API for Virtual Private Cloud user roles

Hi guys,.

About vCloud Air Documentation Center documentation, I see only "Virtual infrastructure" administrator and "End user" roles create and manage virtual machines. The role of "Accounting officer" description is «...» Account administrators can also view virtual data centers, virtual machines, gateways, network and activity logs... «, on this sentence, I understand that "account administrator" NOT able to create virtual machines and can DISPLAY its settings, but I was able to create a virtual machine using API by the user with the role of "Accounting officer".» Someone please clarify the responsibilities of roles?

Hello

Thanks for that bring to our attention. Slightly changed role definitions and I'll have my Tech writers look more closely at this.

I understand also that the account managers are 'super admins' with all the capabilities.

Jenny

Tags: VMware

Similar Questions

  • Connector for Siebel for OPA Private cloud 12.1.0

    When is the expected release date of Siebel connector for OPA Private cloud 12.1.0?.

    The plan is for comparable features available in future releases of Siebel. Note that the mapping is built directly in to OPA 12.x, a separate connector may no longer be necessary.

    More information on this approach will be available by releasing Siebel 15.4.

    Davin.

  • vCloud API for private cloud / backwards?

    Hello

    Sorry for the question of novice.  For API vCloud, VMware provides a cloud application on vCenter server endpoint?  It might be useful for my internal private cloud (and I did not need to develop the additional layer on top of my vCenter server).

    From coffee to speak today, I understand that vCloud what API should talk of endpoint of cloud which is implemented by the provider of public/external cloud services (vCloud Express partner).

    For private/inside cloud based on vSphere, we could use vSphere SDK to speak directly to the cloud.  If the vCenter server shows the implementation of vCloud API, I could use the same code (based on the vCloud API) to talk to the public/external and internal/private clouds.

    Thank you.

    Kong

    Hi Kong,

    vCenter Server does not expose endpoint vCloud API at this time.  VCloud Express partners expose endpoints that will be produced computing cloud of VMware that sits on top of vCenter Server.

  • What are the solutions for remote use unauthorized computer via a virtual private network?

    Dell Dimension E310.  Windows XP. Professional.   "Media Center". 5 years old.  Stand alone computer.  Unsolicited 'demand' come across the screen for remote access.  Wallpaper, next to the clock, someone downloading of graphics file "Accelerator" without authorization.   Called internet provider.  They claim that they do not deal with the configuration of the virtual private network. Tech said there is more than one device connected to my computer!
    I went to "Computer management" and delete all except myself as a user and the administrator.  Obviously, too late as a person UNKNOWN has defined itself as "NT Authority\Authenticated Users".  Locked computer: would not recognize my password.
    Formatted drive / reinstalled windows.  Able to use the computer for "allocation of 7 days; my computer then froze again.  AT and T Tech indicates that UNKNOWN use of my computer and no recourse.  Are there solutions to the unauthorized use?

    Hello

    I suggest you post your question Forums Technet for assistance on this issue.

    Windows XP Service Pack 3 (SP3)

    http://social.technet.Microsoft.com/forums/en-us/itproxpsp/threads

  • Audit/admin API for cloud applications

    Hello

    I'm looking for admin API for cloud Oracle, including Oracle ERP applications.

    I'm looking for APIs such as connection events, management of users (user added, deleted, suspension etc), authentication sessions and so on.

    I enjoy all help direct me to these APIs, if they exist.

    Thank you

    Nimrod

    Wrong forum - try asking on the forum that pertains to the specific app you use.

    Software as a Service (Saas)

  • GRANT SELECT on a table to the user / role changes for the tab last_DDL

    Hello

    Is grant select (or any private object) to the user/role a DDL statement?

    GRANT SELECT on a table to the user / role changes the last_DDL to the table.
    1 > is this expected behavior?
    2 > no way in which we can grant select on a table by another user, without changing the DDL? (for example create view).


