Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Dell PowerFlex Appliance with PowerFlex 4.x Administration Guide

Create credentials for root and non-root users

Use this procedure to create credentials for root and non-root users in PowerFlex Manager.

Prerequisites

To import and create the SSH keys for a PowerFlex node, switch, OS Admin, OS User, ensure you generate SSH key pairs of RSA type without passphrase. See Related information for more information.

About this task

You can now use a non-root user instead of the root user for PowerFlex system administration functions. This enhances security by disabling the root user during node discovery, operating system installation, and non-disruptive updates. The default non-root user name is pflex.

NOTE:The credential type OS Admin is used for root users, and OS User is used for non-root user. OS Admin and OS User credential types apply for the deployment the resource groups.

For non-root user authentication, after the deployment of the resource group, the SSH access to the user root is disabled, password is still available to take console access for troubleshooting.

PowerFlex Manager allows you to specify a non-root user when you configure a template for a compute-only, storage-only, hyperconverged or PowerFlex file deployment.

NOTE:SSH key pairs based root or non-root deployments are not supported for PowerFlex file deployments.

PowerFlex Manager allows you to use an LDAP user for PowerFlex system administration functions. When you create or edit an operating system user credential, you can optionally specify the LDAP domain. This allows you to use an active directory (AD) user rather than a local user for administration functions.

Steps

  1. On the menu bar, click Settings > Security.
  2. Click Resource Credentials. The Credentials Management page opens.
  3. Click Create.
  4. In the Create Credentials dialog box, from the Credential Type drop-down list, select one of the following resource types for which you want to create non-root credentials:
    • Node
    • Switch
    • OS Admin
    • OS User
    The OS Admin and OS User credential types apply to deployed items, not to PowerFlex Manager. If you are creating an OS user credential set for the management virtual machines on a PowerFlex management controller resource group, select OS User.
  5. In the Credential Name field, enter the name to identify the credential.
    NOTE:If you are creating an OS User credential set for the management virtual machines on a PowerFlex management controller resource group, do the following:
    1. Enter MVM delladmin to identify the credential.
    2. In the User Name field, enter delladmin.
    3. Enter the delladmin account password in the Password and Confirm Password fields.
  6. Click Enable Key Pairs to enable log in with SSH key pairs and perform the following:
    Table 1. Key pairs optionsThe following table provides procedures to log in with SSH key pairs.
    To... Do this...
    Enable key pairs for the Node or Switch credential:
    1. Click Import SSH Key Pair.
      NOTE:Manually generate the SSH keys pairs.
    2. Click Choose File and browse to the file that contains the private key.
    3. Type a name for the key pair.
    4. Click Import.
    Create keys using PowerFlex Manager for the OS Admin or OS User credential and enable key pairs:
    1. Click Create a new key.
    2. Click Create & Download Key Pair.
    3. On Key Pair Name, type the name for key pair.
    4. Click Create.
    5. Click Download Public Key.
    To manually generate and import an existing key pairs for the OS Admin or OS User credential
    1. Click Import SSH Key Pair.
      NOTE:Manually generate the SSH keys pairs.
    2. Click Choose File and browse to the file that contains the public and private key.
    3. Type a name for the key pair.
    4. Click Import.
    If you enable SSH key pairs for a Node or Switch credential and use that credential for discovery, PowerFlex Manager uses public or private RSA key pairs to SSH into your node or switch securely, instead of using a user name and password.

    If you enable SSH key pairs for an OS User or OS Admin credential and use that credential for a deployment, PowerFlex Manager uses RSA public or private key pairs for the deployment operations.

    NOTE:PowerFlex Manager does not consume SSH keys for all component types. For example, if you enable SSH key pairs for an admin credential, the SSH keys are not used for the deployment of a CloudLink Center VM. Instead, the user name and password are used instead for all communication.
  7. To enable LDAP for an OS User (optional):
    1. On the Create Credentials page, in the Credential type field, enter OS User.
    2. In the Credential Name field, enter LDAP.
    3. Enter the domain name and username in the Domain and User Name fields.
    4. Enter the passwords and click Save.
    NOTE:Create username with domain name on active directory server. NTP server and active directory server time must sync. Configure DNS server and prefix on the management network configuration.
  8. In the User Name field, enter the username for the credential.
    For Nodes (iDRAC), root is the only valid username for root-level credentials. For a non-root user name, enter the default non-root user name.
    For the OS Admin credential type, the User Name field is disabled because the user is assumed to be root. You must use the root user for new deployments.
    For the OS User credential type, enter the default non-root user name.
    For the embedded operating system, this user account must have SSH enabled and have sudo access. For VMware ESXi, the account must be configured with the administrator role on the local server permission setting, which should enable SSH and other tools like esxcli. You can add existing resource groups with a non-root user. The account on the SVM and/or PowerFlex storage-only nodes for the OS User credential type must have a /home directory and have the correct group permissions.
  9. In the Password and the Confirm Password boxes, enter the password for the credential.

Rate this content

Accurate
Useful
Easy to understand
Was this article helpful?
0/3000 characters
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please select whether the article was helpful or not.
  Comments cannot contain these special characters: <>()\