Role-Based Access Control (RBAC) allows you to assign permissions through roles instead of granting access directly to users. Users and Active Directory (AD) groups can be assigned one or more roles, and the permissions associated with those roles determine the actions they can perform. When upgrading to Release 10.6.1 from an earlier release, existing users are automatically migrated to the RBAC model. Existing access levels are preserved during migration.

The introduction of RBAC to Compliance Manager is being implemented in phases. Release 10.6.1 includes Phase 1, which applies only to Vault appliance users. Vault users for all types of vaults are currently unchanged.


This page provides information on the following topics:


Viewing Assigned Roles

  1. Log in to the Cryptographic Security Platform Vault Management webGUI.
  2. In the top right, click Switch to Appliance Management.
  3. In the Account Settings section, view the Assigned Roles field to see the roles assigned to you. 

    The Account Settings section displays a read-only list of the roles assigned to your user account.

     

Viewing Available Roles

  1. Log in to the Cryptographic Security Platform Vault Management webGUI.
  2. In the top right, click Switch to Appliance Management.
  3. From the top menu, select Users.
  4. Select the Roles tab. A list of roles and their descriptions appear.

    The Roles tab is a read-only view that lists the available roles and the operations each role can perform.


Assigning Roles to a New User

When creating a user, you can assign roles during user creation. The selected roles determine the permissions available to the new user. Complete the steps below to assign roles to a new user.

  1. Log in to the Cryptographic Security Platform Vault Management webGUI.
  2. In the top right, click Switch to Appliance Management.
  3. From the top menu, select Users.
  4. From the Actions dropdown list, select Add User. The Add a New User dialog box appears.
  5. Select the User tab and complete the following fields:
    1. Full Name: Enter the full name of the user.
    2. Email: Enter the email address of the user.
  6. Click Next. The system takes you to the Roles tab.

    An alternative is to select the Roles tab.

  7. Select the role to assign to the user based on your requirements.

    You can select one or more roles for each user that you created.

  8. Click Add. A User Successfully Added dialog box appears.
  9. Click Close.


Assigning Roles to an AD Group

  1. Log in to the Cryptographic Security Platform Vault Management webGUI.
  2. In the top right, click Switch to Appliance Management.
  3. From the top menu, select Users. 
  4. Select the AD Groups tab.
  5. From the Actions dropdown list, select Add AD Group. The Add AD Group dialog box appears.
  6. Select the Group tab. 
  7. In the AD Group field, enter an AD group name based on your requirements.
  8. Click Next. The system takes you to the Roles tab.

    An alternative is to select the Roles tab.

  9. Select the role to assign to the group based on your requirements.

    You can select one or more roles for each group.

  10. Click Add. An AD Group Added Successfully message appears.


Modifying Assigned Roles

  1. Log in to the Cryptographic Security Platform Vault Management webGUI.
  2. In the top right, click Switch to Appliance Management.
  3. From the top menu, select Users. A list of users appears.
  4. Select the user whose assigned roles you want to modify.
  5. Select the Roles tab.
  6. Select or deselect roles as required.
  7. Click Apply. 

The operations available to a user are determined by the roles assigned to the user. The Roles tab displays the operations and level of access associated with the selected roles.


Role Assignment Restrictions

  • A user must already have a role to assign that role to another user.
  • The role assignments for the secroot user and the currently signed-in user cannot be modified.
  • Adding or removing permissions related to admin key management generates a new admin key.