Forum Discussion

Chura_16140's avatar
Chura_16140
Icon for Nimbostratus rankNimbostratus
Jul 10, 2014

Authorization

Hello,

 

I'm using TACACS+ to control access to my LTM's (Relevant device running 11.5.0HF4). I would like to allow one of my users to have a Guest TMSH account however allow him to delete the RAM cache as well. How can I achieve this ?

 

Thanks!

 

4 Replies

  • Hi, may be Icontrol could be a solution, creating a dedicate script (somehow compiled to hide login/password) for him to play with ram cache objects until we have a better RBAC.

     

  • Yes, The Dev Team working on it. So I guess currently its impossible ?

     

    Thanks!

     

  • today guess role doesn't have access to delete command used to delete ramcache, and we cannot add more action to this role. i'm not familiar to cli scripting but first tests shows that it's not elevating privilege.

     

  • We're working on iControl to do so. But again i'm facing a problem. The DEV need a user for it, and this user need full access right ? Or can I set a user to be able to run via iControl only ?