Skip to main content

Critical Private CA roles and permissions

Assign Private CA roles to standard users and service users in Account Manager. Evaluate Account Manager access and Private CA access separately.

See DigiCert Private CA user roles for the complete permission list for each role.

Account roles for standard and service users

These are user roles in DigiCert-hosted DigiCert ONE environments.

Action

Recommended role

Security implication

Request and authorize key escrow and CA recovery, with read access to managed CAs

PKI manager

Includes Manage CA, Manage revoke CA, Manage OCSP responder, Manage CA escrow recovery, Manage recover escrow key, Manage HSM management, and Manage templates.

This role can revoke a CA and recover escrowed keys. Restrict to authorized PKI administrators.

Escrow and recover end-entity keys

Key escrow

Includes Manage recover escrow key and Manage CA escrow recovery.

Grants access to protected key material. Restrict tightly and review every recovery event.

Review CA and certificate information without making changes

Read only

Read access to CAs, certificates, AIAs, domains, OCSP responders, templates, and audit logs.

Note this role also includes Manage CA escrow recovery, Manage HSM management, and Manage recover escrow key.

Review the complete role definition before assuming it is read-only in every respect.

System roles for customer-hosted environments

These are user roles in customer-hosted DigiCert ONE environments.

Action

Recommended role

Security implication

Configure the deployment, manage CAs and HSMs, and approve escrow recovery

CA admin

Broadest administrative role. Includes Manage CA, Manage revoke CA, Manage escrow master keys, Manage import certificate, Manage default configurations, and Manage HSM management.

User can change the trust hierarchy and revoke a CA, invalidating every certificate it issued.

Create and manage CAs, CRLs, and OCSP responders in daily operations

CA operations

Same CA and certificate permissions as CA admin, including Manage revoke CA and Manage escrow master keys.

Assign only to users with an approved operational need.

Manage and review offline CA requests and key pools

PKI operations

Includes CA management and ceremony permissions but not HSM management.

Review and approve the validation section of offline CA requests

PKI validation

Includes CA management and the ceremony validation approval step.

Separate this role from PKI compliance to maintain separation of duties in key ceremonies.

Review and approve the compliance section of offline CA requests

PKI compliance

Includes CA management and the ceremony compliance approval step.

Separate this role from PKI validation.

Support and audit access without configuration rights

Read only

View access to CAs, certificates, escrow master keys, OCSP responders, templates, ceremony requests, key pools, default configurations, HSM management, and audit logs.

Perform only certificate requests through an integration

Service user

User representing an integrated client. Assign only the permissions the integration requires.

Unnecessary administrative permissions increase the impact of a compromised credential.

Review every default role and its permissions before assigning it. Several Private CA roles include permissions beyond what the role name suggests. For example, both Read only roles include escrow-related permissions.

If one role does not meet the business requirement, assign multiple roles or create a custom user role containing only the required permissions. When you assign multiple roles, the user receives their combined permissions. Review the resulting effective access before saving the change.

Permissions to restrict most tightly

Use this table during access reviews. For each permission, the third column lists every default role that grants it. Follow the links to confirm the full permission set before assigning or removing a role.

Permission

Why it matters

Granted by these default roles

Manage revoke CA

Revoking a CA invalidates every certificate it issued and cannot be undone.

PKI manager, CA admin, CA operations, PKI operations, PKI validation, PKI compliance

Manage escrow master keys

Create and recover an escrowed CA key.

CA admin, CA operations, PKI operations, PKI validation, PKI compliance

Manage recover escrow key

Escrow and recover end-entity keys and certificates.

PKI manager, Key escrow, Read only — account

Manage CA escrow recovery

Escrow CAs and recover them.

PKI manager, Key escrow, Read only — account

Manage HSM management

Controls where CA keys are generated and stored.

PKI manager, Key escrow, Read only — account, CA admin, CA operations

Manage import certificate

Allows external roots and ICAs to be introduced into the trust hierarchy.

CA admin, CA operations, PKI operations, PKI validation, PKI compliance

Manage default configurations

Changes CRL and OCSP issuing behavior for Roots and ICAs.

CA admin, CA operations, PKI operations, PKI validation, PKI compliance

Manage templates

Changes what certificates may be issued, including validity and key requirements.

PKI manager, CA admin, CA operations, PKI operations

Manage revoke certificate

Allows revocation of end-entity certificates.

CA admin, CA operations, PKI operations, PKI validation, PKI compliance

Important

The account-level Read only role grants three of these permissions — Manage recover escrow key, Manage CA escrow recovery, and Manage HSM management — despite its name. Do not treat it as a safe default for auditors or support staff without reviewing the full role definition.