<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VMware ESXi 5.5 local users for CIM Monitoring role in ESXi Discussions</title>
    <link>https://communities.vmware.com/t5/ESXi-Discussions/VMware-ESXi-5-5-local-users-for-CIM-Monitoring-role/m-p/1776433#M171458</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I will check this out and get back to you once i have an answer &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://communities.vmware.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt; &lt;/P&gt;&lt;P&gt;For now please use the admin privileges and go ahead with the integration &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://communities.vmware.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 02 Dec 2013 18:39:26 GMT</pubDate>
    <dc:creator>abhilashhb</dc:creator>
    <dc:date>2013-12-02T18:39:26Z</dc:date>
    <item>
      <title>VMware ESXi 5.5 local users for CIM Monitoring role</title>
      <link>https://communities.vmware.com/t5/ESXi-Discussions/VMware-ESXi-5-5-local-users-for-CIM-Monitoring-role/m-p/1776419#M171444</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, Is it possible to create local users in ESXi and assign permissions/roles to manage CIM interactions alone ? I learnt that local groups are not supported from 5.1 onwards. Does it mean that we can not add a role ( For CIM Interactions alone ) for a local user created on ESXi? Please advise!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Nov 2013 18:25:20 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/ESXi-Discussions/VMware-ESXi-5-5-local-users-for-CIM-Monitoring-role/m-p/1776419#M171444</guid>
      <dc:creator>krishnaprasad</dc:creator>
      <dc:date>2013-11-29T18:25:20Z</dc:date>
    </item>
    <item>
      <title>Re: VMware ESXi 5.5 local users for CIM Monitoring role</title>
      <link>https://communities.vmware.com/t5/ESXi-Discussions/VMware-ESXi-5-5-local-users-for-CIM-Monitoring-role/m-p/1776420#M171445</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Krishnaprasad,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can add a new user and give him just CIM Interaction role. Just confirmed it on my test 5.5 host &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://communities.vmware.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Nov 2013 18:58:40 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/ESXi-Discussions/VMware-ESXi-5-5-local-users-for-CIM-Monitoring-role/m-p/1776420#M171445</guid>
      <dc:creator>abhilashhb</dc:creator>
      <dc:date>2013-11-29T18:58:40Z</dc:date>
    </item>
    <item>
      <title>Re: VMware ESXi 5.5 local users for CIM Monitoring role</title>
      <link>https://communities.vmware.com/t5/ESXi-Discussions/VMware-ESXi-5-5-local-users-for-CIM-Monitoring-role/m-p/1776421#M171446</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the reply Abhilash. Looks like I am missing something. Could you please help with the exact steps ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are the steps that i have followed:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Created a local user using vCenter Client (Via Local Users &amp;amp; Groups section )&lt;/P&gt;&lt;P&gt;2. This can not be added to a group since it's not supported from 5.1 onwards i suppose ? &lt;/P&gt;&lt;P&gt;3. Now created a role using vSphere Web client by selecting the&amp;nbsp; CIM interactions&lt;/P&gt;&lt;P&gt;4. Using Webclient, Traverse to Manage --&amp;gt; Permissions. Add Permission. But "Users &amp;amp; Groups" dont list user created in 1st step!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you follow this procedure to assign a role for a specific user ? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 30 Nov 2013 08:46:19 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/ESXi-Discussions/VMware-ESXi-5-5-local-users-for-CIM-Monitoring-role/m-p/1776421#M171446</guid>
      <dc:creator>krishnaprasad</dc:creator>
