Chapter 4 Managing GSS User Accounts Through a Server
Configuring a Server for Use with the GSS
4-12
Cisco Global Site Selector Administration Guide
OL-10410-01
This section contains the following topics:
•
Configuring Primary GSSM GUI Privilege Level Authorization from the
Server
•
Enabling Custom User GUI Views When Authenticating a User from the
Server
Configuring Primary GSSM GUI Privilege Level Authorization from the
Server
You can configure the Cisco Secure ACS server to define the privilege
level (role) of a user when accessing the primary GSSM GUI. The primary GSSM
GUI learns the user’s associated privilege level when communicating with the
server. This capability provides the administrator with the
flexibility to dynamically change a user’s privilege level without requiring that the
user terminate a GUI session and log back in to the primary GSSM.
Users are assigned privileges based on whether they are using the GUI or the GLI
on the primary GSSM as follows:
•
For users who are using the GUI, the privilege configured on the
server takes preference over any privilege configured on the GSS.
•
For users who are using the CLI, the privilege configured on the GSS takes
preference over the privilege configured on the server. If a user is
not
configured locally, then the user is assigned the user privilege by default
(regardless of the privilege configured on the server).
If you configure the server to allow all commands, the user is
automatically set to administrator and has all associated privileges. See the
“Privilege Levels for Using the Primary GSSM GUI”
section in
Chapter 3,
Creating and Managing User Accounts
for more information.
Note
Primary GSSM GUI privileges assigned to a user from the server
override the user privilege level defined from the primary GSSM GUI GSSM User
Administration details page.