Critical Private CA roles and permissions
Assign Private CA roles to standard users and service users in Account Manager. Evaluate Account Manager access and Private CA access separately.
See DigiCert Private CA user roles for the complete permission list for each role.
Account roles for standard and service users
These are user roles in DigiCert-hosted DigiCert ONE environments.
Action | Recommended role | Security implication |
|---|---|---|
Request and authorize key escrow and CA recovery, with read access to managed CAs | PKI manager | Includes Manage CA, Manage revoke CA, Manage OCSP responder, Manage CA escrow recovery, Manage recover escrow key, Manage HSM management, and Manage templates. This role can revoke a CA and recover escrowed keys. Restrict to authorized PKI administrators. |
Escrow and recover end-entity keys | Key escrow | Includes Manage recover escrow key and Manage CA escrow recovery. Grants access to protected key material. Restrict tightly and review every recovery event. |
Review CA and certificate information without making changes | Read only | Read access to CAs, certificates, AIAs, domains, OCSP responders, templates, and audit logs. Note this role also includes Manage CA escrow recovery, Manage HSM management, and Manage recover escrow key. Review the complete role definition before assuming it is read-only in every respect. |
System roles for customer-hosted environments
These are user roles in customer-hosted DigiCert ONE environments.
Action | Recommended role | Security implication |
|---|---|---|
Configure the deployment, manage CAs and HSMs, and approve escrow recovery | CA admin | Broadest administrative role. Includes Manage CA, Manage revoke CA, Manage escrow master keys, Manage import certificate, Manage default configurations, and Manage HSM management. User can change the trust hierarchy and revoke a CA, invalidating every certificate it issued. |
Create and manage CAs, CRLs, and OCSP responders in daily operations | CA operations | Same CA and certificate permissions as CA admin, including Manage revoke CA and Manage escrow master keys. Assign only to users with an approved operational need. |
Manage and review offline CA requests and key pools | PKI operations | Includes CA management and ceremony permissions but not HSM management. |
Review and approve the validation section of offline CA requests | PKI validation | Includes CA management and the ceremony validation approval step. Separate this role from PKI compliance to maintain separation of duties in key ceremonies. |
Review and approve the compliance section of offline CA requests | PKI compliance | Includes CA management and the ceremony compliance approval step. Separate this role from PKI validation. |
Support and audit access without configuration rights | Read only | View access to CAs, certificates, escrow master keys, OCSP responders, templates, ceremony requests, key pools, default configurations, HSM management, and audit logs. |
Perform only certificate requests through an integration | Service user | User representing an integrated client. Assign only the permissions the integration requires. Unnecessary administrative permissions increase the impact of a compromised credential. |
Review every default role and its permissions before assigning it. Several Private CA roles include permissions beyond what the role name suggests. For example, both Read only roles include escrow-related permissions.
If one role does not meet the business requirement, assign multiple roles or create a custom user role containing only the required permissions. When you assign multiple roles, the user receives their combined permissions. Review the resulting effective access before saving the change.
Permissions to restrict most tightly
Use this table during access reviews. For each permission, the third column lists every default role that grants it. Follow the links to confirm the full permission set before assigning or removing a role.
Permission | Why it matters | Granted by these default roles |
|---|---|---|
Manage revoke CA | Revoking a CA invalidates every certificate it issued and cannot be undone. | PKI manager, CA admin, CA operations, PKI operations, PKI validation, PKI compliance |
Manage escrow master keys | Create and recover an escrowed CA key. | CA admin, CA operations, PKI operations, PKI validation, PKI compliance |
Manage recover escrow key | Escrow and recover end-entity keys and certificates. | PKI manager, Key escrow, Read only — account |
Manage CA escrow recovery | Escrow CAs and recover them. | PKI manager, Key escrow, Read only — account |
Manage HSM management | Controls where CA keys are generated and stored. | PKI manager, Key escrow, Read only — account, CA admin, CA operations |
Manage import certificate | Allows external roots and ICAs to be introduced into the trust hierarchy. | CA admin, CA operations, PKI operations, PKI validation, PKI compliance |
Manage default configurations | Changes CRL and OCSP issuing behavior for Roots and ICAs. | CA admin, CA operations, PKI operations, PKI validation, PKI compliance |
Manage templates | Changes what certificates may be issued, including validity and key requirements. | PKI manager, CA admin, CA operations, PKI operations |
Manage revoke certificate | Allows revocation of end-entity certificates. | CA admin, CA operations, PKI operations, PKI validation, PKI compliance |
Important
The account-level Read only role grants three of these permissions — Manage recover escrow key, Manage CA escrow recovery, and Manage HSM management — despite its name. Do not treat it as a safe default for auditors or support staff without reviewing the full role definition.