      <dc:date>2013-11-30T08:46:19Z</dc:date>
    </item>
    <item>
      <title>Re: VMware ESXi 5.5 local users for CIM Monitoring role</title>
      <link>https://communities.vmware.com/t5/ESXi-Discussions/VMware-ESXi-5-5-local-users-for-CIM-Monitoring-role/m-p/1776422#M171447</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi krishnaprasad,&lt;/P&gt;&lt;P&gt;Sure i can help you. &lt;/P&gt;&lt;P&gt;Here's what you are doing. You are logging into the host directly and creating a local user. And you are trying to add that user to vcenter permissions. The "local" user that you created on the host is local to your host and will not appear in vCenter. It can only be assigned when you log into the host directly using vSphere client.&lt;/P&gt;&lt;P&gt;Do this.&lt;/P&gt;&lt;P&gt;Go to your vCenter roles, Create a role with just CIM Interactions.&lt;/P&gt;&lt;P&gt;I hope you have a domain mapped to your vCenter. So create user on the AD as CIM-user.&lt;/P&gt;&lt;P&gt;Now click on vCenter and go to permissions, Click Add permission. Import this user CIM-User with the CIM Interactions role and click ok.&lt;/P&gt;&lt;P&gt;Now the user will be able to do the CIM tasks on each host.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 30 Nov 2013 11:07:19 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/ESXi-Discussions/VMware-ESXi-5-5-local-users-for-CIM-Monitoring-role/m-p/1776422#M171447</guid>
      <dc:creator>abhilashhb</dc:creator>
      <dc:date>2013-11-30T11:07:19Z</dc:date>
    </item>
    <item>
      <title>Re: VMware ESXi 5.5 local users for CIM Monitoring role</title>
      <link>https://communities.vmware.com/t5/ESXi-Discussions/VMware-ESXi-5-5-local-users-for-CIM-Monitoring-role/m-p/1776423#M171448</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the help. I don't have an AD domain created. So i guess I dont have any other option to use a local user ( loca to ESXi ) for CIM Interactions right ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 30 Nov 2013 15:02:09 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/ESXi-Discussions/VMware-ESXi-5-5-local-users-for-CIM-Monitoring-role/m-p/1776423#M171448</guid>
      <dc:creator>krishnaprasad</dc:creator>
      <dc:date>2013-11-30T15:02:09Z</dc:date>
    </item>
    <item>
      <title>Re: VMware ESXi 5.5 local users for CIM Monitoring role</title>
      <link>https://communities.vmware.com/t5/ESXi-Discussions/VMware-ESXi-5-5-local-users-for-CIM-Monitoring-role/m-p/1776424#M171449</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can create a local user in SSO-domainn and map him to this role.&lt;/P&gt;&lt;P&gt;This will help you for that.&lt;/P&gt;&lt;P&gt;&lt;A href="http://pubs.vmware.com/vsphere-51/index.jsp?topic=%2Fcom.vmware.vsphere.security.doc%2FGUID-72BFF98C-C530-4C50-BF31-B5779D2A4BBB.html" title="http://pubs.vmware.com/vsphere-51/index.jsp?topic=%2Fcom.vmware.vsphere.security.doc%2FGUID-72BFF98C-C530-4C50-BF31-B5779D2A4BBB.html"&gt;VMware vSphere 5.1&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #666666; font-family: proxima-nova, Arial, sans-serif; font-size: 14px;"&gt;If you found my answer useful, consider awarding points by choosing correct and helpful answers &lt;/SPAN&gt;&lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://communities.vmware.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 01 Dec 2013 15:44:04 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/ESXi-Discussions/VMware-ESXi-5-5-local-users-for-CIM-Monitoring-role/m-p/1776424#M171449</guid>
      <dc:creator>abhilashhb</dc:creator>
      <dc:date>2013-12-01T15:44:04Z</dc:date>
    </item>
    <item>
      <title>Re: VMware ESXi 5.5 local users for CIM Monitoring role</title>
