Configuring a Registration Manager
Chapter
4
Registration Manager
151
Configuring Authorization
Each subsystem has a set of predefined roles that are assigned a default set of
privileges. You create users in the CMS database and then assign them to a group
to give them the privileges of that group. The privileges assigned to a group are
controlled by Access Control Instructions (ACIs) placed in Access Control Lists
(ACLs). ACLs define points that need specific authorization. Generally, each
defines a distinct set of functionality for the server. ACIs define what operations
can or cannot be performed by a user, group, or IP address for that particular ACL.
You can change the default ACIs set up in the ACLs to change the privileges of a
user, group, or IP address. You can also create new groups and assign privileges to
those groups by adding ACI entries for that group in the ACLs. For complete
details about creating users, assigning users to groups, creating groups, and
changing ACIs and ACLs, see Chapter 8, “Authorization.”
Default ACL Configuration
The configuration set up for the Certificate Manager gives the following privileges
to members of the following groups:
•
Members of the Administrator group can perform any operations in the
administrative interface including viewing configuration settings, changing
configuration settings, adding or deleting plug-ins, creating or deleting
instances or plug-ins, and viewing all logs except for the signed audit log—if
you have the signed audit feature set up. Administrators do not have access to
the agent services interface or any task performed there.
•
Members of the Auditor group can view the signed audit log, and can view
configuration settings, but cannot perform any other operations on
configuration settings and do not have access to the agent services interface.
•
Members of the Registration Manager Agent group can view configuration
settings in the administrative interface, but cannot perform any other
operations on the configuration settings. They can perform all operations for
all tasks associated with the agent services interface. They are allowed to
communicate with the RA via the agent services port.
•
Members of the Trusted Manager group are allowed to communicate with the
Certificate Manager.
Содержание Certificate Management System 6.2
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 2 June 2003...
Страница 22: ...22 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 30: ...Documentation 30 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 70: ...Support for Open Standards 70 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 84: ...Uninstalling CMS 84 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 164: ...How a Registration Manager Works 164 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 322: ...Configuring the Server s Security Preferences 322 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 380: ...ACL Reference 380 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 564: ...Managing Policy Plug in Modules 564 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 744: ...1 3 Organization Security Policies 744 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 750: ...Object Identifiers 750 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 796: ...DNs in Certificate Management System 796 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 828: ...Managing Certificates 828 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 844: ...The SSL Handshake 844 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 862: ...862 Netscape Certificate Management System Administrator s Guide June 2003...