Security Role Permissions
The Security Permissions that are available to be assigned to security roles within Keyfactor Command are documented in the tables below.
System Settings → Security Roles & Claims
Security Structure
The access control string security structure permission model was introduced in Keyfactor Command 11.0 and is used when setting security permissions in the Management Portal, with v2 Security Roles Keyfactor API
An API is a set of functions to allow creation of applications. Keyfactor offers the Keyfactor API, which allows third-party software to integrate with the advanced certificate enrollment and management features of Keyfactor Command. endpoints, and with Keyfactor API Permission Set endpoints.
In the access control string model, permissions are defined using structured strings that support inheritance. The more segments added to a string, the more narrowly the permission is scoped. For example, the following access control string grants full control to the entire product:
Add a certificates level to this, and now you’ve limited this to full control of just functions related to certificates in the product (which would include enrollment
Certificate enrollment refers to the process by which a user requests a digital certificate. The user must submit the request to a certificate authority (CA)., for example):
Add a collections level to this, and now you’ve limited this further to full control of just options that can be found on the Certificates menu item in the Management Portal, including certificates both in collections and found by direct search, certificate import, and certificate collection
The certificate search function allows you to query the Keyfactor Command database for certificates from any available source based on any criteria of the certificates and save the results as a collection that will be available in other places in the Management Portal (for example expiration alerts and certain reports). management:
Add a read to this, and now you’ve limited this to just read for items on the Certificates menu:
Add a certificate collection ID to this, and now you’ve locked this down to just read on just the certificates in the certificate collection with ID 5:
When you apply permissions through the Management Portal, these access control strings are applied for you based on the selections you make in the Role Information dialog when assigning permissions to a role (see Security Role Operations). When you apply permissions through the Keyfactor API using a newer endpoint
An endpoint is a URL that enables the API to gain access to resources on a server. (for example, v2 Security Roles endpoints), you need to specify these access control strings.
Access control strings that are shown below with a # refer to a specific granular ID to which permissions should be granted. When used, they must be specified with an integer in place of the #. For example, use:
To refer to the certificate store application with ID 4, not:
Agents
Table 42: Agents Security Role Permissions
| Permission Tab | Portal Permission | API Permission | Description |
|---|---|---|---|
| Global | Agents | /agents/ | Users can view and modify orchestrator management and jobs. |
| Global | Agents > Management | /agents/management/ | Users can view and modify orchestrator management and jobs. |
| Global | Agents > Management > Modify | /agents/management/modify/ |
Users can access the Management Portal areas and Keyfactor API endpoints to:
|
| Global | Agents > Management > Read | /agents/management/read/ |
Users can access the Management Portal areas and Keyfactor API endpoints to:
|
Application Settings
Table 43: Application Settings Security Role Permissions
| Permission Tab | Portal Permission | API Permission | Description |
|---|---|---|---|
| Global | Application Settings | /application_settings/ | Users can view and modify the application settings. |
| Global | Application Settings > Modify | /application_settings/modify/ |
Users can modify the application settings. |
| Global | Application Settings > Read | /application_settings/read/ |
Users can view the application settings. |
Auditing
Table 44: Auditing Security Role Permissions v2
| Permission Tab | Portal Permission | API Permission | Description |
|---|---|---|---|
| Global | Auditing | /auditing/ | Users can access the Audit Log page in the Management Portal, and will be able to make Keyfactor API requests to obtain data from the audit log. |
| Global |
Auditing > Read |
/auditing/read/ |
Users can access the Audit Log page in the Management Portal, and will be able to make Keyfactor API requests to obtain data from the audit log. |
Certificate Authorities
Table 45: Certificate Authorities Security Role Permissions
| Permission Tab | Portal Permission | API Permission | Description |
|---|---|---|---|
| Global | Certificate Authorities > Read | /certificate_authorities/ | Users can view and modify certificate authority records. Users can view, test, and modify revocation monitoring settings. |
| Global |
Certificate Authorities > Modify |
/certificate_authorities/modify/ |
Users can modify certificate authority and revocation monitoring settings to:
|
| Global |
Certificate Authorities > Read |
/certificate_authorities/read/ |
Users can view certificate authority records. Users can view revocation monitoring settings, CA health monitoring and threshold alert recipients and schedules. |
Certificate Stores
Table 46: Certificate Stores Security Role Permissions
See Application Permissions, Certificate Operations, Certificate Store Types and Certificate Stores for more information.
