Configuring Authorization - Netscape MANAGEMENT SYSTEM 6.1 - ADMINISTRATOR Administrator's Manual

Table of Contents

Advertisement

Configuring Authorization

Each subsystem has a set of predefined roles that are assigned a default set of
privileges. You create users in the CMS database and then assign them to a group
to give them the privileges of that group. The privileges assigned to a group are
controlled by Access Control Instructions (ACIs) placed in Access Control Lists
(ACLs). ACLs define points that need specific authorization. Generally, each
defines a distinct set of functionality for the server. ACIs define what operations
can or cannot be performed by a user, group, or IP address for that particular ACL.
You can change the default ACIs set up in the ACLs to change the privileges of a
user, group, or IP address. You can also create new groups and assign privileges to
those groups by adding ACI entries for that group in the ACLs. For complete
details about creating users, assigning users to groups, creating groups, and
changing ACIs and ACLs, see Chapter 8, "Authorization."
Default ACL Configuration
The configuration set up for the Certificate Manager gives the following privileges
to members of the following groups:
Members of the Administrator group can perform any operations in the
administrative interface including viewing configuration settings, changing
configuration settings, adding or deleting plug-ins, creating or deleting
instances or plug-ins, and viewing all logs except for the signed audit log—if
you have the signed audit feature set up. Administrators do not have access to
the agent services interface or any task performed there.
Members of the Auditor group can view the signed audit log, and can view
configuration settings, but cannot perform any other operations on
configuration settings and do not have access to the agent services interface.
Members of the Registration Manager Agent group can view configuration
settings in the administrative interface, but cannot perform any other
operations on the configuration settings. They can perform all operations for
all tasks associated with the agent services interface. They are allowed to
communicate with the RA via the agent services port.
Members of the Trusted Manager group are allowed to communicate with the
Certificate Manager.
Configuring a Registration Manager
Chapter 4
Registration Manager
153

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.1

Table of Contents