Using roles for access management in Venafi Configuration Console
When an identity accesses applications through the API, what they can do is determined by the role that is assigned to their identity.
The following table lists the roles used for access management, and what rights they have.
Role | Access details |
---|---|
User |
|
Auditor |
|
Application Maintainer |
|
Application Owner |
|
Mixed Owner/Maintainer |
|
Grant Admin |
|
Admin |
|
Assign a role to an identity
-
Connect to the Venafi Configuration Console on the Venafi server, or use the Venafi Access Management MMC snap-in to connect to the server you want to manage.
-
From the Venafi Access Management node, click Roles.
-
In the Actions panel, click Assign....
-
Select the role you want to assign.
-
In the To: field, locate the user or group to be assigned the specified role.
-
[Conditional] If the new role is
Application Maintainer
orApplication Owner
, select which application this role applies to. -
Click OK.
Revoke a role from an identity
-
Connect to the Venafi Configuration Console on the Venafi server, or use the Venafi Access Management MMC snap-in to connect to the server you want to manage.
-
From the Venafi Access Management node, click Roles.
-
Locate the role you want to revoke.
-
In the Actions panel, click Revoke....
-
[Conditional] If a confirmation modal appears, click Yes.