Appendix D. ACL Reference
500
allow (modify,read) group="Enterprise OCSP Administrators"
Operations
Description
Allow/Deny
Access
Targeted
Users/
Groups
read
View OCSP plug-in information, OCSP configuration, and OCSP stores configuration. List OCSP stores configuration.
Allow
(Enterprise)
Administrators
modify
Modify the OCSP configuration, OCSP stores configuration, and default OCSP store.
Allow
(Enterprise)
Administrators
Table D.15. certServer.admin.ocsp ACL Summary
D.3.2. certServer.ca.certificate
Controls basic management operations for certificates in the agents services interface, including
importing and revoking certificates. The default configuration is:
allow (import,unrevoke,revoke,read) group="Certificate Manager Agents"
Operations
Description
Allow/Deny
Access
Targeted
Users/
Groups
import
Retrieve a certificate by serial number.
Allow
Agents
unrevoke
Change the status of a certificate from revoked.
Allow
Agents
revoke
Revoke certificates, or approve certificate revocation requests.
Allow
Agents
read
Retrieve certificates based on the request ID, and display certificate details based on the request ID.
Allow
Agents
Table D.16. certServer.ca.certificate ACL Summary
D.3.3. certServer.ca.certificates
Controls operations for listing or revoking certificates through the agent services interface. The default
configuration is:
allow (revoke,list) group="Certificate Manager Agents"|| group="Registration Manager Agents"
Operations
Description
Allow/Deny
Access
Targeted
Users/
Groups
revoke
Revoke certificates, or approve certificate revocation requests.
Allow
Agents
list
List certificates based on a search. Retrieve details about a range of certificates based on a range of serial numbers.
Allow
Agents
Table D.17. certServer.ca.certificates ACL Summary
D.3.4. certServer.ca.clone
Controls access to submit requests to a master CA through the subsystem interface. The default
configuration is:
Summary of Contents for CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Page 42: ...20 ...
Page 43: ...Part I Setting up Certificate Services ...
Page 44: ......
Page 190: ...168 ...
Page 208: ...186 ...
Page 223: ...Part II Additional Configuration to Manage CA Services ...
Page 224: ......
Page 256: ...234 ...
Page 270: ...248 ...
Page 280: ...258 ...
Page 292: ...270 ...
Page 293: ...Part III Managing the Subsystem Instances ...
Page 294: ......
Page 408: ...386 ...
Page 438: ...416 ...
Page 439: ...Part IV References ...
Page 440: ......
Page 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Page 504: ...482 ...
Page 556: ...534 ...
Page 564: ...542 ...