone in Global mode), SSH Known Host (known-host in Global mode), XML File Capture (file-capture in Global mode), the command for setting the system clock (clock at the login prompt), and the command for shutting down the device (shutdown at the login prompt.

Tivoli (TAM, TFIM): Provides access to commands for configuring Tivoli Access Manager (create-tam-file and tam in Global mode) and Tivoli Federated Identity Manager (tfim in Global mode).

TCP Proxy Service: Provides access to commands for configuring TCP Proxy Service (tcpproxy in Global mode).

URL Map: Provides access to commands for configuring URL Map (urlmap in Global mode).

URL Refresh Policy: Provides access to commands for configuring URL Refresh Policy (urlrefresh in Global mode).

URL Rewrite Policy: Provides access to commands for configuring URL Rewrite Policy (urlrewrite in Global mode).

User Agent: Provides access to commands for configuring FTP Quoted Commands (ftp-quote-command-list in Global mode) and User Agent (user-agent in Global mode).

User and Groups: Provides access to commands for configuring User Account (user in Global mode) and User Group (usergroup in Global mode).

Crypto Validation Credentials: Provides access to commands for configuring Crypto Validation Credentials (valcred in Global mode).

Web Service Proxy: Provides access to commands for configuring SLM Action (slm action in Global mode), SLM Credential Class (slm-cred in Global mode), SLM Policy (slm-policy in Global mode), SLM Resource Class (slm-rsrc in Global mode), SLM Schedule (slm-sched in Global mode), UDDI Registry (uddi-registry in Global mode), UDDI Subscription (uddi-subscription in Global mode), WS-Proxy Endpoint Rewrite (wsm-endpointrewrite in Global mode), WSRR Server (wsrr-server in Global mode), and WSRR Subscription (wsrr-subscription in Global mode).
Web Services Management Agent: Provides access to commands for configuring Web Services Management Agent (wsm-agent in Global mode).

XML Firewall: Provides access to commands for configuring HTTP Proxy (http in Global mode) and XML Firewall (xmlfirewall in Global mode).

XML Manager: Provides access to commands for configuring Document Cache (documentcache in Global Mode), Parser Limits (xml parser limits in Global mode), and XML Manager (xmlmgr and xml-manager in Global mode).

XPath Routing Map: Provides access to commands for configuring XPath Routing Map (xpath-routing in Global mode).

XSL Coprocessor: Provides access to commands for configuring XSL Coprocessor Service (xslcoproc in Global mode).

XSL Proxy: Provides access to commands for configuring HTTP Proxy (http in Global mode) and XML Proxy Service (xslproxy in Global mode).

Low Latency Messaging Service: Provides access to commands for configuring LLM service

I hope this helps.

kjloh99

Posts: 23
Registered: Nov 24, 2008 01:17:25 AM
Re: how to grant CLI command for id other than admin to switch domain
Posted: Nov 12, 2009 08:37:40 PM   in response to: RCW in response to: RCW's post
Click to report abuse...   Click to reply to this thread Reply
Hi Thanks.

this is what we did. it is a very basic thing and it is well documented as you have shown. we just thought if there is anything we missed. also we have not problem with the default id admin.

but we do this in our older firmware 3.6.0.18. we will update to the latest firmware to see how it goes.

thanks.
Loh

Point your RSS reader here for a feed of the latest messages in all forums