    The test is performed:

    Prior to the issuance:


    OBJECT_NAME CREATED TIMESTAMP LAST_DDL_TIME OWNER
    ------- ---------------------- ---------- ------------- --------------------
    AR HZ_CUSTOMER_PROFILES 8 MAY 00 13 MARCH 13 2003-06 - 26:12:41:29



    Grant statement:
    GRANT SELECT ON "AR". "' HZ_CUSTOMER_PROFILES ' TO 'AR_VIEW ';

    Note: AR_VIEW is a role, I tried granting also directly to the user.


    After the grant:

    OBJECT_NAME CREATED TIMESTAMP LAST_DDL_TIME OWNER
    ------- ---------------------- ---------- ------------- --------------------
    AR HZ_CUSTOMER_PROFILES 8 MAY 00 21 MARCH 13 2003-06 - 26:12:41:29



    Old thread, discuss whether Grant is DDL or not, but no documented conclusions.
    ( Re: Grant, revoke is DDL and DCL? )

    Please help in the assessment above.

    -Best regards,.
    Mani

    It's the DOF.

    After all, this isn't DML, it implicitly committed and you cannot use it directly in PL/SQL: features of DDL. :-)

  • public network for virtual machines, private storage and the service console?

    Hello

    So far I had a pretty small facility with 2 servers with 4 physical network adapters each running ESX 3.5, a small box of EqualLogic SAN to shared storage and a few virtual machines on our network of regular reinforcement, routed, not on a private.   The network config was really simple.  I just put everything on real IP addresses on our network of building.

    Now I want to move the SAN and the traffic on a private service console network, but I don't know how to do this.

    Right now I use 2 NETWORK cards on each server:

    vmnic0 is configured on vSwitch0 and has the network of the VM on it that all my use of VMS to talk to the outside world, and it also has the Service Console that uses Virtual Center and I use ssh to it.

    vmnic1 is configured on vSwitch1 and a VMKernel Port and also a Service Console Port for iSCSI Software to talk to my SAN.  (never been clear on why both are needed to talk to the SAN, but doctors say they are)

    My plan is to set up a vSwitch2 and bind it to vmnic2 and implemented a VMKernel Port and the Service Console Port for software iSCSI on the 10.x.x.x network, set up my new (larger) SAN box on the 10.x.x.x network and simply use Storage vMotion to move virtual machines to the new storage space.  As soon as I did this, I would like to not use the Service Console on vSwitch2 and not a Console Service at all on vSwitch0.  Is it possible to delete the one on vSwitch0 and just use a new vSwitch2 for Virtual Center and ssh access?

    So my proposed configuration would be:

    vSwitch0: VM network only, used by the VM guests for oriented public access network, no construction of Network Service Console, linked to vmnic0

    vSwitch1: superfluous once I do storage vMotion of everything on my old SAN, will eventually remove and pair vmnic 1 with vmnic0, linked to vmnic1

    vSwitch2: VMKernel and Service Console on the network 10.x.x.x, used to access the new SAN, used by Virtual Center to access the ESX, used to SSH in to ESX on private network, associated vmnic2

    If it works?

    Thank you.

    Hello

    VMkernel ports cannot live on the same subnet. So if you have 3 vmkernel ports say: vMotion, iSCSI and NFS. You really need 3 subnets. 1 for each vmkernel port.

    Otherwise how does he know all send properly?

    Best regards

    Edward L. Haletky VMware communities user moderator, VMware vExpert 2009, url = http://www.virtualizationpractice.comvirtualization practical analyst [url]
    "Now available: url = http://www.astroarch.com/wiki/index.php/VMware_Virtual_Infrastructure_Security' VMware vSphere (TM) and Virtual Infrastructure Security: securing the virtual environment ' [url]
    Also available url = http://www.astroarch.com/wiki/index.php/VMWare_ESX_Server_in_the_Enterprise"VMWare ESX Server in the enterprise" [url]
    [url =http://www.astroarch.com/wiki/index.php/Blog_Roll] SearchVMware Pro [url] | URL = http://www.astroarch.com/blog Blue Gears [url] | URL = http://www.astroarch.com/wiki/index.php/Top_Virtualization_Security_Links Top security virtualization [url] links | URL = http://www.astroarch.com/wiki/index.php/Virtualization_Security_Round_Table_Podcast Virtualization Security Table round Podcast [url]

  • Adding a user role for SAN switches

    I'll try to find the correct location in 3.3 ACS to add the following: roles = "network-admin". We have our SAN with Ganymede switches +. When one user other than admin connections, you get the role of "network operator". The Cisco MDS 9000 Family Troubleshooting Guide, version 3.x doc explains the role if you are using IOS/PIX Radius. Thank you.

