OpenManage Enterprise Power Manager 3.0

Security Configuration Guide

May 2022 Rev. A00

Notes, Cautions, and Warnings

ℹ️ NOTE: A NOTE indicates important information that helps you make better use of your product.

⚠️ CAUTION: A CAUTION indicates either potential damage to hardware or loss of data and tells you how to avoid the problem.

❗ WARNING: A WARNING indicates a potential for property damage, personal injury, or death.

© 2019-2022 Dell Inc. or its subsidiaries. All rights reserved. Dell Technologies, Dell, and other trademarks are trademarks of Dell Inc. or its subsidiaries. Other trademarks may be trademarks of their respective owners.

Contents

Figures

1Security control map for Power Manager plugin9

Tables

1Role-based user privileges for Power Manager10

Chapter 1: PREFACE

As part of an effort to improve its product lines, Dell EMC periodically releases revisions of its software and hardware. Some functions that are described in this document might not be supported by all versions of the software or hardware currently in use. The product release notes provide the most up-to-date information about product features.

Contact your Dell EMC technical support professional if a product does not function properly or does not function as described in this document. This document was accurate at publication time. To ensure that you are using the latest version of this document, go to https://www.dell.com/support

Scope of the document

This document includes information about security features and capabilities of OpenManage Enterprise Power Manager. Also, use this document to:

Document references

In addition to this guide, you can access other documents of OpenManage Enterprise Power Manager available at https://www.dell.com/support:

Getting help

In addition to the above mentioned guides, see the OpenManage Enterprise Power Manager Online Help and OpenManage Enterprise Online Help integrated in the product.

Chapter 2: Legal disclaimers

THE INFORMATION IN THIS PUBLICATION IS PROVIDED "AS-IS." DELL MAKES NO REPRESENTATIONS OR WARRANTIES OF ANY KIND WITH RESPECT TO THE INFORMATION IN THIS PUBLICATION, AND SPECIFICALLY DISCLAIMS IMPLIED WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. In no event shall Dell Technologies, its affiliates or suppliers, be liable for any damages whatsoever arising from or related to the information contained herein or actions that you decide to take based thereon, including any direct, indirect, incidental, consequential, loss of business profits or special damages, even if Dell Technologies, its affiliates or suppliers have been advised of the possibility of such damages.

The Security Configuration Guide intends to be a reference. The guidance is provided based on a diverse set of installed systems and may not represent the actual risk/guidance to your local installation and individual environment. It is recommended that all users determine the applicability of this information to their individual environments and take appropriate actions. All aspects of this Security Configuration Guide are subject to change without notice and on a case-by-case basis. Your use of the information contained in this document or materials linked herein is at your own risk. Dell reserves the right to change or update this document in its sole discretion and without notice at any time.

Chapter 3: Deployment models

You can download and install Power Manager plug-in from dell.com (online) or from an already downloaded package in a network share (offline). You can configure this setting in OpenManage Enterprise (Application Settings > Console and Plugins > Update Settings). For more information, see the Update settings in OpenManage Enterprise section in OpenManage Enterprise User's Guide.

Prerequisites

Ensure that your connectivity to the repository is successful:

Steps

  1. Launch Dell EMC OpenManage Enterprise, and then click Application Settings > Console and Plugins. The Console and Plugins page is displayed.
  2. In the Power Manager section, click Install. The Install Plugin page is displayed.
  3. Select the plugin version (if there are multiple versions of the plugin that is supported on existing OpenManage Enterprise version) from the Available Version(s) drop-down menu and review to ensure that you meet the list of prerequisites that are mentioned in the Prerequisites section. ℹ️ NOTE: Only the versions of the plugin that is supported on the installed version of OpenManage Enterprise is listed in the Available Version(s) drop-down menu.
  4. Click Download plugin. The progress of download is displayed, and then the plugin is downloaded and the status of the plugin is updated to Downloaded on the Console and Plugins page.
  5. In Install Details page, click Install plugin. The Install Plugin window is displayed.

