Chapter 17. User and Group Authorization
394
The trusted manager relationship is set up in the following way:
• The subsystem trusts the other subsystem as a trusted manager by creating a user ID for the
subsystem, adding it to the trusted manager group, and storing its SSL client authentication
certificate.
• The trusted manager sets up a connector to the subsystem by specifying the agent services port for
that subsystem. All communications between the trusted manager and the subsystem go through
this port.
A subsystem authenticates to the subsystem which trusts it as a trusted manager using its SSL server
certificate for SSL client authentication.
17.2. Creating Users
To create an administrator, agent, or auditor, create a user in the Certificate System instance where
the user will have privileges and assign the user to the appropriate group. An agent or auditor must
have a certificate stored in the subsystem's internal database. If the Console is configured for SSL
client authentication, all administrators must also a certificate.
To create a new user entry, do the following:
1. Log into the administrative console.
pkiconsole https://
hostname:SSLport/subsystemType
2. In the
Configuration
tab, select
Users and Groups
. Click
Add
.
3. Fill in the information in the
Edit User Information
dialog.
Summary of Contents for CERTIFICATE SYSTEM 7.3 - ADMINISTRATION
Page 15: ...xv Index 525 ...
Page 16: ...xvi ...
Page 38: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Page 82: ...Chapter 2 Installation and Configuration 60 rpm ev rhpki manage ...
Page 154: ...132 ...
Page 194: ...172 ...
Page 238: ...216 ...
Page 244: ...222 ...
Page 246: ...224 ...
Page 286: ...264 ...
Page 292: ...270 ...
Page 318: ...Chapter 13 Certificate Profiles 296 Parameter IssuerType_n IssuerName_n ...
Page 321: ...Freshest CRL Extension Default 299 Parameter PointName_n PointIssuerName_n ...
Page 398: ...376 ...
Page 412: ...390 ...
Page 472: ...450 ...
Page 506: ...484 ...
Page 528: ...506 ...
Page 546: ...524 ...