Configuring a Registration Manager
Chapter
4
Registration Manager
153
Configuring Authorization
Each subsystem has a set of predefined roles that are assigned a default set of
privileges. You create users in the CMS database and then assign them to a group
to give them the privileges of that group. The privileges assigned to a group are
controlled by Access Control Instructions (ACIs) placed in Access Control Lists
(ACLs). ACLs define points that need specific authorization. Generally, each
defines a distinct set of functionality for the server. ACIs define what operations
can or cannot be performed by a user, group, or IP address for that particular ACL.
You can change the default ACIs set up in the ACLs to change the privileges of a
user, group, or IP address. You can also create new groups and assign privileges to
those groups by adding ACI entries for that group in the ACLs. For complete
details about creating users, assigning users to groups, creating groups, and
changing ACIs and ACLs, see Chapter 8, “Authorization.”
Default ACL Configuration
The configuration set up for the Certificate Manager gives the following privileges
to members of the following groups:
•
Members of the Administrator group can perform any operations in the
administrative interface including viewing configuration settings, changing
configuration settings, adding or deleting plug-ins, creating or deleting
instances or plug-ins, and viewing all logs except for the signed audit log—if
you have the signed audit feature set up. Administrators do not have access to
the agent services interface or any task performed there.
•
Members of the Auditor group can view the signed audit log, and can view
configuration settings, but cannot perform any other operations on
configuration settings and do not have access to the agent services interface.
•
Members of the Registration Manager Agent group can view configuration
settings in the administrative interface, but cannot perform any other
operations on the configuration settings. They can perform all operations for
all tasks associated with the agent services interface. They are allowed to
communicate with the RA via the agent services port.
•
Members of the Trusted Manager group are allowed to communicate with the
Certificate Manager.
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...