
3BSE056141-510 F 53
Section 6 Security
When an ESX(i) server is installed, the root user is setup as the administrative user
on all objects in the ESX(i) server. Items such as virtual machines that are added
have the root user added to their permissions by default.
A danger with this is that mistakes or abuse of the system is possible by those who
have knowledge of the root password. To limit this, additional users who have
limited roles in the ESX(i) server should be added. These limited roles would only
allow the user to start the virtual machine, but not stop, delete, or modify it. The
roles should be applied to those virtual machines which are relevant to that user.
Roles
Roles are a group of privileges that can be allocated to a user and applied as
permissions to the objects in the ESX(i) server. These privileges are grouped into
categories such as Datastore and Virtual Machine.
By default, there are three roles in an ESX(i) server. These cannot be edited and new
roles need to be created to define the required set of privileges.
Creating a role with a limited set of permissions through the following actions:
• Login to the ESX(i) Server using the vSphere Client.
• In the task bar, select Home – Administration – Roles.
•Select Add Role.
• Provide a name for the new role.
• By default, the new role has no privileges.
• Add the minimal level of privileges required.
For example, expand the tree structure of:
Kommentare zu diesen Handbüchern