ACL ReferenceChapter 8 Authorization 365OperationsDefault ACIsallow (read) group="Administrators" || group="Auditors" ||group=”Certificate Manager Agents” || group=”Registration ManagerAgents” || group=”Data Recovery Manager Agents” || group=”OnlineCertificate Status Manager Agents”allow (modify) group="Administrators"Administrators, auditors, and agents are allowed to read CMS generalconfiguration; only administrators are allowed to modify CMS generalconfiguration.certServer.job.configurationAllow or deny a read or modify operation to the jobs configuration.OperationsDefault ACIsallow (read) group="Administrators" || group=”Certificate ManagerAgents” || group=”Registration Manager Agents” || group=”DataRecovery Manager Agents” || group=”Online Certificate Status ManagerAgents” || group="Auditors"read Viewing operating environment, LDAP configuration, SMTPconfiguration, server statistics, encryption, token names, subjectname of certificates, certificate nicknames, all subsystems that havebeen loaded by the server, get CA certificates, and get allcertificates for management.modify Modifying LDAP database configuration, SMTP configuration, andencryption. Performing server stop/start/restart operations.Issuing import certificate, trusting/untrusting CA certificate,importing cross-certification certificate, installing certificates, anddeleting certificates. Logging all tokens and checking token status.Running self tests on demand. Getting certificate information.Processing certificate subject name. Validating certificate subjectname, certificate key length, and certificate extension.read Viewing basic job settings, job instance settings, and job plug-insettings. Listing job plug-ins and job instances.modify Adding and deleting job plug-ins and job instances. Modifying jobplug-ins and job instances.