Skip to main content
Version: 4.32

Role permissions settings

Certificates

CertificateDescription
Add from fileAllows installing certificates on the unit.
Add from CA (FNMT)Allows performing operations related to FNMT.
EditAllows users to:
  • Disable/Enable a certificate.
  • Edit the certificate alias and the use reason field.
  • Set the certificate PIN.
ReplaceGrants permission to replace certificates.
DeleteAllows deleting a certificate along with its associated private key. This action is permanent.
Manage ownerAllows editing or assigning an owner to a certificate. Owners can use the certificate, overriding all policies.
FirmaprofesionalDescription
Issue from FirmaprofesionalGrants permission to use the API to request and consolidate certificates on the server. The generated certificates will be assigned to the groups defined in the role.
Download Firmaprofesional certificateAllows certificate holders to download a copy of their certificate from the personal area. Each certificate can be downloaded once.
Allow operator copyAllows users to obtain a backup copy of the certificate.
PendingDescription
InstallAllows users to upload personal certificates for later activation.
DeleteGrants permission to delete activation-pending certificates.
CADescription
InstallGrants users permission to install CA certificates on the unit.
DeleteAllows users to delete CA certificates.
EmailDescription
InstallAllows users to install email certificates on the unit.
DeleteGrants permission to delete email certificates.
AlertsDescription
ViewGrants users permission to view any configured certificate alerts.
CreateAllows users to create certificate alerts.
EditAllow users to edit any already created certificate alerts.
DeleteGrants users permission to delete any already created certificate alerts.

Policies

SectionPermissionsDescription
User PoliciesView, Edit, Delete, and CreateAllows to view, edit, delete, and create policies.
WebsitesView, Edit, Delete, and CreateGrants permission to view, edit, delete, and create site groups.
ApplicationsView, Edit, Delete, and CreateGrants permission to view, edit, delete, and create application groups.
tip

For these settings to be applicable, the user's role must also be assigned to the policy. For more information, see Policy operations.

Events

SectionDescription
UsersAllows users to see events related to other users within the domain scoped by this role.
CertificatesGrants permission to view events related to certificates in the certificate group assigned to this role.
PoliciesAllows users to view events related to policies assigned to this role.
AllGrants permission to view all event logs.

Access

Domain UsersDescription
ViewAllows users to view domain settings and users.
EditGrants users permission to edit domain settings and users.

System

SectionPermissionsDescription
Services**View and EditAllows users to view and edit the Services tab in the System section.
External Log ServicesView and EditGrants users permission to view and edit external log services configuration.
High AvailabilityView and EditGrants users permission to view and edit the HA tab in the System section.
System LogViewAllows users to view the audit list tab in the Events section.

Unit

SectionDescription
ViewAllows users to view system configuration (Unit, Server configuration, and Agent configuration tabs).
EditGrants permission to view and edit system configuration (Unit, Server configuration, and Agent configuration tabs).
Server LogsDescription
DownloadAllows users to download server logs.
NetworkDescription
ViewGrants users permission to view the server's network configuration and service ports.
EditAllows users to view and edit the server's network configuration and service ports.
BackupDescription
GenerateGrants users permission to generate a backup copy of the server database.
RestoreAllows users to restore a backup copy of the server database.
MaintenanceDescription
Upgrade/DowngradeEnables users to upgrade the server version or revert to a previous version.
Restart/ShutdownGrants users permission to manage server restart and shutdown operations from the admin console.

Agents

SectionDescription
ManageGrants users permission to view the Agent Management tab in the System section.
Update PackagesAllows users to view the Agent Updates tab in the System section.