| Permission Tab | Portal Permission | API Permission | Description |
|---|---|---|---|
| Global | Certificate Stores | /certificate_stores/ | Users can view and manage all certificate stores and add certificates to certificate stores, renew/reissue certificates, and remove certificates from certificate stores for all certificate stores. Users can manage certificate store applications. Users can initiate certificate store discovery jobs and manage the resulting certificate stores. |
| Global | Certificate Stores > Modify | /certificate_stores/modify/ |
Users with the Modify role permission for either Certificate Stores or an application (#) can view the certificate stores grid and the applications grid and use the following operations on these pages (plus those available with Read and Schedule permissions):
Note: This permission does not control additions of certificates to certificate stores (see Certificate Stores > Schedule and Certificates).
|
| Application | Certificate Stores > Modify | /certificate_stores/modify/#/ |
See description above. Users with permissions at only the application level can act only on certificates stores within the specified container. For example:
|
| Global | Certificate Stores > Read | /certificate_stores/read/ |
Users with the Read global role permission for either Certificate Stores or a specific application (#) can view the certificate stores grid and the applications grid and use the following operations on these pages:
Users can perform no operations on the certificate stores or applications. |
| Application |
Certificate Stores > Read |
/certificate_stores/read/#/ |
See description above. Users with permissions at only the application level can act only on certificates stores within the specified application. For example:
|
| Global | Certificate Stores > Schedule | /certificate_stores/schedule/ |
Users with the Schedule and Read role permission for either Certificate Stores or an application (#) can view the certificate stores grid and the applications grid and use the following operations on these pages:
|
| Application |
Certificate Stores > Schedule |
/certificate_stores/schedule/#/ |
See description above. Users with permissions at only the application level can act only on certificates stores within the specified application. For example:
|
| Global | Certificate Stores > Change Owner | /certificate_stores/change_owner/ |
Users with the Change Owner and Read role permission for either Certificate Stores or an application (#) can change the certificate owner (a security role) assigned to a certificate found in a certificate store from the View Inventory subpage to the Certificate Stores page. Users will only be able to change the owner to a security role of which they are a member (see Change Owner). Note: This permission does not apply to operations on the Certificate Search page.
|
| Application |
Certificate Stores > Change Owner |
/certificate_stores/change_owner/#/ |
See description above. Users with permissions at only the application level can act only on certificates in certificates stores within the specified application. |
| Global | Certificate Stores > Private Key Read | /certificate_stores/private_key/read/ |
Users with the Private Key Read and Read role permission for either Certificate Stores or an application (#) can download a certificate found in a certificate store with its private key from the View Inventory subpage to the Certificate Stores page. Note: This permission does not apply to operations on the Certificate Search page.
|
| Container |
Certificate Stores > Private Key Read |
/certificate_stores/private_key/read/#/ |
See description above. Users with permissions at only the application level can act only on certificates in certificates stores within the specified application. |
| Global | Certificate Stores > Metadata Modify | /certificate_stores/metadata/modify/ |
Users with the Metadata Modify and Read role permission for either Certificate Stores or an application (#) can edit the metadata fields for a certificate found in a certificate store from the View Inventory subpage to the Certificate Stores page. Note: This permission does not apply to operations on the Certificate Search page.
|
| Container |
Certificate Stores > Metadata Modify |
/certificate_stores/metadata/modify/#/ |
See description above. Users with permissions at only the application level can act only on certificates in certificates stores within the specified application. |
| Global | Certificate Stores > Revoke | /certificate_stores/revoke/ |
Users with the Revoke and Read role permission for either Certificate Stores or an application (#) can revoke a certificate found in a certificate store from the View Inventory subpage to the Certificate Stores page. Note: This permission does not apply to operations on the Certificate Search page.