      <link>https://communities.vmware.com/t5/ESXi-Discussions/VMware-ESXi-5-5-local-users-for-CIM-Monitoring-role/m-p/1776425#M171450</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;THanks Again. I created a user and added permission. Infact i had given full permission. But I can't login using this newly created user via wbemcli (opensource CIM Management tool) or vSphere Client. Here are the steps followed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. From Webclient, Traversed to Administration --&amp;gt; Access. Under "SSO Users and Groups" --&amp;gt; Users tab --&amp;gt; Created a user&lt;/P&gt;&lt;P&gt;2. Traversed to Groups tab under the same section and added the user. Here the domain of the user is showed as "System-Domain". Where as for root it showed 'localos'. &lt;/P&gt;&lt;P&gt;3. From Role Manager section, Created a new Role with just CIM access ( tried Full access as well)&lt;/P&gt;&lt;P&gt;4. From ESXi host connected to webclient, traversed to 'Manage' --&amp;gt; Permissions, Added the new user and assigned the newly created role. Save the changes&lt;/P&gt;&lt;P&gt;5. Try connecting from vSphere client using the user shows "incorrect user name / password". &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any steps missing? Appreciate your help!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 01 Dec 2013 18:47:41 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/ESXi-Discussions/VMware-ESXi-5-5-local-users-for-CIM-Monitoring-role/m-p/1776425#M171450</guid>
      <dc:creator>krishnaprasad</dc:creator>
      <dc:date>2013-12-01T18:47:41Z</dc:date>
    </item>
    <item>
      <title>Re: VMware ESXi 5.5 local users for CIM Monitoring role</title>
      <link>https://communities.vmware.com/t5/ESXi-Discussions/VMware-ESXi-5-5-local-users-for-CIM-Monitoring-role/m-p/1776426#M171451</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV&gt;&lt;P&gt;Are you trying to login to the host using that user? It will not work. Webclient is to manage vcenter. The permissions will work if you login into vcenter using vsphere client or webclient. Once logged in the user will have CI'M interaction on all hosts.&lt;/P&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 01 Dec 2013 18:55:33 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/ESXi-Discussions/VMware-ESXi-5-5-local-users-for-CIM-Monitoring-role/m-p/1776426#M171451</guid>
      <dc:creator>abhilashhb</dc:creator>
      <dc:date>2013-12-01T18:55:33Z</dc:date>
    </item>
    <item>
      <title>Re: VMware ESXi 5.5 local users for CIM Monitoring role</title>
      <link>https://communities.vmware.com/t5/ESXi-Discussions/VMware-ESXi-5-5-local-users-for-CIM-Monitoring-role/m-p/1776427#M171452</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ok. I think I understood the problem. The SSO user created is specific to the vCenter and the specific ESXi host dont have any information about this user. My requirement is little different. I need to communicate to ESXi host directly using non root user with out using vCenter. Is that possible? As you may know, there is an opensource tool available wbemcli (&lt;A href="http://pic.dhe.ibm.com/infocenter/zos/v1r11/index.jsp?topic=/com.ibm.zos.r11.idarc00/wbemcli.htm"&gt;http://pic.dhe.ibm.com/infocenter/zos/v1r11/index.jsp?topic=/com.ibm.zos.r11.idarc00/wbemcli.htm&lt;/A&gt;) which can communicate with ESXi CIMOM/SFCB by talking to port 5989. Using root user, I am able to communicate remotely. I want to know if its possible using non root user ( local to ESXi ). &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Dec 2013 05:43:47 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/ESXi-Discussions/VMware-ESXi-5-5-local-users-for-CIM-Monitoring-role/m-p/1776427#M171452</guid>
      <dc:creator>krishnaprasad</dc:creator>
      <dc:date>2013-12-02T05:43:47Z</dc:date>
    </item>
    <item>
      <title>Re: VMware ESXi 5.5 local users for CIM Monitoring role</title>
