- 5 minutes to read
- Print
- DarkLight
- PDF
How to set up the Access Groups
- 5 minutes to read
- Print
- DarkLight
- PDF
This article explains how to set up Access Groups to use within Certificate Manager.
Create an access group
To create a new group, follow these steps:
- In the top left corner, click Grid Menu, identified by the nine squares icon, and then select Certificate Manager.
- On the side menu, select Settings and then Access Groups.
- In the upper right corner, click View Actions (the three vertical dots icon).
- Select New; this will open the Access group registration form.
- In Access group name, enter the group name.
- Keep Enabled as Yes.
- If necessary, add another Description about the group.
Settings tab
Download Settings section
- Set the items that group users can download or not.
- In User can download the request?, check Yes or No.
- In User can download key?, check Yes or No.
- In User can download certificate?, check Yes or No.
Certificate Passwords section
- Configure the password settings.
- In User can view the passwords certificate, check the box to allow users to view passwords.
- In Requires justification to view certificate password, check the box to require users to write a justification before viewing passwords.
- In Require approval to view a password, check the box to require an approver to authorize viewing passwords.
- In Approvals required for viewing, set the number of approvals needed to authorize the view. Different approvers must authorize the request.
- In Disapprovals required to cancel, define the number of denials that, when added together, cancel the request. Different approvers must deny the request.
- In Approval in levels, check the box to define that approvals will happen in levels.
- From the Part of the password to be viewed dropdown, select among the viewing options: Complete password, First password part, or Second password part.
Certificate signature and renewal section
- Configure the subscription settings.
- In Require reason for signature, check the box to require users to write a reason before signing certificates.
- In Require approval for signature, check the box to require an approver to authorize signing certificates.
- In Approval in levels, check the box to define that approvals will happen in levels.
- In Approvals needed to sign, define the number of approvals needed to authorize the signature. Different approvers must authorize the request.
- In Disapprovals required to cancel, define the number of denials that, when added together, cancel the request. Different approvers must deny the request.
Certificate Publishing section
- Configure the publishing settings.
- In Require reason to publish, check the box to require users to write a justification before publishing certificates.
- In Require approval to publish, check the box to require an approver to authorize publishing certificates.
- In Approval in levels, check the box to define that approvals will happen in levels.
- In Approvals needed to publish, define the number of approvals needed to authorize the publication. Different approvers must authorize the request.
- In Disapprovals required to cancel, define the number of denials that, when added together, cancel the request. Different approvers must deny the request.
Settings for approvals section
- Configure other approvals settings.
- In Governance ID required when justifying?, check Yes or No to define that the user has to add a code when justifying. The code is intended to track and control user actions.
- In Always add user manager to approvers?, check Yes or No to define that the user manager of the access group in question will always be among the approvers.
Criteria tab
You can set additional conditions to allow the group to perform actions. For instance, when completing the Organization field, you restrict that only the users of the group who are also part of that organization can take actions.
- Fill in the CA, Organization, DNS, or Tags fields according to your scenario and needs.
- Under Allowed authorities, check all authorities that can sign the certificates. You must have authorities registered.
Users tab
- Add all users that will be part of the access group.
- Click on the plus icon next to the word Users.
- In the System users window, locate the desired users. Use the search fields or the scroll bar.
- Check the box on the left next to the username.
- Click Add.
When a user belongs to multiple access groups, the system will apply the settings of the most restrictive group.
Approvers tab
To become an approver, a user must have the Certificates Approver profile.
- Add all approving users to the access group.
- Click on the plus icon next to the word Approvers.
- In the Approvers window, locate the desired users. Use the search fields or the scroll bar.
- Check the box on the left next to the username.
- Click Add.
- Click Save to confirm the settings.
On the Access groups' main page, you'll see the group you just created.
Edit a group
To edit a group, follow these steps:
- On the Access groups' main page, locate the group you want.
- In the corresponding Action column, click Edit (the pencil icon).
- Update the form.
- Click Save to confirm the changes.
The counterclockwise arrow icon in the top right corner refreshes the screen.
Clone a group
Cloning serves to copy all the settings of an existing group, speeding up the creation process.
To clone a group, follow these steps:
- On the Access groups' main page, locate the group you want to clone.
- In the corresponding Action column, click View Actions (the three vertical dots icon).
- Select Clone.
- Click Yes to confirm the cloning.
The new group will appear listed on the Access groups' main page with the word copy in parentheses.
Deactivate a group
To deactivate a group, follow these steps:
- On the Access groups' main page, locate the group to deactivate.
- In the corresponding Action column, click Edit (the pencil icon).
- In Enabled, set to No.
- Click Save to confirm the deactivation.
The group will disappear from the list on the main page because the search field Enabled is set to Yes as default. Select No if you want to find the group you deactivated.
You can always select Edit to enable the group again.
Do you still have questions? Reach out to the senhasegura Community.