ACL for Mid Server

John Vo1
Tera Guru

I have an ITIL user trying to do a quick discovery and when he clicks on magnifying glass to select mid server he is getting security constraints. Which ACL do I need to edit for him to see the mid servers?

find_real_file.png

1 ACCEPTED SOLUTION

This was ServiceNow recommendations.   Create a Discover by ip address and update the script and it worked.



find_real_file.png


View solution in original post

21 REPLIES 21

Thanks John.



Best practice: If you don't already have it, create a group for those desktop techs.


Grant the appropriate role to those techs to allow them to read those records.


Chuck,



The reason I don't want to give them roles is we want them limited as possible.   I don't want them being able to mess with the mid servers or discovery schedules.   So can I just add the role to read, write, delete and they should be able scan by ip address using quick discovery?



Thanks,


John


Technically, Quick Discovery creates a schedule (and runs now). I don't think you're going to get where you need to be with a limited approach on the ACLs. Eventually you'll find you need to open those ACLs up as much as the existing roles require.



glennpinto - any thoughts on this one?


Chuck,



I added role ITIL to all ecc_agent ACL and when I try to run quick discovery I get this error.   Mid servers are up and running.


find_real_file.png


To resolve this issue, you have to add the "ITIL" role to the ACL created for the DiscoveryAjax script include.