Adding administrators
Add an administrator
-
Navigate to
. -
Click the Add icon.
-
In the Add Admin Type dialog, select Standard.
-
Click Next.
-
Complete the Add New Admin fields based on the information provided in the following table.
Field Description Username
The administrator’s username for the purpose of identification and access
Email
The administrator’s email address
Forename, Surname
The administrator’s first name (forename) and last name (surname)
Title
The administrator’s title
Telephone Number
The administrator’s phone number
Street, Locality, State/Province, Postal Code, Country
The administrator’s address details
Relationship
The nature of the administrator’s relationship with the organizations or departments that they are delegated to (such as, employee or third party)
-
Click Next.
-
Complete the Roles & Privileges tab fields.
-
Select an administrator role.
-
For RAO and DRAO administrators, select the certificate types and organizations or departments that can be managed.
-
Assign administrator privileges based on the information provided in the following table.
Field Description Allow creation of peer admin users
The administrator can create other administrators of their own level or lower
Allow editing of peer admin users
The administrator can edit other administrators of their own level or lower
Allow deleting of peer admin users
The administrator can remove other administrators of their own level or lower
Allow to manage organizations/departments
The administrator can do the following:
-
Create new organizations
-
View, edit, and delete delegated organizations
-
Create new departments under delegated organizations
-
Manage certificate settings, notification templates, access control lists, and EV details for delegated organizations
Allow DCV
The administrator can initiate domain control validation for newly created domains
Allow SSL details changing
The administrator can change SSL certificate request details prior to approval
Automatically approve certificate requests
Certificate requests initiated by the administrator are automatically approved
Allow certificate revocation
The administrator can revoke certificates
MS AD Discovery
The MRAO administrator can access the
page, download and install MS Agents, and view the certificates and web servers discovered by MS Agents by scanning respective AD serversAllow download keys from Key Vault
The administrator can download certificate private keys stored in Sectigo Key Vault
Approve domain delegation
The administrator can approve domain delegation requests by other administrators of their own level or lower
-
-
-
Complete the Authentication tab fields.
-
Enter and confirm a password for the new administrator.
-
(Optional) Select a valid client certificate for use in authentication.
-
(Optional) Configure SAML IdP by selecting an identity provider and entering the appropriate EPPN.
-
-
Click Save.
-
Navigate to
. -
Click the Add icon.
-
In the Add Admin Type dialog, select IdP Template.
-
Click Next.
-
Provide a name for the IdP template.
-
Click Next.
-
Complete the Roles & Privileges tab fields.
-
Select an administrator role.
-
For RAO and DRAO administrators, select the certificate types and organizations or departments that can be managed.
-
Assign administrator privileges based on the information provided in the following table.
Field Description Allow creation of peer admin users
The administrator can create other administrators of their own level or lower
Allow editing of peer admin users
The administrator can edit other administrators of their own level or lower
Allow deleting of peer admin users
The administrator can remove other administrators of their own level or lower
Allow to manage organizations/departments
The administrator can do the following:
-
Create new organizations
-
View, edit, and delete delegated organizations
-
Create new departments under delegated organizations
-
Manage certificate settings, notification templates, access control lists, and EV details for delegated organizations
Allow DCV
The administrator can initiate domain control validation for newly created domains
Allow SSL details changing
The administrator can change SSL certificate request details prior to approval
Automatically approve certificate requests
Certificate requests initiated by the administrator are automatically approved
Allow certificate revocation
The administrator can revoke certificates
MS AD Discovery
The administrator can access the
page, download and install MS Agents, and view the certificates and web servers discovered by MS Agents by scanning respective AD serversAllow download keys from Key Vault
The administrator can download certificate private keys stored in Sectigo Key Vault
Approve domain delegation
The administrator can approve domain delegation requests by other administrators of their own level or lower
-
-
-
Complete the Authentication tab fields.
-
Select an identity provider for SAML IdP.
-
Configure IdP Attribute mapping based on the information provided in the following table.
Field Description cn
The user’s full name or common name
displayname
A human-readable display name for the user
entitlement
Information about the user’s access rights or permissions
eppn
A unique identifier for individuals within education and research institutions, often resembling an email address
givenname
The user’s first name
groups
Information about the user’s group memberships or affiliations
mail
The user’s email address
schachomeorganization
The user’s organization identifier
sn
The user’s last name or surname
uid
A unique identifier for the user within an organization or system
-
-
Click Save.
