Skip to main content
Version: Next

Role permissions settings

Certificates

CertificateDescription
Add from fileAllows installing certificates on the unit.
Add from CA (FNMT)Allows performing operations related to FNMT.
EditAllows users to:
  • Disable/Enable a certificate.
  • Edit the certificate alias and the use reason field.
  • Set the certificate PIN.
  • ReplaceGrants permission to replace certificates.
    DeleteAllows deleting a certificate along with its associated private key. This action is permanent.
    Manage ownerAllows editing or assigning an owner to a certificate. Owners can use the certificate, overriding all policies.
    FirmaprofesionalDescription
    Issue from FirmaprofesionalGrants permission to use the API to request and consolidate certificates on the server. The generated certificates will be assigned to the groups defined in the role.
    Download Firmaprofesional certificateAllows certificate holders to download a copy of their certificate from the personal area. Each certificate can be downloaded once.
    Allow operator copyAllows users to obtain a backup copy of the certificate.
    PendingDescription
    InstallAllows users to upload personal certificates for later activation.
    DeleteGrants permission to delete activation-pending certificates.
    CADescription
    InstallGrants users permission to install CA certificates on the unit.
    DeleteAllows users to delete CA certificates.
    EmailDescription
    InstallAllows users to install email certificates on the unit.
    DeleteGrants permission to delete email certificates.
    AlertsDescription
    ViewGrants users permission to view any configured certificate alerts.
    CreateAllows users to create certificate alerts.
    EditAllow users to edit any already created certificate alerts.
    DeleteGrants users permission to delete any already created certificate alerts.

    Policies

    SectionPermissionsDescription
    User PoliciesView, Edit, Delete, and CreateAllows to view, edit, delete, and create policies.
    WebsitesView, Edit, Delete, and CreateGrants permission to view, edit, delete, and create site groups.
    ApplicationsView, Edit, Delete, and CreateGrants permission to view, edit, delete, and create application groups.
    tip

    For these settings to be applicable, the user's role must also be assigned to the policy. For more information, see Policy operations.

    Events

    SectionDescription
    UsersAllows users to see events related to other users within the domain scoped by this role.
    CertificatesGrants permission to view events related to certificates in the certificate group assigned to this role.
    PoliciesAllows users to view events related to policies assigned to this role.
    AllGrants permission to view all event logs.

    Access

    Domain UsersDescription
    ViewAllows users to view domain settings and users.
    EditGrants users permission to edit domain settings and users.

    System

    SectionPermissionsDescription
    Services**View and EditAllows users to view and edit the Services tab in the System section.
    External Log ServicesView and EditGrants users permission to view and edit external log services configuration.
    High AvailabilityView and EditGrants users permission to view and edit the HA tab in the System section.
    System LogViewAllows users to view the audit list tab in the Events section.

    Unit

    SectionDescription
    ViewAllows users to view system configuration (Unit, Server configuration, and Agent configuration tabs).
    EditGrants permission to view and edit system configuration (Unit, Server configuration, and Agent configuration tabs).
    Server LogsDescription
    DownloadAllows users to download server logs.
    NetworkDescription
    ViewGrants users permission to view the server's network configuration and service ports.
    EditAllows users to view and edit the server's network configuration and service ports.
    BackupDescription
    GenerateGrants users permission to generate a backup copy of the server database.
    RestoreAllows users to restore a backup copy of the server database.
    MaintenanceDescription
    Upgrade/DowngradeEnables users to upgrade the server version or revert to a previous version.
    Restart/ShutdownGrants users permission to manage server restart and shutdown operations from the admin console.

    Agents

    SectionDescription
    ManageGrants users permission to view the Agent Management tab in the System section.
    Update PackagesAllows users to view the Agent Updates tab in the System section.