Searching the Help
To search for information in the Help, type a word or phrase in the Search box. When you enter a group of words, OR is inferred. You can use Boolean operators to refine your search.
Results returned are case insensitive. However, results ranking takes case into account and assigns higher scores to case matches. Therefore, a search for "cats" followed by a search for "Cats" would return the same number of Help topics, but the order in which the topics are listed would be different.
Search for | Example | Results |
---|---|---|
A single word | cat
|
Topics that contain the word "cat". You will also find its grammatical variations, such as "cats". |
A phrase. You can specify that the search results contain a specific phrase. |
"cat food" (quotation marks) |
Topics that contain the literal phrase "cat food" and all its grammatical variations. Without the quotation marks, the query is equivalent to specifying an OR operator, which finds topics with one of the individual words instead of the phrase. |
Search for | Operator | Example |
---|---|---|
Two or more words in the same topic |
|
|
Either word in a topic |
|
|
Topics that do not contain a specific word or phrase |
|
|
Topics that contain one string and do not contain another | ^ (caret) |
cat ^ mouse
|
A combination of search types | ( ) parentheses |
|
Access control
Roles control what a user can access in CSA. For more information about available roles, see the Welcome to Cloud Service Automation topic in this help system. Adding a distinguished name (DN) to the roles authorizes members of the LDAP directory organizational units access to the Cloud Service Management Console or Marketplace Portal. If a user has access to the Cloud Service Management Console, a user may have access to one or more of the functional areas in the console. If a user has access to the Marketplace Portal, a user has access to all areas in the portal.
Access control allows you to add or remove directory service groups or organizational units (ou) to a CSA role by associating the ou's DN to the desired role. Authenticated LDAP users, who are members of a group or organizational unit that is assigned to a predefined role, can perform specific tasks and access specific parts of the Cloud Service Management Console or access the Marketplace Portal.
Only members of a group or organizational unit are assigned to the role. To ensure secure role assignment, access control inheritance stops at the assigned organizational unit. This does not follow the traditional directory service pattern where inheritance flows down the organizational unit's hierarchy. Instead, assignments to roles must be assigned to individual organizational units (ou).
A group or organizational unit DN can be assigned to more than one role.
LDAP must be configured in order to authenticate users so that they can log in to the Cloud Service Management Console and Marketplace Portal. Refer to LDAP for more information.
To add a DN to a role
- Locate the role to which you want to add a DN.
-
Below the role, click Add DN.
Note CSA supports the following attributes for an object class:
-
group
-
groupOfNames
-
groupOfUniqueNames
Ensure the groups you are adding in CSA organizations are using one of the above attributes for the group object class in LDAP.
-
-
Provide the following information, and click Save:
To select an existing named DN: Item Description Select from existing named DNs Select an existing named DN (that identifies a group or organizational unit DN) to add to the role. If there are no existing named DNs, this item is not selectable. To add a new named DN: Item Description Enter a name for the group or organizational unit DN Enter a name to identify the DN. Enter a group or organizational unit DN Enter the group or organizational unit DN to add to the role. This DN must be relative to the Base DN you configured in the LDAP section of this organization. If the base DN is empty, supply the full DN of the group.
To update a name or DN in a role
- Locate the role whose DN you want to update.
- Below the role, locate the DN you want to update.
- Move your cursor over the DN and click the Edit button.
- In the Update DN dialog, update the DN name and/or the DN.
- Click Update.
To remove a named DN from a role
- Locate the role from which you want to remove a named DN.
- Below the role, locate the group you want to remove.
- Click the Remove DN icon.
- Click Yes.
We welcome your comments!
To open the configured email client on this computer, open an email window.
Otherwise, copy the information below to a web mail client, and send this email to clouddocs@hpe.com.
Help Topic ID:
Product:
Topic Title:
Feedback: