Bookmark this page

Summary

  • You can define access controls to delegate lifecycle administrative tasks, such as creating users and changing passwords, to a nonadministrative user.

  • You can define and assign role-based access controls (RBAC) to groups, granting members the ability to conduct specific lifecycle management tasks.

  • You can define host-based access control (HBAC) rules to limit access to specified systems in your domain to members of a specific user group.

  • Identity Management provides a mechanism to consistently apply Sudo policies across the IdM domain.

  • You can configure network-shared home directories in IdM to centralized storage and administration of automount configurations.

  • IdM uses host principals to identify a host in the domain and to interact with some services, such as SSH.

  • Service principals use keytab files instead of passwords, enabling them to start without human intervention.

Revision: rh362-9.1-4c6fdb8