ユーザーのロールと権限
DigiCert® Device Trust Manager は、ロールベースのアクセス制御(RBAC)を使用して、ユーザーがプラットフォーム内で各自の責任に応じた適切な権限を持つことを保証します。このモデルは、ユーザーに割り当てられたロールに基づいてアクセスを制限または許可し、IoT デバイスを管理するための安全で組織的な構造を可能にします。
ロールの割り当ては、アカウント管理によって DigiCert® Account Manager で管理されます。ユーザーの作成と管理の詳細については、Account Manager のドキュメントを参照してください。
An account administrator is responsible for adding users and assigning roles in Device Trust Manager. Below is a quick breakdown of each role to help you understand each one and best practices for assigning them:
Solution Administrator: This is the primary administrator role for Device Trust Manager, with full access to all permissions. Assign this role carefully, as users in this position have the ability to perform any action within Device Trust Manager.
Device Creator: This role is intended for users responsible for registering devices individually or in bulk. It is commonly assigned to production managers or staff at manufacturing facilities where devices are initialized and registered.
Device Administrator: Assigned to users who need control over device lifecycle management, including enabling, disabling, deleting, and restoring devices. This role is often designated to users involved in ongoing device operations and support.
Artifact Manager: Artifact Managers are typically firmware developers or software engineers who create and upload device update packages. They handle the software artifacts that are deployed to devices, making this role essential for maintaining and updating device functionality.
注記
The Solution Administrator and Account Administrator roles are typically held by two different individuals. An Account Administrator, usually from IT, IT Security, or PKI Ops, administers DigiCert ONE and controls access to the various management applications, including Device Trust Manager. The Solution Administrator, however, is more likely to be part of the product or operational team responsible for managing devices.
次の表は、Device Trust Manager における各ロールに対応する権限の詳細な内訳です。
ソリューション管理者 | デバイス作成者 | デバイス管理者 | アーティファクトマネージャー | |
|---|---|---|---|---|
全般的な権限 | ||||
ダッシュボード | 表示/編集 | 表示/編集 | 表示/編集 | 表示/編集 |
ディビジョン | 表示/編集 | 表示 | 表示 | 表示 |
通知 | 表示/編集 | 表示/編集 | 表示/編集 | 表示/編集 |
ライセンス | 表示 | - | - | - |
システムログ | 表示 | 表示 | 表示 | 表示 |
証明書管理の権限 | ||||
認証 CA | 表示/編集 | - | - | - |
CA コネクター | 表示/編集 | - | - | - |
証明書管理ポリシー | 表示/編集 | 表示 | 表示 | - |
証明書プロファイル | 表示/編集 | 表示 | 表示 | - |
証明書テンプレート | 表示 | 表示 | 表示 | - |
証明書の更新 | 表示/編集 | - | 表示/編集 | - |
証明書リクエスト | 表示/編集 | 表示/編集 | 表示/編集 | - |
証明書の失効 | 表示/編集 | - | 表示/編集 | - |
OCSP グループ | 表示/編集 | - | - | - |
デバイス管理の権限 | ||||
デバイス | 表示/編集 | 表示 | 表示/編集 | - |
ブートストラップ設定のダウンロード | 表示/編集 | 表示/編集 | 表示/編集 | - |
証明書のダウンロード | 表示/編集 | 表示/編集 | 表示/編集 | - |
多数のデバイスの登録 | 表示/編集 | 表示/編集 | - | - |
単一デバイスの登録 | 表示/編集 | 表示/編集 | - | - |
デバイスグループ | 表示/編集 | 表示 | 表示 | - |
クラウドプラットフォームポリシー | 表示/編集 | 表示 | 表示 | - |
ソフトウェアアップデートの権限 | ||||
アーティファクト | 表示/編集 | 表示 | 表示 | 表示/編集 |
リリース | 表示/編集 | 表示 | 表示 | 表示 |
デプロイメント | 表示/編集 | 表示 | 表示 | 表示 |
ジョブの権限 | ||||
バッチ証明書発行ジョブ | 表示/編集 | - | 表示/編集 | - |
バッチデバイス登録ジョブ | 表示/編集 | 表示/編集 | - | - |
デプロイメントジョブ | 表示/編集 | - | - | - |
DigiCert® ゲートウェイ管理 | ||||
DigiCert® ゲートウェイ | 表示/編集 | 表示 | 表示 | - |
Device Trust Manager のロールにユーザーを割り当てる処理は、アカウント管理者権限の所有者が 1.923.0 を通じて実行します。
アカウント管理者として DigiCert® ONE にサインインします。
In the Managers () menu, select Account.
[アクセス]>[ユーザー]を選択します。
[ユーザーの追加]をクリックし、必要なユーザーの詳細を指定します。
[DigiCert ONE Manager へのアクセス]で、[Device Trust]を選択します。
[Device Trust Manager]ドロップダウンで、ユーザーに適したロールを選択します。たとえば、[ソリューション管理者]などです。