Chapter 17. User and Group Authorization
420
17.7.33.2. Default ACIs
allow (read) group="Administrators"
|| group="Certificate Manager Agents"
|| group="Data Recovery Manager Agents"
|| group="Online Certificate Status Manager Agents"
|| group="Auditors"
allow (modify) group="Administrators"
Administrators, agents, and auditors are allowed to read job configuration; only administrators are
allowed to modify job configuration.
17.7.34. certServer.kra.certificate.transport
Controls actions to display the key transport certificate.
17.7.34.1. Operations
Operations
Description
read
Display the key transport certificate.
17.7.34.2. Default ACIs
allow (read) user="anybody"
Anyone can view the key transport certificate.
17.7.35. certServer.kra.configuration
Controls operations on the DRM configuration.
17.7.35.1. Operations
Operations
Description
read
View automatic key recovery automatic configuration, key
recovery archive configuration, and notification request in
queue configuration.
modify
Modify automatic key recovery archive configuration, agent
passwords, and notification requests in queue configuration.
17.7.35.2. Default ACIs
allow (read) group="Administrators"
|| group="Auditors"
Summary of Contents for CERTIFICATE SYSTEM 7.3 - ADMINISTRATION
Page 15: ...xv Index 525 ...
Page 16: ...xvi ...
Page 38: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Page 82: ...Chapter 2 Installation and Configuration 60 rpm ev rhpki manage ...
Page 154: ...132 ...
Page 194: ...172 ...
Page 238: ...216 ...
Page 244: ...222 ...
Page 246: ...224 ...
Page 286: ...264 ...
Page 292: ...270 ...
Page 318: ...Chapter 13 Certificate Profiles 296 Parameter IssuerType_n IssuerName_n ...
Page 321: ...Freshest CRL Extension Default 299 Parameter PointName_n PointIssuerName_n ...
Page 398: ...376 ...
Page 412: ...390 ...
Page 472: ...450 ...
Page 506: ...484 ...
Page 528: ...506 ...
Page 546: ...524 ...