|
| Container |
Certificate Stores > Revoke |
/certificate_stores/revoke/#/ |
See description above. Users with permissions at only the application level can act only on certificates in certificates stores within the specified application. |
Certificate Templates
Table 47: Certificate Templates Security Role Permissions
| Permission Tab | Portal Permission | API Permission | Description |
|---|---|---|---|
| Global | Certificate Templates | /certificate_templates/ | Users can view and modify certificate template records. |
| Global |
Certificate Templates > Modify |
/certificate_templates/modify/ |
Users can modify certificate template settings to import, edit, and configure system settings for certificate templates. |
| Global |
Certificate Templates > Read |
/certificate_templates/read/ |
Users can view certificate template records. |
Certificates
Table 48: Certificates Security Role Permissions
| Permission Tab | Portal Permission | API Permission | Description |
|---|---|---|---|
| Global | Certificates | /certificates/ | Users can view, modify, and act on everything certificate-related, including certificates in collections, certificates found in a search that are not in a collection, certificate import, certificate enrollment, and pending certificate request management. |
| Global | Certificates > Collections | /certificates/collections/ | Users can view, modify, and act on everything related to certificate collections, including change owner, modify metadata, revoke, access private keys, and delete certificates. |
| Global | Certificates > Change Owner | /certificates/collections/change_owner/ | Users can change the certificate owner (a security role) assigned to any certificate. Users will only be able to change the owner to a security role of which they are a member. See Change Owner. |
| Collection | Certificates > Change Owner | /certificates/collections/change_owner/#/ | Users can change the certificate owner assigned to certificates in the specified certificate collection. Users will only be able to change the owner to a security role of which they are a member. See Change Owner. |
| Global | Certificates > Delete | /certificates/collections/delete/ |
Users can delete certificates (but not exclude) and, if applicable, the private keys of the certificates from the Keyfactor Command database for any certificates. Only users with both delete, and delete and exclude permissions will be able to delete certificates with or without excluding them. |
| Collection | Certificates > Delete | /certificates/collections/delete/#/ |
Users can delete certificates and, if applicable, the private keys of the certificates from the Keyfactor Command database for certificates in the specified certificate collection. Only users with both delete, and delete and exclude permissions will be able to delete certificates with or without excluding them. |
| Global | Certificates > Delete And Exclude | /certificates/collections/delete_and_exclude/ |
Users can delete AND exclude certificates and, if applicable, the private keys of the certificates, which will permanently delete a certificate from the Keyfactor Command database, excluding it from all product functionality. See Excluded Certificates. |
| Collection | Certificates > Delete And Exclude | /certificates/collections/delete_and_exclude/#/ |
Users can delete AND exclude certificates and, if applicable, the private keys of the certificates for any certificates in the specified certificate collection, which will permanently delete a certificate from the Keyfactor Command database, excluding it from all product functionality. See Excluded Certificates. Important: Deletion of a certificate from a collection for which a user has permission will also delete it from collections for which the user does not have permissions.
|
| Global |
Certificates > Metadata Modify |
/certificates/collections/metadata/modify/ | Users can modify certificate metadata for certificates in the Certificate Details dialog (only information on the metadata tab can be edited) and the equivalent API functions for any certificates. |
| Collection |
Certificates > Metadata Modify |
/certificates/collections/metadata/modify/#/ |
Users can modify certificate metadata for certificates in the Certificate Details dialog (only information on the metadata tab can be edited) and the equivalent API functions for certificates in the specified certificate collection. |
| Global | Certificates > Collections | /certificates/collections/modify/ |
Users can view, modify, and act upon certificate-related functions including certificates in collections and certificates found in a search that are not in a collection. Users can add or edit certificate collections. See Certificate Collection Permissions for more information. |
| Global | Certificates > Private Key Import | /certificates/collections/private_key/import/ |
Users can save the private key for the certificate in the Keyfactor Command database. Users with this role can add a certificate with an associated private key through the Add Certificate option under the Certificate Locations menu and the private key will be stored in the Keyfactor Command database. Users must also be granted the Import role to be able to use the Add Certificate feature. Note: This permission cannot be applied at the certificate collection level.