Chapter 4: Product and Subsystem Security

Topics:

Security controls map

Power Manager uses fine-grained instrumentation to provide increased visibility to power consumption, anomalies, and utilization. Power Manager alerts and reports about power and thermal events in servers, chassis, and custom groups consisting of servers and chassis. This reporting enables increased control, faster response times, greater accuracy, and broader decision-making intelligence than is otherwise possible.

Figure 1. Security control map for Power Manager plugin

The security control map illustrates the flow of information and connections within the Power Manager ecosystem. A Browser or REST Client connects to OpenManage Enterprise via HTTPS. OpenManage Enterprise then communicates with the Power Manager Plugin, also via HTTPS. The Power Manager Plugin interacts with Devices using protocols such as WSMan, Redfish, SSH, or SNMP. This setup ensures secure communication channels for managing power and system data.

Authentication

Access control settings provide protection of resources against unauthorized access. Only Administrators, Device Managers, and Viewers have access to Power Manager plug-in features with appropriate roles and privileges configured. For feature-based access details, see the OpenManage Enterprise Power Manager and OpenManage Enterprise User's Guide.

Rest API security

For the rest API security-related information, see the Security section in OpenManage Enterprise Power Manager RESTful API Guide.

Login security settings

There are various security configurations available in OpenManage Enterprise which when applied in OpenManage Enterprise gets automatically applied to Power Manager plug-in. For example, you can provide an IP range where only the devices that are specified in the IP range can access OpenManage Enterprise, block a user by specifying the username or an IP address, or lock a user for a specific duration after multiple failed attempts. For more details, see the Set the login security properties topic in OpenManage Enterprise User's Guide.

User and credential management

Each user is assigned certain privileges that determine their access level in OpenManage Enterprise. For information about the user roles and feature-based access privileges for OpenManage Enterprise and Power Manager, see the Dell EMC OpenManage Enterprise User's Guide and Dell EMC OpenManage Enterprise Power Manager User's Guide.

Role and scope-based access control in OpenManage Enterprise

OpenManage Enterprise has Role Based Access Control (RBAC) that clearly defines the user privileges for the three built-in roles—Administrator, Device Manager, and Viewer. Additionally, using the Scope-Based Access Control (SBAC) an administrator can limit the device groups that a device manager has access to. The following topics further explain the RBAC and SBAC features.

Role-Based Access Control (RBAC) privileges in OpenManage Enterprise

Users are assigned roles which determine their level of access to the appliance settings and device management features. This feature is termed as Role-Based Access Control (RBAC). The console enforces the privilege required for a certain action before allowing the action.

This table lists the various privileges that are enabled for each role.

Table 1. Role-based user privileges for Power Manager

FeaturesAdministratorDevice Manager (scope for assigned groups)Device Manager (scope for non-assigned groups)Viewer
Install Power ManagerYesNoNoNo
Upgrade Power ManagerYesNoNoNo
Enable Power ManagerYesNoNoNo
Disable Power ManagerYesNoNoNo
Uninstall Power ManagerYesNoNoNo
Add or remove supported devices from Power ManagerYesYesNoNo
Add or remove static groups from Power ManagerYesYesNoNo
Add or remove unmonitored devices from Power ManagerYesNoNoNo
Add or remove Power Distribution Units (PDUs) from Power ManagerYesNoNoNo
Monitor PDUsYesYesNoYes
Create, edit, or delete Physical GroupsYesNoNoNo
Import physical groups through CSV fileYesNoNoNo
Manage the devices in rackYesNoNoNo
Monitor metricsYesYesNoYes
Manage power policies for devicesYesYesNoNo
Manage power policies for groupsYesYesNoNo
Manage temperature-triggered policies for groupYesYesNoNo
Manage alert thresholds for devicesYesYesNoNo
Manage alert thresholds for groupsYesYesNoNo
View alert thresholds in Power ManagerYesYesNoYes
Modify Power Manager SettingsYesNoNoNo
View SettingsYesYesYesYes
Manage Power Manager Emergency Power Reduction (EPR) for devicesYesYesNoNo
Manage EPR for groupsYesYesNoNo
Run and view reports for devices and groupsYesYesNoYes
Manage custom reports for devicesYesYesNoNo
Manage custom reports for groupsYesYesNoNo
View eventsYesYesNoYes
DashboardYesYesNoYes
Create, edit, or delete VM GroupsYesNoNoNo
Analyze usage metricsYesYesNoYes
Automatically create physical hierarchyYesNoNoNo
View maximum and minimum power consumption of VMs on the Overview pageYesYesNoYes
Disable LCS Event-triggered EPRYesNoNoNo
Enable and disable Liquid cooling system alert policyYesNoNoNo
View maximum and minimum power consumption of VM groups on the Overview pageYesYesYesYes
Update device location in device consoleYesNoNoNo
View idle serversYesYesNoYes

