User access roles, privileges, and security domains are access control mechanisms that
-
associate Cisco Application Centric
Infrastructure (ACI) fabric users with predefined or custom roles containing one or more privileges
-
determine the managed objects (MOs) to which the user has access through a set of privileges
-
provide privilege types for each role: no access, read-only, or read-write, and
-
use one or more security domain tags that identify the portions of the management information tree (MIT) that a user can access.
Roles and privileges
A privilege controls access to a particular function within the system. The ACI fabric manages access privileges at the managed object (MO) level. Every object holds a list of the privileges that can read
from it and a list of the privileges that can write to it. All objects that correspond to a particular function will have
the privilege for that function in its read or write list. Because an object might correspond to additional functions, its
lists might contain multiple privileges. When a user is assigned a role that contains a privilege, the user is given read
access to the associated objects whose read list specifies read access, and write access to those whose write list specifies
write access.
As an example, 'fabric-equipment' is a privilege that controls access to all objects that correspond to equipment in the physical
fabric. An object corresponding to equipment in the physical fabric, such as 'eqptBoard,' will have 'fabric-equipment' in
its list of privileges. The 'eqptBoard' object allows read-only access for the 'fabric-equipment' privilege. When a user is
assigned a role such as 'fabric-admin' that contains the privilege 'fabric-equipment,' the user will have access to those
equipment objects, including read-only access to the 'eqptBoard' object.

Note
|
Some roles contain other roles. For example, '-admin' roles such as tenant-admin, fabric-admin, access-admin are groupings
of roles with the same base name. For example, 'access-admin' is a grouping of 'access-connectivity', 'access-equipment',
'access-protocol', and 'access-qos.' Similarly, tenant-admin is a grouping of roles with a 'tenant' base, and fabric-admin
is a grouping of roles with a 'fabric' base.
The 'admin' role contains all privileges. The 'admin' user cannot be deleted from APIC.
|
For more details about roles and privileges see APIC Roles and Privileges Matrix.
A security domain is a tag associated with a certain subtree in the ACI MIT object hierarchy. For example, the default tenant "common" has a domain tag common. Similarly, the special domain tag all includes the entire MIT object tree. An administrator can assign custom domain tags to the MIT object hierarchy. For example,
an administrator could assign the "solar" domain tag to the tenant named "solar." Within the MIT, only certain objects can
be tagged as security domains. For example, a tenant can be tagged as a security domain, but objects within a tenant cannot.

Note
|
(Until R6.1.2) Password strength parameters can be configured by either creating Custom Conditions or by selecting Any Three Conditions that are provided.
|

Note
|
(From R6.1.3) Password strength parameters can be configured by either creating Custom Conditions or by selecting the Default Three Conditions, which include lowercase letters, digits, and special characters.
|
Creating a user and assigning a role to that user does not enable access rights. It is necessary to also assign the user to
one or more security domains. By default, the ACI fabric includes these special pre-created domains:
-
All—allows access to the entire MIT
-
Common—allows access to fabric common objects/subtrees
-
Mgmt—allows access to fabric management objects/subtrees

Note
|
For read operations to the managed objects that a user's credentials do not allow, a "DN/Class Not Found" error is returned,
not "DN/Class Unauthorized to read." For write operations to a managed object that a user's credentials do not allow, an HTTP
401 Unauthorized error is returned. In the GUI, actions that a user's credentials do not allow, either they are not presented,
or they are grayed out.
|
A set of predefined managed object classes can be associated with domains. These classes should not have overlapping containment.
Examples of classes that support domain association are:
-
Layer 2 and Layer 3 network managed objects
-
Network profiles (such as physical, Layer 2, Layer 3, management)
-
QoS policies
When an object that can be associated with a domain is created, the user must assign domains to the object within the limits
of the user's access rights. Domain assignment can be modified at any time.
If a virtual machine management (VMM) domain is tagged as a security domain, the users contained in the security domain can
access the correspondingly tagged VMM domain. For example, if a tenant named solar is tagged with the security domain called
sun and a VMM domain is also tagged with the security domain called sun, then users in the solar tenant can access the VMM
domain according to their access rights.