|
| Global |
Certificates > Download with Private Key |
/certificates/collections/private_key/read/ | Users can download a certificate with its private key for any certificate. |
| Collection |
Certificates > Private Key Read |
/certificates/collections/private_key/read/#/ | Users can download a certificate with its private key for certificates in the specified certificate collection. |
| Global | Certificates > Read | /certificates/collections/read/ |
Users can view any certificates, including certificate history, and can download certificates. Users who also have Read permissions for Certificate Store Management or certificate store container permissions can add certificates to certificate stores from Certificate Search and Certificate Collections. The certificate operations possibly available to users with this permission are:
Users with global Read role permissions can browse to Certificate Search in the Management Portal and view all saved certificate collections. They can view any certificate in the Keyfactor Command database and are not limited to just those returned by select collections. Users with this permission can view the certificates returned by searches and open the details of the certificates. |
| Collection |
Certificates > Read |
/certificates/collections/read/#/ |
Users can view certificates in the specified certificate collection, including certificate history, and can download certificates. Users who also have Read permissions for Certificate Store Management or certificate store application permissions can add the certificates in the collection to certificate stores from Certificate Search and Certificate Collections. The certificate operations possibly available to users with this permission are:
Users with collection-level Read role permissions on a collection will see the collections to which they have been granted access appear on the Certificate Collections menu (if they have been configured to appear on the menu—see Certificate Collection Management). The users will be able to view all the certificates in the collections and open the details of the certificates. |
| Global | Certificates > Revoke | /certificates/collections/revoke/ |
Users can revoke any certificates through Keyfactor Command. This includes certificates that have been issued by a Microsoft or EJBCA CA configured for synchronization or by a cloud-based certificate vendor that is managed via a Keyfactor certificate gateway. Important: In order to successfully revoke certificates for a Microsoft CA, Issue and Manage Certificates and Manage CA permissions on the CA must be granted to one of the following, depending on the authentication configuration in Keyfactor Command:
|
| Collection | Certificates > Revoke | /certificates/collections/revoke/#/ |
Users can revoke certificates in the specified certificate collection through Keyfactor Command. This includes certificates that have been issued by a Microsoft or EJBCA CA configured for synchronization or by a cloud-based certificate vendor that is managed via a Keyfactor certificate gateway. Important: In order to successfully revoke certificates for a Microsoft CA, Issue and Manage Certificates and Manage CA permissions on the CA must be granted to one of the following, depending on the authentication configuration in Keyfactor Command:
|
| Global | Certificates > Enrollment | /certificates/enrollment/ | Users can use all the enrollment-related functions, including CSR generation, CSR enrollment, and PFX enrollment. |
| Global |
Certificates > Enrollment > Csr |
/certificates/enrollment/csr/ |
Users can use the CSR Enrollment page in the Management Portal and the equivalent Keyfactor API functions. |
| Global |
Certificates > Enrollment > Csr Generation |
/certificates/enrollment/csr_generation/ |
Users can use the CSR Generation page in the Management Portal and the equivalent Keyfactor API functions. |
| Global |
Certificates > Enrollment > Pfx |
/certificates/enrollment/pfx/ |
Users can use the PFX Enrollment page in the Management Portal and the equivalent Keyfactor API functions. |
| Global | Certificates > Excluded Certificates | /certificates/excluded_certificates/ | Users can view certificates that have been marked to be deleted and excluded from Keyfactor Command on the Excluded Certificates page. |
| Global | Certificates > Excluded Certificates > Read | /certificates/excluded_certificates/read/ | Users can view certificates that have been marked to be deleted and excluded from Keyfactor Command on the Excluded Certificates page. |
| Global | Certificates > Expanded Change Owner | /certificates/expanded_change_owner/ |
Users can change the certificate owner to any role within the permission sets of which the acting user is a member. The Change Owner dialog presents a search select dropdown containing all the allowed roles. This list is inactive if the acting user is not a member of the original certificate owner's security role permission set. This permission setting overrides the Certificates > Collections > Change Owner permission at both the global and collection levels when both permissions are set. To use the Expanded Change Owner permission, a user must hold at least one security role within a permission set and have either Security or Security > Read permissions on that role to access all security roles within the permission set. For more details, see Change Owner. |
| Global | Certificates > Import | /certificates/import/ |
Users can import certificates using the Management Portal Add Certificate page or the Keyfactor API POST /Certificates/Import operation. Users who also have Read permissions for Certificate Store Management or application permissions can add certificates to certificate stores from Add Certificate. Note: This permission was controlled at the global certificate collection level in previous versions of Keyfactor Command, but has moved to a higher level separate from collections.