      <link>https://communities.vmware.com/t5/ESXi-Discussions/VMware-ESXi-5-5-local-users-for-CIM-Monitoring-role/m-p/1776428#M171453</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok now we are back to square one. You need to create users on each host and link it to wbemcli right?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now login into every host that you want to link to wbemcli using vSphere client,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Go to roles and create a new role with just CIM interactions.&lt;/P&gt;&lt;P&gt;Then go to local users and groups and create a new user.&lt;/P&gt;&lt;P&gt;Click on the host, go to permissions tab and add this user there with the CIM role.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you need to do it on all hosts.&lt;/P&gt;&lt;P&gt;And then you can link these accounts to wbemcli and use it. the users will loaclly work. I have tried that as i mentioned in my first comment.&lt;/P&gt;&lt;P&gt;Let me know if you any more help &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://communities.vmware.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Dec 2013 07:06:34 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/ESXi-Discussions/VMware-ESXi-5-5-local-users-for-CIM-Monitoring-role/m-p/1776428#M171453</guid>
      <dc:creator>abhilashhb</dc:creator>
      <dc:date>2013-12-02T07:06:34Z</dc:date>
    </item>
    <item>
      <title>Re: VMware ESXi 5.5 local users for CIM Monitoring role</title>
      <link>https://communities.vmware.com/t5/ESXi-Discussions/VMware-ESXi-5-5-local-users-for-CIM-Monitoring-role/m-p/1776429#M171454</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I did that ! But unless, I give the "administrator" role to the newly created user OR /etc/security/access.conf is modified, it says "Invalid user/password". Let's say if I create a new role by just selecting Host --&amp;gt; CIM --&amp;gt; CIM Interactions. From the permissions tab, assigned the new role to the new user created. However wbemcli showed invalid username/password. If the user is assigned with "Administrator" role, it works fine as expected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;I also see that when /etc/security/access.conf is modified from '-' to '+' for the specific user, wbemcli started working for this user.&amp;nbsp; I dont think /etc/security/access.conf editing is supposed to be done manually. Anything missing here ? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;When access.conf is not modified&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;~# wbemcli -dx ec -noverify &lt;/SPAN&gt;&lt;A _jive_internal="true" href="https://communities.vmware.com/"&gt;https://&lt;/A&gt;&lt;SPAN&gt;&amp;lt;user&amp;gt;:&amp;lt;password@&amp;lt;ESXi IP&amp;gt;/root/cimv2&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;To server: &amp;lt;?xml version="1.0" encoding="utf-8" ?&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;CIM CIMVERSION="2.0" DTDVERSION="2.0"&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;MESSAGE ID="4711" PROTOCOLVERSION="1.0"&amp;gt;&amp;lt;SIMPLEREQ&amp;gt;&amp;lt;IMETHODCALL NAME="EnumerateClasses"&amp;gt;&amp;lt;LOCALNAMESPACEPATH&amp;gt;&amp;lt;NAMESPACE NAME="root"&amp;gt;&amp;lt;/NAMESPACE&amp;gt;&amp;lt;NAMESPACE NAME="cimv2"&amp;gt;&amp;lt;/NAMESPACE&amp;gt;&amp;lt;/LOCALNAMESPACEPATH&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;IPARAMVALUE NAME="DeepInheritance"&amp;gt;&amp;lt;VALUE&amp;gt;TRUE&amp;lt;/VALUE&amp;gt;&amp;lt;/IPARAMVALUE&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;IPARAMVALUE NAME="LocalOnly"&amp;gt;&amp;lt;VALUE&amp;gt;FALSE&amp;lt;/VALUE&amp;gt;&amp;lt;/IPARAMVALUE&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;IPARAMVALUE NAME="IncludeQualifiers"&amp;gt;&amp;lt;VALUE&amp;gt;FALSE&amp;lt;/VALUE&amp;gt;&amp;lt;/IPARAMVALUE&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;IPARAMVALUE NAME="IncludeClassOrigin"&amp;gt;&amp;lt;VALUE&amp;gt;TRUE&amp;lt;/VALUE&amp;gt;&amp;lt;/IPARAMVALUE&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;/IMETHODCALL&amp;gt;&amp;lt;/SIMPLEREQ&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;/MESSAGE&amp;gt;&amp;lt;/CIM&amp;gt;&lt;/P&gt;&lt;P&gt;From server: WWW-Authenticate: Basic realm="cimom"&lt;/P&gt;&lt;P&gt;From server: Server: sfcHttpd&lt;/P&gt;&lt;P&gt;From server: Content-Length: 0&lt;/P&gt;&lt;P&gt;*&lt;/P&gt;&lt;P&gt;* wbemcli: Http Exception: Invalid username/password.