    Hi Ed,

    Here is the link,

    http://www.Cisco.com/en/us/docs/storage/san_switches/MDS9000/SW/rel_2_x/San-OS/Configuration/Guide/cradtac.html

    If you are looking for:

    GANYMEDE + custom attributes can be set on a control access (ACS) server for various

    Services (for example, shell). The Cisco MDS 9000 family switches require custom GANYMEDE +.

    attribute of the shell of service to use for the definition of the roles.

    Cisco ACS GANYMEDE +.

    Shell: roles = "network-admin".

    Shell: roles * "network-admin".

    Cisco-av-pair * shell: roles = "network-admin".

    Cisco-av-pair * shell: roles * "network-admin".

    Cisco-av-pair = shell: roles * "network-admin".

    On GBA, if you go to: the Interface configuration, GANYMEDE + (Cisco IOS), check nex to: "display a window for each selected service in which you can enter custom GANYMEDE + attributes.

    Then, go to the configuration of groups and define the role information according to the above attributes.

    Hope that helps

    Kind regards

    ~ JG

  • The worksheet name change for the interactive user role

    Hi all

    I have a question about DRM security for users with access add to the sheet and only read access to the members. The requirement is that the user should be able to add a sheet and change all the properties associated with the leaves but cannot add or change the Member or any property associated with a branch. To do this, I created a group of node (NAG1) and assigned categories of goods (PC1) associated with the hierarchy of the NAG1 with editing access to PC1. The NAG1 for journal access ADD and NAG1 for branch had read access. The user has only one role which is the interactive user. This way, the user cannot add spreadsheets, edit the properties associated with the leaves, but don't can't add limb or change all the properties associated with limb, HOWEVER, the user is not able to change the name of an existing journal. If I give the user role 'Director of Application', while they are able to change the name of the system, but then they see the section Administration on the left and everything related which we want give...

    Is it possible to give the user the ability to change the name of the worksheet without giving ""Application Administrator ' role? "

    Denzz Murali Pasumarti

    Thanks in advance

    Sumit

    Have you checked RenameLeaf and RenameLimb system preferences?  I think that by default, only the administrator can change the name of the node, but you can grant this possibility of additional roles.

  • What opening of database Service of Cloud Computing console receiveing "the user role cannot access the Cloud database Service" message and see no service. Why?

    What opening of database Service of Cloud Computing console receiveing "the user role cannot access the Cloud database Service" message and see no service. Why?

    Thank you in advance.

    Try now

  • Reset password for virtual users

    Is it possible to reset a password for virtual users or if they forgot get it back? All I see is to remove the virtual user and again share access.

    See you soon

    When the user of the virtual user name is entered in the login screen, a forgotten password? link in the lower part. Clicking on it will reset the password and send an e-mail to the e-mail address of the user.

    Is that what you are looking for?

  • Is there an API for uploading and downloading PDF files from Document clouds

    Is there an API available?

    No, there is no API for loading/downloading of PDF files to the cloud of Document.

  • For applications, hosted on a private server, users have to reinstall the application to see the updates to the App Builder?

    For applications, hosted on a private server, users have to reinstall the application to see the updates to the App Builder? Let's say that I was updating a banner of right or a library style...

    If you change the .zip offline banner or a library style that is part of a .zip file that you specify in DPS App Builder, then Yes, you must change the app and make it available for users to update. But if you change the style of banner or library that is hosted on a server, the changes appear immediately without any modification to the application.

  • Questions of Virtual Private Network (VPN) connection

    OK I did some research on the private network connections, and I have a few questions:

    • Is it true that a connection to a vpn is possible thanks to a transport to a Wi - fi (I want to connect to a network non - bes)?
    • As far as I know, you can connect to a vpn only if create you a vpn manually account via the phone options menu. Is it possible to programmatically create the connection without having to manually create the profile?
    • This connection can be established via a proxy server?
    • Any article or the sample code will be really appreciated

    BlackBerry Smartphones have supported integrated to connect through a VPN using WiFi.  Other transport routes are not supported out of the box for this.

