certServer.registry.configuration
499
D.2.12. certServer.registry.configuration
Controls access to the administration registry, the file that is used to register plug-in modules.
Currently, this is only used to register certificate profile plug-ins.
allow (read) group="Administrators" || group="Certificate Manager Agents" ||
group="Registration Manager Agents" || group="Data Recovery Manager Agents" || group="Online
Certificate Status Manager Agents" || group="Auditors";allow (modify) group="Administrators"
Operations
Description
Allow/Deny
Access
Targeted
Users/
Groups
read
View the administration registry.
Allow
Administrators
Agents
Auditors
modify
Modify the administration registry.
Allow
Administrators
Table D.13. certServer.registry.configuration ACL Summary
D.2.13. certServer.usrgrp.administration
Controls who can add, edit, and remove users and groups used by the instance. The default
configuration is:
allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager
Agents" || group="Registration Manager Agents" || group="Data Recovery Manager Agents" ||
group="Online Certificate Status Manager Agents";allow (modify) group="Administrators"
Operations
Description
Allow/Deny
Access
Targeted
Users/
Groups
read
View users, groups, and user's certificates. Find users and groups.
Allow
Administrators
Agents
Auditors
modify
Add, modify, and delete groups and users. Add and modify a user certificate.
Allow
Administrators
Table D.14. certServer.usrgrp.administration ACL Summary
D.3. Certificate Manager-Specific ACLs
This section covers the default access control configuration attributes which are set specifically for
the Certificate Manager. The CA ACL configuration also includes all of the common ACLs listed in
Section D.2, “Common ACLs”
.
There are access control rules set for each of the CA's interfaces (administrative console and agents
and end-entities services pages) and for common operations like listing and downloading certificates.
D.3.1. certServer.admin.ocsp
Limits access to the Certificate Manager's OCSP configuration to members of the enterprise OCSP
administrators group.
Summary of Contents for CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Page 42: ...20 ...
Page 43: ...Part I Setting up Certificate Services ...
Page 44: ......
Page 190: ...168 ...
Page 208: ...186 ...
Page 223: ...Part II Additional Configuration to Manage CA Services ...
Page 224: ......
Page 256: ...234 ...
Page 270: ...248 ...
Page 280: ...258 ...
Page 292: ...270 ...
Page 293: ...Part III Managing the Subsystem Instances ...
Page 294: ......
Page 408: ...386 ...
Page 438: ...416 ...
Page 439: ...Part IV References ...
Page 440: ......
Page 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Page 504: ...482 ...
Page 556: ...534 ...
Page 564: ...542 ...