&lt;/P&gt;&lt;P&gt;*&lt;/P&gt;&lt;P&gt;~#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;With access.conf modified&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;~# wbemcli -dx ec -noverify &lt;/SPAN&gt;&lt;A _jive_internal="true" href="https://communities.vmware.com/"&gt;https://&lt;/A&gt;&lt;SPAN&gt;&amp;lt;user&amp;gt;:&amp;lt;password@&amp;lt;ESXi IP&amp;gt;/root/cimv2&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;lt;ESXi IP&amp;gt;:5989/root/cimv2:CIM_RoleBasedAuthorizationService&lt;/P&gt;&lt;P&gt;&amp;lt;ESXi IP&amp;gt;:5989/root/cimv2:OMC_ProcessorRealizes&lt;/P&gt;&lt;P&gt;&amp;lt;ESXi IP&amp;gt;:5989/root/cimv2:VMware_Battery&lt;/P&gt;&lt;P&gt;....&lt;/P&gt;&lt;P&gt;~#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any clues ? Thanks much for the help!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Dec 2013 09:06:04 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/ESXi-Discussions/VMware-ESXi-5-5-local-users-for-CIM-Monitoring-role/m-p/1776429#M171454</guid>
      <dc:creator>krishnaprasad</dc:creator>
      <dc:date>2013-12-02T09:06:04Z</dc:date>
    </item>
    <item>
      <title>Re: VMware ESXi 5.5 local users for CIM Monitoring role</title>
      <link>https://communities.vmware.com/t5/ESXi-Discussions/VMware-ESXi-5-5-local-users-for-CIM-Monitoring-role/m-p/1776430#M171455</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Saw the similar issue discussed in forum &lt;A _jive_internal="true" href="https://communities.vmware.com/message/1646911#1646911"&gt;https://communities.vmware.com/message/1646911#1646911&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Dec 2013 18:09:02 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/ESXi-Discussions/VMware-ESXi-5-5-local-users-for-CIM-Monitoring-role/m-p/1776430#M171455</guid>
      <dc:creator>krishnaprasad</dc:creator>
      <dc:date>2013-12-02T18:09:02Z</dc:date>
    </item>
    <item>
      <title>Re: VMware ESXi 5.5 local users for CIM Monitoring role</title>
      <link>https://communities.vmware.com/t5/ESXi-Discussions/VMware-ESXi-5-5-local-users-for-CIM-Monitoring-role/m-p/1776431#M171456</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV&gt;&lt;P&gt;Why not give a user administrative privilege? May be it needs admin access to host and not just CIM interactions. Any issue with giving admin privileges?&lt;/P&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Dec 2013 18:23:43 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/ESXi-Discussions/VMware-ESXi-5-5-local-users-for-CIM-Monitoring-role/m-p/1776431#M171456</guid>
      <dc:creator>abhilashhb</dc:creator>
      <dc:date>2013-12-02T18:23:43Z</dc:date>
    </item>
    <item>
      <title>Re: VMware ESXi 5.5 local users for CIM Monitoring role</title>
      <link>https://communities.vmware.com/t5/ESXi-Discussions/VMware-ESXi-5-5-local-users-for-CIM-Monitoring-role/m-p/1776432#M171457</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;nothing as such. but wanted to know why access.conf was not modified though the role was added for CIM Interaction. any ways thanks for all the help. I am closing this thread.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Dec 2013 18:35:20 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/ESXi-Discussions/VMware-ESXi-5-5-local-users-for-CIM-Monitoring-role/m-p/1776432#M171457</guid>
      <dc:creator>krishnaprasad</dc:creator>
      <dc:date>2013-12-02T18:35:20Z</dc:date>
    </item>
    <item>
      <title>Re: VMware ESXi 5.5 local users for CIM Monitoring role</title>
