
PM 1000162 000 14
Device handbook SINEAX AMx000
50/118
6.9.1 RBAC management
The access control system described below is available for devices with Ethernet interface
only. For devices without Ethernet see:
Simple password protection
.
Each access to device data via website, local display or external software applications can be
comprehensively protected using the role-based access control (RBAC) system. This way, access to
measured value information, the change of configuration parameters or the resetting / deletion of
measurement data can be individually adapted to the role of the active user.
Note
: All settings of the security system are stored in the device in encrypted form only; login credentials
are never transmitted in plain text.
A maximum of 8 users is supported
3 pre-defined standard users
•
admin
: A user with administrator rights (Default setting password: „CBM_1234“)
•
localgui
: The standard user for the local display. Its permissions determine what can be displayed or
changed via the built-in display without a user having to log in.
•
anonymous
: The standard user for access via device website. Its permissions determine what can
be displayed or changed via the website without a user having to log in.
Up to 5 definable users or API keys
Users or API keys may be created by each user with write access to the settings of the security
system. In any case, each user with a web login can change the password of its own account.
Application programming interface (API) keys are used to allow applications to access device data via
REST interface (communication via http/https protocol). Such keys are timely unlimited and have
either read-only permissions, all permissions or all permissions except security.
The pre-defined administrator or any other user with full access rights to the settings of the security
system can:
•
Change its own credentials (user name and/or password)
•
Change the credentials (user name and/or password) of any other user
•
Freely define the permissions of the standard users
localgui
and
anonymous
; both users are
standard users without login credentials
•
Create new users up to a maximum of 5
•
Restrict users to local operation only (no login via website)
The RBAC settings are managed via the menu Settings | Security system | Users and Permissions. To do
this, Users and Permissions must be enabled:
Adding users / API keys
In addition to the 3 predefined users a maximum of 5 users or API keys may be created. To do so, use
“Add user / API key” and select the type of user to be created.