How to restrict "Execute host command" - even if host credentials are needed
This question is about how to restrict actions performed from OEM.
Scenario:
OEM 13.2
Many - 100k+ targets
Almost all kinds of Oracle Linux host, Oracle Database and Oracle Fusion Midlleware targets.
We are in the process of adding new administrators to OEM.
In contrast to the "old" administrators (which does both monitoring and administration) the
new administrators should only be able to do monitoring, including tracing - especially with
the Fusion Middleware targets.
This however presents a security issue:
Some monitoring actions (like using tracing in Fusion Middleware) requires the use of OS credentials
on the hosts running Fusion Middleware components