Symantec logo

Veritas Enterprise Administrator

You may need to update Veritas Enterprise Administrator so that users other than root can access features.

Adding Users to Veritas Enterprise Administrator for DB2

You may want to add users to the VEA Authorization Database (AZDB) to allow access to the interface to users other than root. You also have the option to give database administrators root privileges.

 To add users other than root to the Veritas Enterprise Administrator AZDB

  1. Make sure that the optional GUI package was installed.

    # pkginfo -l VRTSd2gui | egrep STATUS

STATUS: completely installed

  1. Stop the VEA server.

    # /opt/VRTS/bin/vxsvcctrl stop

  2. To give root privileges to the database administrator, use the vxdb2edusr command as follows.

    # /opt/VRTS/bin/vxdb2edusr -a {user | group} [-A] [-f] -n \

  user_name [-h fully_qualified_host_name -d domain_name \

-t domain_type]

where:

-a user adds a user to the registry

-A grants the user root access

-f allows the user to be a user other than the /opt/VRTSdb2ed owner.

-n indicates the name of the user or group.

-h specifies a fully qualified host name on which you want to add a user.

-d specifies the domain to which the user belongs.

-t specifies the type of domain to which the user belongs. Valid values are nis, nisplus, Idap, unixpwd, and gssapi.

For example, to add a database administrator with the name db2inst1 as a user with root privileges, enter the following:

# /opt/VRTS/bin/vxdb2edusr -a user -A -f -n db2inst1

  1. To add a user without root privileges, use the vxdbedusr command as follows.

# /opt/VRTS/bin/vxdbe2dusr -a user -n user_name

where -a adds a user to the registry.

For example, to add db2inst1 as a user, enter the following:

# /opt/VRTS/bin/vxdb2edusr -a user -n db2inst1

  1. To add a group to the console registry, use the vxdb2edusr command as follows:

# /opt/VRTS/bin/vxdb2edusr -a group -n group_name

where -a adds the user group to the registry.

For example, to add "dba" as a group, enter the following:

# /opt/VRTS/bin/vxdb2edusr -a group -n dba

  1. Restart the VEA Server.

    # /opt/VRTS/bin/vxsvcctrl start

Removing users from Veritas Enterprise Administrator for DB2

You may need to restrict access to the VEA Authorization Database (AZDB). You can remove users or user groups from the AZDB if they have been previously added.


  Note   You cannot remove root from the AZDB.


 To remove users other than root from the Veritas Enterprise Administrator AZDB

  1. Make sure that the optional GUI package was installed.

    # pkginfo -l VRTSd2gui | egrep STATUS

STATUS: completely installed

  1. Stop the VEA server.

    # /opt/VRTS/bin/vxsvcctrl stop

  2. Use the vxdb2edusr command to remove a group or user.

# /opt/VRTS/bin/vxdb2edusr -r {user | group} \

  -n {user_name | group_name} \

[-h fully_qualified_host_name -d domain_name \

-t domain_type]

where -r removes a user or user group from the registry.

For example, to remove the user db2inst1, enter the following:

# /opt/VRTS/bin/vxdb2edusr -r user -n db2inst1

  1. Restart the VEA Server.

    # /opt/VRTS/bin/vxsvcctrl start

Adding Users to Veritas Enterprise Administrator for Oracle

You may want to add users to the VEA Authorization Database (AZDB) to allow access to the interface to users other than root. You also have the option to give database administrators root privileges.

 To add users other than root to the Veritas Enterprise Administrator AZDB

  1. Make sure that the optional GUI package was installed.

# pkginfo -l VRTSorgui | egrep STATUS

STATUS: completely installed

  1. Stop the VEA server.

    # /opt/VRTS/bin/vxsvcctrl stop

  2. To give root privileges to the database administrator, use the vxdbedusr command as follows.
        # /opt/VRTS/bin/vxdbedusr -a {user | group} [-A] [-f] -n \

      user_name [-h fully_qualified_host_name -d domain_name \
 

-t domain_type]

where:

-a user adds a user to the registry

-A grants the user root access

-f allows the user to be a user other than the /opt/VRTSdbed owner.

-n indicates the name of the user.

-h specifies a fully qualified host name on which you want to add a user.

-d specifies the domain to which the user belongs.

-t specifies the type of domain to which the user belongs. Valid values are nis, nisplus, Idap, unixpwd, and gssapi.

For example, to add a database administrator with the name "oracle" as a user with root privileges, enter the following:

# /opt/VRTS/bin/vxdbedusr -a user -A -f -n oracle

  1. To add a user without root privileges, use the vxdbedusr command as follows.

# /opt/VRTS/bin/vxdbedusr -a user -n user_name

where -a adds a user to the registry.

For example, to add "oracle" as a user, enter the following:

# /opt/VRTS/bin/vxdbedusr -a user -n oracle

  1. To add a group to the console registry, use the vxdbedusr command as follows:

# /opt/VRTS/bin/vxdbedusr -a group -n group_name

where -a adds the user group to the registry.

For example, to add "dba" as a group, enter the following:

# /opt/VRTS/bin/vxdbedusr -a group -n dba

  1. Restart the VEA Server.

    # /opt/VRTS/bin/vxsvcctrl start

Removing users from Veritas Enterprise Administrator for Oracle

You may need to restrict access to the VEA Authorization Database (AZDB). You can remove users or user groups from the registry if they have been previously added.


  Note   You cannot remove root from the AZDB.


 To remove users other than root from the Veritas Enterprise Administrator AZDB

  1. Make sure that the optional GUI package was installed.

# pkginfo -l VRTSorgui | egrep STATUS

STATUS: completely installed

  1. Stop the VEA server.

    # /opt/VRTS/bin/vxsvcctrl stop

  2. Use the vxdbedusr command to remove a group or user.

# /opt/VRTS/bin/vxdbedusr -r {user | group} \

  -n {user_name | group_name}

where -r removes a user or user group from the registry.

For example, to remove the user "oracle," enter the following:

# /opt/VRTS/bin/vxdbedusr -r user -n oracle

  1. Restart the VEA Server.

    # /opt/VRTS/bin/vxsvcctrl start