cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
553
Views
0
Helpful
1
Replies

Prime 3.1.1 RBAC issue with bug CSCuz18426

andrewswanson
Level 7
Level 7

Hello

I'm having an issue with configuring RBAC for PI 3 - bug id is

CSCuz18426
Config RBAC read only access is not working for non-root users.
 
I upgraded to 3.1.1 as the release notes state that this bug is resolved:

http://www.cisco.com/c/en/us/td/docs/net_mgmt/prime/infrastructure/3-1-1/release/notes/cpi_rn.html

With PI 3.1.1 I still cannot give Read Only and Deploy access for Configuration Groups. If I apply the bug workaround users can deploy templates but they then have rights to create/design

Has anyone managed to resolve CSCuz18426 with PI 3.1.1

Thanks
Andy

1 Reply 1

andrewswanson
Level 7
Level 7

The following role settings allowed for users to view Config Groups and deploy (but not modify/create) in PI 2.X

Role Tasks/Permissions
Network Configuration

  •  Configuration Templates Read Access
  •  Configure Config Groups 
  •  Deploy Configuring Access

With the above settings, PI 3.1.1 gives the error below when a user tries to access the Config Groups page:

You do not have access to the page 'Configuration Groups'.

If I add the following task/permission to the role, the user can view Config Groups but has Read/Write access 

Network Configuration

  • Design Configuration Template Access

The above was tested with:


Version : 3.1.0
Build : 3.1.0.0.132
Critical Fixes:
        PI 3.1.1 ( 1.0.0 )
Device Support:
        Prime Infrastructure 3.1 Device Pack 1 ( 1.0 )