Security Roles and Claims

Tip:  Where to find this in the Management Portal:
System Settings → Security Roles & Claims

There are several elements that make up Keyfactor Command Security infrastructure. To define your security design you will use these elements in combinations that meet your needs. You can limit user menu access through global permissions, and user certificate access through collectionClosed The certificate search function allows you to query the Keyfactor Command database for certificates from any available source based on any criteria of the certificates and save the results as a collection that will be available in other places in the Management Portal (for example expiration alerts and certain reports). and certificate stores permissions.

Note:  Keyfactor Command caches the mapping between security claims and roles to improve performance when evaluating permissions. Because this cache is based on claims rather than individual users, the same mapping can be reused across users who share the same claims, such as users who are members of the same group.

Cache entries expire after a fixed interval from when they are cached. Security role cache entries expire after 10 minutes. Claim and identity cache entries expire after 5 minutes.

Cache entries are also affected by the Security Roles Cache Cleanup Interval application setting (see Application Settings: Console Tab).

Security Roles

Figure 427: Security Roles

During the Keyfactor Command installation and configuration process, the security role Administrator is created. The Administrator role grants full permissions to the Management Portal and cannot be deleted and canonly be edited to add user claims. If all users of the Management Portal should have full access to all features within the portal, this one role may be sufficient for your needs. However, if you would like to grant access to other users or limit the functionality available to those users, you need to add one or more new security roles for this purpose.

A Reporting API Access role is automatically created during installation to support the dashboard and reporting access required by the Logi Analytics Platform. The service account user associated with the IIS application pools on the Keyfactor Command Management Portal server (where Logi is installed) is automatically created as an identity and associated with this role.

Security Claims

Figure 428: Security Claims

Claims are created in Keyfactor Command using users or groups.

If you would like to grant access to other users but limit the functionality available to those users, you need to add one or more new security claims for this purpose and link them to one or more appropriate security roles. See Security Claim Operations.

Tip:  Click the help icon () next to the Security Roles and Claims page title to open the Keyfactor Software & Documentation Portal to this section. You will receive a prompt indicating:

You are being redirected to an external website ‘software.keyfactor.com'. Would you like to proceed?

You can also find Help in the NavigatorClosed The Navigator is the Keyfactor Command left-hand (newer versions) or top (older versions) navigation menu. Certificate collections and reports can be configured to be added to the menu using user-defined Show in Navigator settings.. From here you can choose to open either the Keyfactor Software & Documentation Portal at the home page or the Keyfactor API Endpoint Utility.

Keyfactor provides two sets of documentation: the On-Premises Documentation Suite and the Managed Services Documentation Suite. Which documentation set is accessed is determined by the Application Settings: On-Prem Documentation setting (see Application Settings: Console Tab).