Appendix D. ACL Reference
508
allow (read) user="anybody"
Operations
Description
Allow/Deny
Access
Targeted
Users/
Groups
read
Retrieve the status of a request and serial numbers of any certificates that have been issued against that request.
Allow
Anyone
Table D.42. certServer.ee.requestStatus ACL Summary
D.3.29. certServer.job.configuration
Controls who can configure jobs for the Certificate Manager.
allow (read) group="Administrators" || group="Certificate Manager Agents" ||
group="Registration Manager Agents" || group="Data Recovery Manager Agents" || group="Online
Certificate Status Manager Agents" || group="Auditors";allow (modify) group="Administrators"
Operations
Description
Allow/Deny
Access
Targeted
Users/
Groups
read
View basic job settings, job instance settings, and job plug-in settings. List job plug-ins and job instances.
Allow
Administrators
Agents
Auditors
modify
Add and delete job plug-ins and job instances. Modify job plug-ins and job instances.
Allow
Administrators
Table D.43. certServer.job.configuration ACL Summary
D.3.30. certServer.kra.configuration
Controls who can view and manage the DRM instance configuration.
allow (read) group="Administrators" || group="Auditors" || group="Certificate Manager
Agents" || group="Registration Manager Agents" || group="Data Recovery Manager Agents" ||
group="Online Certificate Status Manager Agents";allow (modify) group="Administrators"
Operations
Description
Allow/Deny
Access
Targeted
Users/
Groups
read
View automatic key recovery automatic configuration, key recovery archive configuration, and notification request in queue configuration.
Allow
Administrators
Agents
Auditors
modify
Modify automatic key recovery archive configuration, agent passwords, and notification requests in queue configuration.
Allow
Administrators
Table D.44. certServer.kra.configuration ACL Summary
D.3.31. certServer.ocsp.configuration
Controls who can access, view, or modify the configuration for the Certificate Manager's OCSP
services. The default configuration is:
allow (read) group="Administrators" || group="Certificate Manager Agents" ||
group="Registration Manager Agents" || group="Data Recovery Manager Agents" || group="Online
Certificate Status Manager Agents" || group="Auditors";allow (modify) group="Administrators"
Summary of Contents for CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Page 42: ...20 ...
Page 43: ...Part I Setting up Certificate Services ...
Page 44: ......
Page 190: ...168 ...
Page 208: ...186 ...
Page 223: ...Part II Additional Configuration to Manage CA Services ...
Page 224: ......
Page 256: ...234 ...
Page 270: ...248 ...
Page 280: ...258 ...
Page 292: ...270 ...
Page 293: ...Part III Managing the Subsystem Instances ...
Page 294: ......
Page 408: ...386 ...
Page 438: ...416 ...
Page 439: ...Part IV References ...
Page 440: ......
Page 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Page 504: ...482 ...
Page 556: ...534 ...
Page 564: ...542 ...