/usr/share/pki/ca/conf/acl.properties is in pki-ca 10.6.0-1ubuntu2.
This file is owned by root:root, with mode 0o644.
The actual contents of the file can be viewed below.
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 | # ACL mapping
#
# Format:
# <mapping name> = <resource ID>,<operation>
# Example:
# users = certServer.ca.users,execute
account.login = certServer.ca.account,login
account.logout = certServer.ca.account,logout
# audit configuration
audit.read = certServer.log.configuration,read
audit.modify = certServer.log.configuration,modify
# audit logs
audit-log.read = certServer.log.content.signedAudit,read
certs = certServer.ca.certs,execute
certrequests = certServer.ca.certrequests,execute
groups = certServer.ca.groups,execute
kraconnectors = certServer.ca.connectorInfo,modify
profiles.approve = certServer.ca.profile,approve
profiles.create = certServer.profile.configuration,modify
profiles.delete = certServer.profile.configuration,modify
profiles.list = certServer.ee.profiles,list
profiles.modify = certServer.profile.configuration,modify
profiles.read = certServer.profile.configuration,read
securityDomain.installToken = certServer.securitydomain.domainxml,read
selftests.read = certServer.ca.selftests,read
selftests.execute = certServer.ca.selftests,execute
users = certServer.ca.users,execute
authorities.create = certServer.ca.authorities,create
authorities.list = certServer.ca.authorities,list
authorities.modify = certServer.ca.authorities,modify
authorities.read = certServer.ca.authorities,read
authorities.delete = certServer.ca.authorities,delete
|