Software Trust Manager user permissions
Assign one or more Software Trust Manager permissions when you create a custom role.
Account permissions for standard and service users
The following permissions are available in your account:
Permission | User can | Notes |
---|---|---|
Manage account settings | Update Software Trust Manager > Accounts > Account settings. | |
Manage CertCentral API key | Delete, disable, enable, setup, update and validate a CertCentral API key. | |
Manage all teams |
| |
Manage my teams | View, update, deactivate, and map resources to existing teams that they are part of, provided that they have relevant resource permissions. | |
View audit log | View audit and signature logs in the account. | |
Export audit logs | Export audit and signature logs in the account. | |
Permission | User can | Notes |
---|---|---|
View keypair | View keypairs and key rotations relying on keypairs assigned to them. | Users with |
Generate keypair | Create a new keypair. | |
Import keypair | Import keypairs into the account. | To import a GPG secring, |
Request keypair export | Request to export keypairs that they are assigned to. | Users with |
Approve keypair export | Approve requests to export keypairs that they are assigned to. | Users with |
Approve keypair delete | Approve requests to delete keypairs that they are assigned to. | Users with |
Manage keypair |
| |
Sign | Sign software with keypairs assigned to them. |
Permission | User can | Notes |
---|---|---|
View certificate | View certificate details for all certificates assigned to them. | Users with |
Generate certificate | Create a new certificate using keypairs that they are assigned to. | Users with |
Import certificate | Import certificates for keypairs that they are assigned to. | Users with |
Revoke certificate | Revoke certificates associated with keypairs that they are assigned to. | Users with |
Manage certificate hierarchy | View and create hierarchies. They can also activate and deactivate restricted hierarchies. | |
View certificate profile | View certificate profiles created by the user. | |
Manage certificate profiles |
| |
View certificate template | View certificate template details in the account. |
System permissions for on-premises administration
For on-premises customers, these permissions are available for custom user roles used for system administration.
Permission | User can | Notes |
---|---|---|
Manage CertCentral API key | Delete, disable, enable, setup, update and validate a CertCentral API key. | |
View audit log | View audit and signature logs in the account. | |
Export audit logs | Export audit and signature logs in the account. | |
View health | View app health (API). |
Permission | User can | Notes |
---|---|---|
View keypair | View keypair details in the account. | |
Import keypair | Import keypairs into the account. | |
Manage keypair |
| |
Permission | User can | Notes |
---|---|---|
View certificate | View certificate details in the account. | |
Manage certificate hierarchy | Create, update, approve, reject, suspend, unsuspend, and view certificate hierarchies. | |
View certificate template | View certificate template details in the account. | |
Manage certificate template | Create, update, and clone certificate templates. | |
View certificate profile | View certificate profile details in the account. | |
Manage certificate profiles |
| |
Permission | User can |
---|---|
View release | View releases in the account. |