Can backup (CSBackup) and restore (CSRestore) the subsystem from the
❍
command-line.
•
Online Certificate Status Manager Agents
Can add CRLs (to the OCSP Responder Agent interface via SSL-capable
❍
browsers).
Can define supported CAs (via SSL-capable browsers to the OCSP Responder
❍
Agent interface).
•
Auditors
Can view signed audit logs (via the CS Console). This is the only role allowed this
❍
privilege.
Can verify audit log signatures by running the AuditVerify tool (from the IT
❍
environment).
About Roles
Of all privileged roles supported by CS, the Certificate Manager Agents role, the
Registration Manager Agents role, and the DRM Agent Role are the ones that map directly
to the "Officer" role defined in the ST and the CIMC PP. The Online Certificate Status
Manager Agents are a sub-group of the Administrator role defined in the CIMC PP. The
following further specifies this mapping:
•
Administrator
The Administrator role is divided into finer-grained sub-roles, each bearing different
responsibilities:
Administrators for the CA, RA, DRM, and OCSP subsystems
❍
Online Certificate Status Manager Agents
❍
•
Officer
Certificate Manager Agents
❍
Data Recovery Manager Agents
❍
Registration Manager Agents
❍
•
Auditor
Auditors from CA, RA, DRM, and OCSP
❍
Appendix B
Common Criteria Environment: Setup and Operations
CS Privileged Users and Groups (Roles)
695
Need help?
Do you have a question about the CERTIFICATE SYSTEM 7.1 - ADMINISTRATOR and is the answer not in the manual?