To create symauth host based user entries on the array: 1. Ensure that symauth is disabled on the array: # symauth -sid xxx list 2. Create a command file called adduser.cmd with the following entries: assign user H:sangs7\sw54321 to role SecurityAdmin; assign user H:sangs7\cp12345 to role StorageAdmin; 3. After the command file is create, execute the command file with the symauth command: # symauth -sid xxx preview -f adduser.cmd 4. Verify the user entries: # symauth -sid xxx list -users Note : On RHEL, the users with the StorageAdmin role will need to have rwx access to the files in the /var/symapi/config and /var/symapi/db directory. To create symauth domain based group entries on the array: 1. Create a command file called assign-grp with the following entries: assign group D:NAMDEV\per_csbe_symm_admin to role StorageAdmin 2. After the command file is create, execute the command file with the symauth command: # symauth -sid xxx -file assign-grp commit -v –nop 3. Verify group entry # symauth -sid xxx list -users # symauth -sid xxx list -user -v 4. To find out what the current username is for the user currently logged into the system, type the following command: #symauth show -username # symauth -sid xxx list -users 5. On RHEL, the users with the StorageAdmin role will need to have rwx access to the files in the /var/symapi/config and /var/symapi/db directory. To set ACL entries for individual users, do the following: # setfacl –R -m user:cp12345:rwx /var/symapi/config # chmod 775 /var/symapi/config # setfacl –R –m user:cp12345:rwx /var/symapi/db # chmod 775 /var/symapi/db If wanting to set the ACL entries for user groups, do the following: # setfacl -R -m group:503:rwx /var/symapi/db # getfacl /var/symapi/db # setfacl -R -m group:503:rwx /var/symapi/config # getfacl /var/symapi/config 6. Once all of the symauth user entries are entered on both the local and remote storage arrays (symauth entries must be also be created for the remote arrays for SRDF functionality), enable symauth on the Symmetrix: # symauth -sid xxx enable 7. Verify that the Enforcement Mode is set to Enforce: Backing Up and Restoring the Symauth Database The symauth entries for each array should be backed up on a periodic basis; especially after changes are made to the entries. Use the following command to backup the symauth entries to a file on the SE management server: symauth –sid backup –f To restore the symauth entries from an earlier backup of the symauth database; use the following command: symauth –sid commit –restore –f Note: As of SE 7.2, the quotes are added around the username automatically when backing up the symauth entries. For example: assign user "D:NT AUTHORITY\SYSTEM" to role Monitor; Configuring the Event Daemon (storevntd) 1. Add a symauth entry for storevntd. In the example below, a command file called adduser.cmd was created with the entry assign user H:sangs7\storevntd to role Auditor; to create the symauth entry for storevntd: 2. Start storevntd: # stordaemon start storevntd 3. Run the command to have storevntd start automatically after a system reboot: # stordaemon install storevntd -autostart