Scope-Based Access Control (SBAC) in OpenManage Enterprise

With the use of Role-Based Access Control (RBAC) feature, administrators can assign roles while creating users. Roles determine their level of access to the appliance settings and device management features. Scope-based Access Control (SBAC) is an extension of the RBAC feature that allows an administrator to restrict a Device Manager role to a subset of device groups called scope.

While creating or updating a Device Manager (DM) user, administrators can assign scope to restrict operational access of DM to one or more system groups, custom groups, and / or plugin groups. Administrator and Viewer roles have unrestricted scope. That means they have operational access as specified by RBAC privileges to all devices and groups entities.

Scope can be implemented as follows:

  1. Create or Edit User
  2. Assign DM role
  3. Assign scope to restrict operational access

A natural outcome of the SBAC functionality is the Restricted View feature. With Restricted View, particularly the Device Managers will see only the following:

It should be noted that if the scope of a Device Manager is 'unrestricted', then that Device Manager can view all the devices and groups, however, would only be able to see the entities owned by him/her such as jobs, alert policies, baselines, and so on along with the community and built-in entities of any kind.

When a Device Manager (DM) user with an assigned scope logs in, the DM can see and manage scoped devices only. Also, the DM can see and manage entities such as jobs, firmware or configuration templates and baselines, alert policies, profiles and so on associated with scoped devices, only if the DM owns the entity (DM has created that entity or is assigned ownership of that entity). For more information about the entities a DM can create, see Role-Based Access Control (RBAC) privileges in OpenManage Enterprise.

In OpenManage Enterprise, scope can be assigned while creating a local or importing AD/LDAP user. Scope assignment for OIDC users can be done only on Open ID Connect (OIDC) providers.

SBAC for Local users:

While creating or editing a local user with DM role, admin can select one or more device groups that defines the scope for the DM.

For example, you (as an administrator) create a DM user named dm1 and assign group g1 present under custom groups. Then dm1 will have operational access to all devices in g1 only. The user dm1 will not be able to access any other groups or entities related to any other devices.

Furthermore, with SBAC, dm1 will also not be able to see the entities created by other DMs (let's say dm2) on the same group g1. That means a DM user will only be able to see the entities owned by the user.

For example, you (as an administrator) create another DM user named dm2 and assign the same group g1 present under custom groups. If dm2 creates configuration template, configuration baselines, or profiles for the devices in g1, then dm1 will not have access to those entities and vice versa.

A DM with scope to All Devices has operational access as specified by RBAC privileges to all devices and group entities owned by the DM.

SBAC for AD/LDAP users:

While importing or editing AD/LDAP groups, administrators can assign scopes to user groups with DM role. If a user is a member of multiple AD groups, each with a DM role, and each AD group has distinct scope assignments, then the scope of the user is the union of the scopes of those AD groups.

For example,

When a user is a member of multiple AD groups that have different roles, the higher-functionality role takes precedence (in the order Administrator, DM, Viewer).

A DM with unrestricted scope has operational access as specified by RBAC privileges to all device and group entities.

SBAC for OIDC users:

Scope assignment for OIDC users does not happen within the OME console. You can assign scopes for OIDC users at an OIDC provider during user configuration. When the user logs in with OIDC provider credentials, the role and scope assignment will be available to OME. For more information about configuring user roles and scopes, see Configure an OpenID Connect provider policy in PingFederate for role section in OpenManage Enterprise User's Guide.

