How do I let User role accounts create and edit user groups and machine groups without making them Web UI administrators?
This article explains how to enable delegated group management on the Stratusphere Hub appliance using the USER_GROUP_MODIFY setting, including the three available levels, the steps to set and verify the value, and how to revert.
Enable this setting after the Hub has been upgraded to 6.7.1. See Upgrade First below.
📄 Contents
Problem
By default, only accounts with the Web UI Administrator role can create, edit, or delete user groups and machine groups. Administrators who want to delegate group management to other staff have had to grant full Web UI administrator access to do so.
Per the Stratusphere 6.7.1 release notes:
Stratusphere 6.7.1 now allows users with the User role to create and edit user and machine groups, so administrators can delegate group management without granting full Web UI administrator access. This is not universally enabled and needs to be enabled on the console for those who need this functionality.
This article covers enabling that functionality on the Hub appliance.
IMPORTANT — Upgrade First
It must be enabled AFTER the upgrade to 6.7.1 has completed on the Hub.
Setting this value on 6.7.0-x or earlier has no effect, and the setting is not carried forward in a way that activates the feature on upgrade. If you set it before upgrading, re-verify the value afterwards using the steps below.
Confirm the Hub version before proceeding:
cat /tmp/statusor
/opt/tnt/bin/tntdbconf BUILD
rpm -q tnt-releaseAvailable Settings
USER_GROUP_MODIFY accepts three values. Decide which level of delegation is appropriate before running the command.
| Value | Behavior |
|---|---|
| 0 | Default — Off. Same behavior as 6.7.0-x and earlier. User roles cannot add, update, or delete groups or their members. |
| 1 |
Add groups, add members only — no deletes. User roles can create groups and add members to local groups including dash_users, but not dash_admin. Cannot delete users from any group. |
| 2 |
Add groups, add and delete members. User roles can create groups, add members to local groups including dash_user but not dash_admin, and delete users from local groups except the dash_user and dash_admin groups. |
The
dash_admin group is protected at every level — User role accounts can never add members to it. At level 2, the dash_user group is additionally protected from member deletion.Resolution
Perform the following on the Hub appliance only.
1. Connect to the Hub
Open an SSH session to the Hub using PuTTY (or use the VM console) and log in as the appliance login account:
-
On-premises appliances:
friend -
AWS:
ec2-user -
Azure:
azureuser, or the custom username listed in the Azure console
2. Elevate to root
sudo bashEnter the login account's password when prompted.
3. Check the current value
/opt/tnt/bin/tntdbconf USER_GROUP_MODIFYA blank result or 0 indicates the feature is currently disabled.
4. Set the desired value
To allow group creation and adding members, with no deletions:
/opt/tnt/bin/tntdbconf USER_GROUP_MODIFY 1To additionally allow deleting members from local groups:
/opt/tnt/bin/tntdbconf USER_GROUP_MODIFY 25. Verify the value was written
/opt/tnt/bin/tntdbconf USER_GROUP_MODIFYThe command should return the value you set.
6. Wait and test
Wait a few minutes, then log into the Web UI using an account with the User role. Group creation and editing options should now be available according to the level you set.
Reverting
To return to default behavior:
/opt/tnt/bin/tntdbconf USER_GROUP_MODIFY 0Notes and Cautions
Do not repeat it rapidly if the change does not appear to take immediately.
If the value does not read back correctly, verify the configuration file is intact before retrying:
ls -al /etc/tntdb.confThe file should be non-zero in size (approximately 1.2 KB) and owned root:tntcfg. This behavior is corrected in 6.7.1-2 and later.
It does not need to be set on Collectors or the Database appliance.
The
dash_admin group cannot be modified by User role accounts at any setting.| Product | Stratusphere FIT/UX |
| Product Version | 6.7.1 and later |
| Expires on | 365 days from publish date |