certServer.log.configuration
497
Operations
Description
Allow/Deny
Access
Targeted
Users/
Groups
read
View the operating environment, LDAP configuration, SMTP configuration, server statistics, encryption, token names, subject name of certificates,
certificate nicknames, CA certificates, and all certificates for management.
Allow
Administrators
Agents
Auditors
modify
Modify the settings for the LDAP database, SMTP, and encryption. Import certificates, trust and untrust CA certificates, import cross-pair certificates,
and delete certificates. Log all tokens and check token status. Run self-tests on demand. Get certificate information. Process the certificate subject
name. Validate the certificate subject name, certificate key length, and certificate extension.
Allow
Administrators
delete
Remove any configuration entries or settings.
Allow
Administrators
Table D.7. certServer.general.configuration ACL Summary
D.2.7. certServer.log.configuration
Controls access to the log configuration for the Certificate Manager, including changing the log
settings.
allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager
Agents" || group="Registration Manager Agents" || group="Data Recovery Manager Agents" ||
group="Online Certificate Status Manager Agents";allow (modify) group="Administrators"
Operations
Description
Allow/Deny
Access
Targeted
Users/
Groups
read
View log plug-in information, log plug-in configuration, and log instance configuration. List log plug-ins and log instances.
Allow
Administrators
Agents
Auditors
modify
Add and delete log plug-ins and log instances. Modify log instances.
Allow
Administrators
Table D.8. certServer.log.configuration ACL Summary
D.2.8. certServer.log.configuration.fileName
Restricts access to change the file name of a log for the instance.
allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager
Agents" || group="Registration Manager Agents" || group="Data Recovery Manager Agents" ||
group="Online Certificate Status Manager Agents";deny (modify) user=anybody
Operations
Description
Allow/Deny
Access
Targeted
Users/
Groups
read
View the value of the
fileName
parameter for a log instance.
Allow
Administrators
Agents
Auditors
modify
Change the value of the
fileName
parameter for a log instance.
Deny
Anyone
Table D.9. certServer.log.configuration.fileName ACL Summary
D.2.9. certServer.log.configuration.signedAudit.expirationTime
Restricts access to view or change the expiration time for the signed audit log. The default setting is:
Содержание CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Страница 1: ...Red Hat Certificate System 8 0 Admin Guide Publication date July 22 2009 updated on March 25 2010 ...
Страница 42: ...20 ...
Страница 43: ...Part I Setting up Certificate Services ...
Страница 44: ......
Страница 190: ...168 ...
Страница 208: ...186 ...
Страница 223: ...Part II Additional Configuration to Manage CA Services ...
Страница 224: ......
Страница 256: ...234 ...
Страница 270: ...248 ...
Страница 280: ...258 ...
Страница 292: ...270 ...
Страница 293: ...Part III Managing the Subsystem Instances ...
Страница 294: ......
Страница 363: ...Managing RA Users 341 5 The user details page shows the person s UID full name email address and user SSL certificate ...
Страница 408: ...386 ...
Страница 438: ...416 ...
Страница 439: ...Part IV References ...
Страница 440: ......
Страница 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Страница 504: ...482 ...
Страница 556: ...534 ...
Страница 564: ...542 ...