Transfer ownership

The administrator can transfer owned resources from a device manager (source) to another device manager. For example, an administrator can transfer all the resources assigned from a source dm1 to dm2. A device manager with owned entities such as firmware and/or configuration baselines, configuration templates, alert policies, and profiles is considered an eligible source user. Transfer of ownership transfers only the entities and not the device groups (scope) owned by a device manager to another. For more information see, Transfer of ownership of Device Manager entities section in OpenManage Enterprise User's Guide.

Data security

The data that is maintained by Power Manager is stored and secured in internal databases within the appliance and it cannot be accessed from outside. The data that is transferred through Power Manager is secured by secure communication channel.

Cryptography

Sensitive data is encrypted and stored in an internal database. For more information, see the Security features in OpenManage Enterprise section in OpenManage Enterprise User's Guide.

Auditing and logging

Power Manager lists all the actions that are performed on the monitored devices in audit logs. Use the OpenManage Enterprise console to generate the audit logs with all the relevant information. You can export the audit log files to a CSV file format.

Alerting

Automate your actions for the alerts generated, manage the alerts and forward the alerts that are generated in OpenManage Enterprise. For more information, see the Alert policies section in OpenManage Enterprise User's Guide.

Chapter 5: Contacting Dell

Prerequisites

ℹ️ NOTE: If you do not have an active Internet connection, you can find contact information on your purchase invoice, packing slip, bill, or Dell product catalog.

About this task

Dell provides several online and telephone-based support and service options. Availability varies by country and product, and some services may not be available in your area. To contact Dell for sales, technical support, or customer service issues:

Steps

  1. Go to Dell.com/support.
  2. Select your support category.
  3. Verify your country or region in the Choose a Country/Region drop-down list at the bottom of the page.
  4. Select the appropriate service or support link based on your need.
Models: OpenManage Enterprise Power Manager 3.0, Enterprise Power Manager 3.0, Power Manager 3.0, Manager 3.0

File Info : application/pdf, 15 Pages, 123.09KB

PDF preview unavailable. Download the PDF instead.

pmp-3-0-security-guide-en-us

References

Antenna House PDF Output Library 7.1.1629

Related Documents

Preview Dell EMC OpenManage Enterprise 3.2 User's Guide
Comprehensive guide to Dell EMC OpenManage Enterprise version 3.2, covering installation, configuration, device management, firmware updates, security features, and reporting for Dell servers, chassis, storage, and network switches.
Preview Dell EMC Repository Manager 3.0 User's Guide | Manage System Updates
Comprehensive user guide for Dell EMC Repository Manager (DRM) version 3.0. Learn how to create and manage repositories, download updates, and deploy system firmware, drivers, and BIOS.
Preview Dell EMC OpenManage Enterprise Power Manager v3.0 Release Notes | Features, Issues, and Updates
Dell EMC OpenManage Enterprise Power Manager v3.0 Release Notes detailing new features, resolved issues, known issues, and limitations for the enterprise power management software.
Preview Dell EMC OpenManage Plug-in 3.2.0 for Nagios Core: Security Configuration Guide
Securely manage Dell hardware with the Dell EMC OpenManage Plug-in v3.2.0 for Nagios Core. This guide covers authentication, data security, network security, and integrity verification for PowerEdge servers, modular infrastructure, and more.
Preview Dell EMC OpenManage Enterprise 3.0 Release Notes
This document provides release notes for Dell EMC OpenManage Enterprise Version 3.0, detailing new features, enhancements, and known issues.
Preview Installing Dell EMC OpenManage Essentials: A Comprehensive Guide
This technical white paper provides a detailed guide on installing, maintaining, and upgrading Dell EMC OpenManage Essentials (OME), covering prerequisites, installation procedures, and troubleshooting.
Preview Dell EMC OpenManage Enterprise Update Manager v1.0 Release Notes
Release notes for Dell EMC OpenManage Enterprise Update Manager Version 1.0, detailing new features, known issues, and recommendations for IT administrators managing PowerEdge devices.
Preview Dell EMC Systems Management Tools & Documentation Consoles v10.2.0.0 Release Notes
Official release notes for Dell EMC Systems Management Tools and Documentation Management Consoles version 10.2.0.0, detailing new features, enhancements, and fixed issues for server and storage management.