    There is no way to programmatically configure a VPN.  Virtual private networks can be configured on a BlackBerry Enterprise Server and pushed to users.

    BlackBerry Enterprise Server is able to connect through a proxy server.  All of the BlackBerry Java API does not include API to manage proxy communications.

  • Look for no logged in user to Active Directory

    Hello

    Our application meets with AD where all the users and groups are configured.

    Given a unique ID for a user (non-logged) and ad group name, it is possible to search for this user in this group and return such a value true or false based on whether the user is present in this ad group or not?

    For a logged-in user, we have an established securityContext and it is very easy to do using userInRole ["app_role_name"]. This would tell us whether or not the user belong to this group. But how can we do this for a user not registered?

    I was going through the API OPSS but could not understand it if possible.

    Team database probably for this using the DBMS_LDAP API but I want to make sure you that there is a java solution as I remove the call to the DB.

    Thank you.

    Here you have an example OPSS:

    (MyGroup and MyUser are just POJO)

    Public collection {} getGroupsForUser (MyUser myUser)

    Collection roleList = new ArrayList ();

    IdentityStore idStore = null;

    try {}

    idStore = getIdStore();

    User user = searchUserByUsername (idStore, myUser.getUsername ());

    If (user! = null) {}

    SearchResponse resp = idStore.getRoleManager () .getGrantedRoles (user.getPrincipal (), true);

    While (resp.hasNext ()) {}

    Role = resp.next () (role);

    MyGroup myGroup = new MyGroup();

    myGroup.setName (role.getName ());

    roleList.add (myGroup);

    }

    resp. Close();

    } else

    throw new UnexistentResourceException (myUser, ResourceTypes.IDSTORE);

    } catch (oracle.security.idm.ObjectNotFoundException e) {}

    the user does not exist

    } catch (IMException e) {}

    throw new MySecurityException (e);

    } {Finally

    If (idStore! = null) {}

    try {}

    idStore.close ();

    } catch (Exception e) {}

    }

    }

    }

    Return roleList;

    }

    private getIdStore() {} IdentityStore

    IdentityStore instance;

    try {}

    JpsContextFactory ctxf = JpsContextFactory.getContextFactory ();

    JpsContext ctx = ctxf.getContext ();

    IdentityStoreService storeService = (IdentityStoreService.class) ctx.getServiceInstance;

    If (storeService is nothing)

    throw new MySecurityException ("JPS invalid configuration! Please check your configuration environment");

    instance = storeService.getIdmStore ();

    } catch (JpsException e) {}

    throw new MySecurityException (e);

    }

    return instance;

    }

    /**

    * Returns the user having a certain username of the FIRST identity store

    * WARNING: The user can be duplicated in OPSS, because coming from two different authentication providers

    @param username

    * @return

    */

    private user searchUserByUsername (idStore, String username IdentityStore) {}

    List = new ArrayList ()evaluations1 users;

    IdentityStore idStore1 = null;

    try {}

    idStore1 = getIdStore();

    SimpleSearchFilter filter =.

    idStore1.getSimpleSearchFilter (SimpleSearchFilter.TYPE_EQUAL, "Username", username);

    SearchParameters sps is new SearchParameters (filter, SearchParameters.SEARCH_USERS_ONLY);.

    SearchResponse resp = idStore1.searchUsers (sps);

    While (resp.hasNext ()) {}

    User user = resp.next () (user);

    USERS1. Add (User);

    }

    resp. Close();

    } catch (ObjectNotFoundException exception) e {}

    do nothing, return of empty collections

    } catch (IMException e) {}

    throw new PenfaxSecurityException (e);

    } {Finally

    If (idStore1! = null) {}

    try {}

    idStore1.close ();

    } catch (Exception e) {}

    }

    }

    }

    List of users of = users1;

    If (users.isEmpty ())

    Returns a null value.

    on the other

    Return users.get (0);

    }

Maybe you are looking for