<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: VC Permissions to Deploy Templates</title>
	<atom:link href="http://www.jeremypries.com/?feed=rss2&#038;p=104" rel="self" type="application/rss+xml" />
	<link>http://www.jeremypries.com/?p=104</link>
	<description>Virtualization Boy - Jeremy Pries</description>
	<lastBuildDate>Sat, 21 Nov 2009 18:17:20 -0700</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Michael</title>
		<link>http://www.jeremypries.com/?p=104&#038;cpage=1#comment-3826</link>
		<dc:creator>Michael</dc:creator>
		<pubDate>Wed, 09 Apr 2008 14:45:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.jeremypries.com/?p=104#comment-3826</guid>
		<description>Hi Jeremy,

nice write-up! I discovered some &quot;interesting&quot; issues one would not expect when working with permissions in VC.
If you work with folders in &quot;Hosts &amp; Clusters&quot; and &quot;VMs and Templates&quot; you have to be very careful:
Permissions are always treated differently between these two views, which is OK. Folders created above Datacenters will always share the same permissions. Folders created below Datacenters, even with the same name, will not automatically share the same permissions.

Also people might want to combine roles on one object, e.g. some users are in _create_hosts on Object1 (propagate=yes) but should also be given the right to create VMs on objects somewhere deeper in the hierarchie. Since you can only have on role associated to an object at one time you have to should groups and not single users . VC will then combine all roles/ permissions on that specific object, e.g. create hosts in folder1 and subfolders   create VMs in
subfolder xyz...

Hope this helps or someone can comment.

Best,
Michael</description>
		<content:encoded><![CDATA[<p>Hi Jeremy,</p>
<p>nice write-up! I discovered some &#8220;interesting&#8221; issues one would not expect when working with permissions in VC.<br />
If you work with folders in &#8220;Hosts &amp; Clusters&#8221; and &#8220;VMs and Templates&#8221; you have to be very careful:<br />
Permissions are always treated differently between these two views, which is OK. Folders created above Datacenters will always share the same permissions. Folders created below Datacenters, even with the same name, will not automatically share the same permissions.</p>
<p>Also people might want to combine roles on one object, e.g. some users are in _create_hosts on Object1 (propagate=yes) but should also be given the right to create VMs on objects somewhere deeper in the hierarchie. Since you can only have on role associated to an object at one time you have to should groups and not single users . VC will then combine all roles/ permissions on that specific object, e.g. create hosts in folder1 and subfolders   create VMs in<br />
subfolder xyz&#8230;</p>
<p>Hope this helps or someone can comment.</p>
<p>Best,<br />
Michael</p>
]]></content:encoded>
	</item>
</channel>
</rss>