|
| Global |
Certificates > Requests Manage |
/certificates/requests/manage/ |
Users can use the Pending CSRs page in the Management Portal and the equivalent Keyfactor API functions. |
| Global | Certificates > Risk Intelligence | /certificates/risk_intelligence/ | Users may both view the Risk Intelligence dashboard on the certificate details page and make modifications through the Keyfactor APIendpoints for Risk Intelligence. Must be licensed for Risk Intelligence to access this permission. |
| Global | Certificates > Risk Intelligence > Modify | /certificates/risk_intelligence/modify/ | Users can modify Risk Intelligence through the Keyfactor API endpoints. Must be licensed for Risk Intelligence to access this permission. |
| Global | Certificates > Risk Intelligence > Read | /certificates/risk_intelligence/read/ | Users can view the Risk Intelligence dashboard on the certificate details page. Must be licensed for Risk Intelligence to access this permission. |
[Legacy] Dashboard
Table 49: Legacy Dashboard Security Role Permissions
| Permission Tab | Portal Permission | API Permission | Description |
|---|---|---|---|
| Global | Dashboard | /dashboard/ | Users have full legacy dashboard permissions. |
| Global |
Dashboard > Read |
/dashboard/read/ |
Users can view the panels on their personalized legacy dashboard. |
| Global | Dashboard > Risk Header | /dashboard/risk_header/ | Users can view the risk header at the top of the legacy dashboard. |
| Global | Dashboard > Risk Header > Read | /dashboard/risk_header/read/ | Users can view the risk header at the top of the legacy dashboard. |
Enrollment Pattern
Table 50: Enrollment Pattern Security Role Permissions
| Permission Tab | Portal Permission | API Permission | Description |
|---|---|---|---|
| Global | Enrollment Pattern | /enrollment_pattern/ | Users can view and modify the enrollment pattern settings. |
| Global |
Enrollment Pattern > Read |
/enrollment_pattern/read/ |
Users can view the enrollment pattern settings. |
| Global | Enrollment Pattern > Modify | /enrollment_pattern/write/ | Users can modify the enrollment pattern settings. |
Identity Providers
Table 51: Identity Providers Security Role Permissions
| Permission Tab | Portal Permission | API Permission | Description |
|---|---|---|---|
| Global | Identity Providers | /identity_providers/ | Users can view and modify the identity provider settings for identity providers. |
| Global | Identity Providers > Modify | /identity_providers/modify/ | Users can modify the identity provider settings for identity providers. |
| Global | Identity Providers > Read | /identity_providers/read/ | Users can view the identity provider settings for identity providers. |
Metadata
Table 52: Certificate Metadata Types Security Role Permissions
| Permission Tab | Portal Permission | API Permission | Description |
|---|---|---|---|
| Global | Metadata | /metadata/ | Users can view and modify custom metadata attribute definitions. |
| Global | Metadata > Types | /metadata/types/ | Users can view and modify custom metadata attribute definitions. |
| Global |
Metadata > Types > Modify |
/metadata/types/modify/ |
Users can add, edit, and delete custom metadata attribute definitions on the Certificate Metadata page in the Management Portal and the equivalent API functions. |
| Global |
Metadata > Types > Read |
/metadata/types/read/ |
Users can view custom metadata attribute definitions on the Certificate Metadata page in the Management Portal and the equivalent API functions. |
Monitoring
Table 53: Monitoring Security Role Permissions
| Permission Tab | Portal Permission | API Permission | Description |
|---|---|---|---|
| Global | Monitoring | /monitoring/ | Users can view, modify, and test the pending, issued, and denied certificate request alerts and the event handler registration settings. |
| Global | Monitoring > Alerts | /monitoring/alerts/ | Users can view, modify, and test the pending, issued, and denied certificate request alerts. |
| Global |
Monitoring > Alerts > Modify |
/monitoring/alerts/modify/ |
Users can modify the pending, issued, and denied certificate request alerts, including the alert text, recipients, and event handlers. Users can also add new alerts, delete alerts, and configure the pending alert delivery schedule. |
| Global |
Monitoring > Alerts > Read |
/monitoring/alerts/read/ |
Users can view the pending, issued, and denied certificate request alerts. |
| Global | Monitoring > Alerts > Schedule | /monitoring/alerts/schedule/ |
Users can schedule the revocation monitoring alerts. Tip: To allow the revocation monitoring alerts page to appear in the Keyfactor Command Management Portal, users also require Read permissions for Certificate Authorities.
|
| Global | Monitoring > Alerts > Schedule > Revocation | /monitoring/alerts/schedule/revocation/ |
Users can schedule the revocation monitoring alerts. Tip: To allow the revocation monitoring alerts page to appear in the Keyfactor Command Management Portal, users also require Read permissions for Certificate Authorities.
