Understand critical roles and permissions
Access in DigiCert® Trust Lifecycle Manager is determined by:
The permissions granted by the user's role.
The access scope where those permissions apply.
Access scopes
Scope | Meaning |
|---|---|
| Highest scope Applies across the entire deployment. Reserved for customer-hosted system administration. |
| Applies to all data within a single account. |
| Applies only to the business units the user is assigned to. |
| Lowest scope Self-service portal users acting on their own certificates. Blocked from administrative operations. |
Account roles
Assign these roles to standard and service users. Choose the most restrictive role that provides the access required for their responsibilities.
Role | Grants | Sensitivity |
|---|---|---|
Manager | Set up the account and manage day-to-day operations.
| Highest Effectively full account control. Restrict tightly. |
User and certificate manager | Manage seats, enrollments, certificates, and reports. Read-only on profiles, templates, business units, and connectors. | High Can issue and revoke certificates. |
Certificate profile manager | Create and manage certificate profiles and templates. | High Controls the algorithms used for issuance and directly affects FIPS posture. |
Recovery manager | Recover escrowed certificates and keys. | Highest Grants access to private key material. |
Import manager | Import certificates from external CAs. | Moderate Can introduce externally issued trust into the inventory. |
Infrastructure admin | View and manage client tools. | Moderate |
Reporting admin | View and manage reports. | Moderate Reports can contain inventory detail. |
Certificate owners manager | View and manage certificate owners only. | Low |
SSP manager | Configure the self-service portal only. | Moderate Controls what end users may do. |
Custom attribute manager | View and manage custom attributes only. | Low |
CMDB Integration Config Manager | Add and manage ServiceNow CMDB connectors only. | Moderate |
View only | Read-only access to account data. | Low Preferred default for auditors and observers. |
System roles for customer-hosted environments
Role | Grants | Sensitivity |
|---|---|---|
TLM admin | Superadmin for managing Trust Lifecycle Manager users, accounts, and workflows across the deployment. | Highest Grant to the minimum number of named individuals and review every cycle. |
Technical support | Read-only access to account data for support purposes, including audit logs. | Moderate Grant only for the duration of an active support engagement. |
Read only | Read-only access to user and account setup data, including audit logs. | Low |
Permissions to restrict most tightly
Regardless of which role carries them, treat the following permissions as privileged. Apply least-privilege review, separation of duties, and periodic recertification to these permissions.
Permission | Why it is sensitive |
|---|---|
| Grants recovery of escrowed private keys. This is the most sensitive permission in the product. |
| Controls key algorithms, key sizes, and signature algorithms used for issuance. These settings directly affect your FIPS posture. |
| Allows issuance of new certificates. |
| Allows revocation, which can cause outages if misused. |
| Allows suspension and reinstatement of trust. |
| Allows external certificates to enter the managed inventory. |
| Establishes trust relationships with external CAs and cloud services. |
| Allows automated actions against managed endpoints. |
| Changes tenant boundaries and can widen a user's effective data access. |
| Controls which operations end users may perform on their own certificates. |
| Audit records may contain sensitive operational detail. |