      <link>https://communities.vmware.com/t5/ESXi-Discussions/VMware-ESXi-5-5-local-users-for-CIM-Monitoring-role/m-p/1776433#M171458</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I will check this out and get back to you once i have an answer &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://communities.vmware.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt; &lt;/P&gt;&lt;P&gt;For now please use the admin privileges and go ahead with the integration &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://communities.vmware.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Dec 2013 18:39:26 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/ESXi-Discussions/VMware-ESXi-5-5-local-users-for-CIM-Monitoring-role/m-p/1776433#M171458</guid>
      <dc:creator>abhilashhb</dc:creator>
      <dc:date>2013-12-02T18:39:26Z</dc:date>
    </item>
    <item>
      <title>Re: VMware ESXi 5.5 local users for CIM Monitoring role</title>
      <link>https://communities.vmware.com/t5/ESXi-Discussions/VMware-ESXi-5-5-local-users-for-CIM-Monitoring-role/m-p/1776434#M171459</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Anyone figure this out on 5.5? We have people that need access to Dell's OMSA interface to be able to troubleshoot things like failed HDDs and do not want them to be full root admins, since 5.5 this seems to be an impossible task.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Jun 2015 13:13:30 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/ESXi-Discussions/VMware-ESXi-5-5-local-users-for-CIM-Monitoring-role/m-p/1776434#M171459</guid>
      <dc:creator>kluken</dc:creator>
      <dc:date>2015-06-26T13:13:30Z</dc:date>
    </item>
    <item>
      <title>Re: VMware ESXi 5.5 local users for CIM Monitoring role</title>
      <link>https://communities.vmware.com/t5/ESXi-Discussions/VMware-ESXi-5-5-local-users-for-CIM-Monitoring-role/m-p/1776435#M171460</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN style="color: #000000; font-size: 10pt; font-family: 'trebuchet ms', geneva;"&gt;We can create a local user in ESXi and assign it only for accessing sfcb (CIM). &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL style="list-style-type: decimal;"&gt;&lt;LI&gt;&lt;SPAN style="color: #000000; font-family: 'trebuchet ms', geneva; font-size: 10pt;"&gt;Create a local user in ESXi (Using esxcli system account add)&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="color: #000000; font-family: 'trebuchet ms', geneva; font-size: 10pt;"&gt;Add permission only for sfcbd by editing /etc/security/access.conf&lt;/SPAN&gt;&lt;OL style="list-style-type: lower-alpha;"&gt;&lt;LI&gt;&lt;SPAN style="color: #000000; font-family: 'trebuchet ms', geneva; font-size: 10pt;"&gt;+:cimuser:sfcb&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: 'trebuchet ms', geneva; font-size: 10pt;"&gt;&amp;nbsp; 3.&amp;nbsp;&amp;nbsp; Now a remote client can access VMware CIM classes using this local user account. However ssh and other root&amp;nbsp; permissions will not be available for this user. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: 'trebuchet ms', geneva; font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 10pt; font-family: 'trebuchet ms', geneva;"&gt;I hope this is what we were looking for ? . However note that /etc/security/access.conf is recreated on every boot and hence whatever modifications done to this file manually may not be persistent (need to check though). &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 10pt; font-family: 'trebuchet ms', geneva;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 10pt; font-family: 'trebuchet ms', geneva;"&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 10pt; font-family: 'trebuchet ms', geneva;"&gt;Krishnaprasad&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Jul 2015 17:27:59 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/ESXi-Discussions/VMware-ESXi-5-5-local-users-for-CIM-Monitoring-role/m-p/1776435#M171460</guid>
      <dc:creator>krishnaprasad</dc:creator>
      <dc:date>2015-07-07T17:27:59Z</dc:date>
    </item>
  </channel>
</rss>