|
| Global | Monitoring > Alerts > Test | /monitoring/alerts/test/ |
Users can test the pending certificate request alerts, including sending email to recipients. Users must also have Read permissions for Alerts. |
| Global | Monitoring > Handlers | /monitoring/handlers/ | Users can view and modify the event handler registration settings. |
| Global | Monitoring > Handlers > Registration | /monitoring/handlers/registration/ | Users can view and modify the event handler registration settings. |
| Global |
Monitoring > Handlers > Registration > Modify |
/monitoring/handlers/registration/modify/ |
Users can modify the event handler registration settings. |
| Global |
Monitoring > Handlers > Registration > Read |
/monitoring/handlers/registration/read/ |
Users can view the event handler registration settings. |
Privileged Access Management (PAM)
Table 54: Privileged Access Management Security Role Permissions
| Permission Tab | Portal Permission | API Permission | Description |
|---|---|---|---|
| Global | Pam | /pam/ | Users can view and modify any PAM provider. |
| Global | Pam > Modify | /pam/modify/ | Users can add, edit, and delete any PAM provider. |
| PAM Provider |
Pam > Modify |
/pam/modify/#/ |
Users can add, edit, and delete the specified PAM provider. |
| Global | Pam > Read | /pam/read/ | Users can view any PAM provider. Users can select any PAM providers to provide credentials within Keyfactor Command for:
|
| PAM Provider |
Pam > Read |
/pam/read/#/ |
Users can view or select the specified PAM provider. |
[Management] Portal
Table 55: Management Portal Security Role Permissions
| Permission Tab | Portal Permission | API Permission | Description |
|---|---|---|---|
| Global | Portal | /portal/ | Users can access the Management Portal. |
| Global |
Portal > Read |
/portal/read/ |
Users can access the Management Portal. This permission must be turned on for all roles that will access the Management Portal. |
Reports
Table 56: Reports Security Role Permissions
| Permission Tab | Portal Permission | API Permission | Description |
|---|---|---|---|
| Global | Reports | /reports/ | Users can view and run reports. For newer reports, users can modify the report configuration. For legacy reports, users can modify the delivery schedule. Users can also add, edit, and delete custom legacy reports. |
| Global |
Reports > Modify |
/reports/modify/ |
For newer reports, users can modify the report configuration. For legacy reports, users can modify the delivery schedule. Users can also add, edit, and delete custom legacy reports. These actions can also be performed using equivalent Keyfactor API functions. Note: Report configuration and scheduling are limited by collection permissions. Users with Reports > Read and Reports > Modify permissions must also have either global certificate Read permission or Read permission for the relevant certificate collections to add, edit, or delete reports and schedules associated with those collections. For newer reports, this includes adding, editing, and deleting reports. For legacy reports, this includes adding, editing, and deleting delivery schedules. If permissions are granted on a collection-by-collection basis rather than globally, users cannot modify reports or schedules for collections for which they do not have Read permission.
|
| Global |
Reports > Read |
/reports/read/ |
Users can view and run reports. |
Scripts
Table 57: Scripts Security Role Permissions
| Permission Tab | Portal Permission | API Permission | Description |
|---|---|---|---|
| Global | Scripts | /scripts/ | Users can view and modify scripts used in alert event handlers and workflows. |
| Global |
Scripts > Modify |
/scripts/modify/ |
Users can add, edit, and delete scripts used in alert event handlers and workflows. |
| Global |
Scripts > Read |
/scripts/read/ |
Users can view scripts used in alert event handlers and workflows. |
Security
Table 58: Security Settings Security Role Permissions
| Permission Tab | Portal Permission | API Permission | Description |
|---|---|---|---|
| Global | Security | /security/ | Users can view and modify the settings for Security Roles and Security Claims. |
| Global |
Security > Modify |
/security/modify/ |
Users can modify the settings for Security Roles and Security Claims. |
| Global |
Security > Read |
/security/read/ |
Users can view the settings for Security Roles and Security Claims. Users must also have the System Settings > Read permission to access this in the Management Portal. |
SMTP
Table 59: SMTP Security Role Permissions
| Permission Tab | Portal Permission | API Permission | Description |
|---|---|---|---|
| Global | Smtp | /smtp/ | Users can view, modify, and test the SMTP settings. |
| Global |
Smtp > Modify And Test |
/smtp/modify/ |
Users can update the SMTP settings in the Management Portal and the equivalent API functions. |
| Global |
Smtp > Read |
/smtp/read/ |
Users can view the SMTP configuration page in the Management Portal and the equivalent API functions and see the current SMTP settings. |
| Global | Smtp > Test | /smtp/test/ |
Users with Smtp > Read permissions can use the Test option on SMTP configuration settings in the Management Portal Users without Smtp > Read permissions can use the System Settings > Test Email Notification option in the Management Portal. Users can use the POST /SMTP/Test and POST /SMTP/TestOnly API operations. |
SSH
Table 60: SSH Security Role Permissions
| Permission Tab | Portal Permission | API Permission | Description |
|---|---|---|---|
| Global | Ssh | /ssh/ | Users can use all SSH functions. |
| Global | Ssh > Enterprise Admin | /ssh/enterprise_admin/ | Users can use all SSH functions. |
| Global |
Ssh > Server Admin |
/ssh/server_admin/ |
Users can use all SSH functions, except creating server groups and assigning server group owners. Users have limited access to some functions based on server group ownership. |
| Global |
Ssh > User |
/ssh/user/ |
Users can generate their own SSH keys. |
SSL
Table 61: SSL Management Security Role Permissions
| Permission Tab | Portal Permission | API Permission | Description |
|---|---|---|---|
| Global | Ssl | /ssl/ | Users can view and modify the SSL Discovery settings. |
| Global |
Ssl > Modify |
/ssl/modify/ |
Users can modify the SSL Discovery settings:
|
| Global |
Ssl > Read |
/ssl/read/ |
Users can view the SSL Discovery pages in the Management Portal and the equivalent API functions, including defined networks and the network ranges configured for them, agent pools, and scan results. Users can use the query tool on the Results tab to find discovered endpoints and then view the discovered endpoints, including the details for the endpoints. |
System Settings
Table 62: System Settings Permissions
| Permission Tab | Portal Permission | API Permission | Description |
|---|---|---|---|
| Global | System Settings | /system_settings/ |
Users can modify the System Settings for:
|
| Global |
System Settings > Modify |
/system_settings/modify/ |
Users can modify the System Settings for:
|
| Global |
System Settings > Read |
/system_settings/read/ |
Users can view the System Settings for:
|
Trust Bundles
Table 63: Trust Bundle Security Role Permissions
| Permission Tab | Portal Permission | API Permission | Description |
|---|---|---|---|
| Global | Trust Bundles | /trust_bundles/ | Users can view and modify the Trust Bundles settings. |
| Global |
Trust Bundles > Modify |
/trust_bundles/modify/ |
Users can use the modify Trust Bundles settings in the Management Portal and the equivalent API functions:
|
| Global |
Trust Bundles > Read |
/trust_bundles/read/ |
Users can view the Trust Bundles pages in the Management Portal and the equivalent API functions. Users can use the Manage Roots option to open a trust bundle and view the certificates within it. |
Workflows
Table 64: Workflows Security Role Permissions
| Permission Tab | Portal Permission | API Permission | Description |
|---|---|---|---|
| Global | Workflows | /workflows/ | Users can view and modify the configured workflow definitions and view and manage all initiated workflow instances. |
| Global | Workflows > Definitions | /workflows/definitions/ | Users can view and modify the configured workflow definitions. |
| Global |
Workflows > Definitions > Modify |
/workflows/definitions/modify/ |
Users can modify both the built-in and any custom workflow definitions, including the name and description and the configuration for the steps. Users can also add new workflow definitions, delete workflow definitions, publish workflow definitions, and import and export workflow definitions. |
| Global |
Workflows > Definitions > Read |
/workflows/definitions/read/ |
Users can view the configured workflow definitions. |
| Global | Workflows > Instances | /workflows/instances/ | Users can view and manage all initiated workflow instances. |
| Global | Workflows > Instances > Manage | /workflows/instances/manage/ |
Users can manage initiated workflow instances, including stopping, restarting, and deleting them. |
| Global |
Workflows > Instances > Read |
/workflows/instances/read/ |
Users can view all the workflow instances that have been initiated. |
| Global | Workflows > Instances > Read > Mine | /workflows/instances/read/mine/ |
Users can view the workflow instances that have been initiated by them (for example, because they enrolled for a certificate). |
| Global |
Workflows > Instances > Read > Pending |
/workflows/instances/read/pending/ |
Users can view the workflow instances that have been initiated and are awaiting input from them. Tip: There is not a security permission at this level that controls whether users can provide input (a signal) to a workflow instance. This is controlled using the security roles configured on the specific workflow definition. Any user who holds one of the roles configured in the workflow step that requires a signal may provide the necessary input. The user does not need to hold the Workflows > Instances > Read > Pending permission to provide the input.
|
Was this page helpful? Provide Feedback