-
Navigate to
. -
Click the Add icon.
-
In the Add Admin Type dialog, select IdP.
-
Click Next.
-
Complete the Add New Admin fields based on the information provided in the following table.
Field Description Email
The administrator’s email address
Forename, Surname
The administrator’s first name (forename) and last name (surname)
Title
The administrator’s title
Telephone Number
The administrator’s phone number
Street, Locality, State/Province, Postal Code, Country
The administrator’s address details
Relationship
The nature of the administrator’s relationship with the organizations or departments that they are delegated to (such as, employee or third party)
-
Click Next.
-
Complete the Roles & Privileges tab fields.
-
Select an administrator role.
-
For RAO and DRAO administrators, select the certificate types and organizations or departments that can be managed.
-
Assign administrator privileges based on the information provided in the following table.
Field Description Allow creation of peer admin users
The administrator can create other administrators of their own level or lower
Allow editing of peer admin users
The administrator can edit other administrators of their own level or lower
Allow deleting of peer admin users
The administrator can remove other administrators of their own level or lower
Allow to manage organizations/departments
The administrator can do the following:
-
Create new organizations
-
View, edit, and delete delegated organizations
-
Create new departments under delegated organizations
-
Manage certificate settings, notification templates, access control lists, and EV details for delegated organizations
Allow DCV
The administrator can initiate domain control validation for newly created domains
Allow SSL details changing
The administrator can change SSL certificate request details prior to approval
Automatically approve certificate requests
Certificate requests initiated by the administrator are automatically approved
Allow certificate revocation
The administrator can revoke certificates
MS AD Discovery
The administrator can access the
page, download and install MS Agents, and view the certificates and web servers discovered by MS Agents by scanning respective AD serversAllow download keys from Key Vault
The administrator can download certificate private keys stored in Sectigo Key Vault
Approve domain delegation
The administrator can approve domain delegation requests by other administrators of their own level or lower
-
-
-
Click Save.
Once an IdP administrator has been added in SCM, they are sent an email with links to all configured IdPs. They should use the most appropriate IdP link to complete their registration. |
-
Navigate to
. -
Click the Add icon.
-
In the Add Admin Type dialog, select Sectigo Authentication Service.
-
Click Next.
-
Complete the Add New Admin fields based on the information provided in the following table.
Field Description Email
The administrator’s email address
Forename, Surname
The administrator’s first name (forename) and last name (surname)
Title
The administrator’s title
Telephone Number
The administrator’s phone number
Street, Locality, State/Province, Postal Code, Country
The administrator’s address details
Relationship
The nature of the administrator’s relationship with the organizations or departments that they are delegated to (such as, employee or third party)
-
Click Next.
-
Complete the Roles & Privileges tab fields.
-
Select an administrator role.
-
For RAO and DRAO administrators, select the certificate types and organizations or departments that can be managed.
-
Assign administrator privileges based on the information provided in the following table.
Field Description Allow creation of peer admin users
The administrator can create other administrators of their own level or lower
Allow editing of peer admin users
The administrator can edit other administrators of their own level or lower
Allow deleting of peer admin users
The administrator can remove other administrators of their own level or lower
Allow to manage organizations/departments
The administrator can do the following:
-
Create new organizations
-
View, edit, and delete delegated organizations
-
Create new departments under delegated organizations
-
Manage certificate settings, notification templates, access control lists, and EV details for delegated organizations
Allow DCV
The administrator can initiate domain control validation for newly created domains
Allow SSL details changing
The administrator can change SSL certificate request details prior to approval
Automatically approve certificate requests
Certificate requests initiated by the administrator are automatically approved
Allow certificate revocation
The administrator can revoke certificates
MS AD Discovery
The administrator can access the
page, download and install MS Agents, and view the certificates and web servers discovered by MS Agents by scanning respective AD serversAllow download keys from Key Vault
The administrator can download certificate private keys stored in Sectigo Key Vault
Approve domain delegation
The administrator can approve domain delegation requests by other administrators of their own level or lower
-
-
-
Click Save.
Once created in SCM, the administrator can access SCM using a Sectigo Authentication Service account with the same email address. This account can be created from the SCM login page. |
-
Navigate to
. -
Click the Add icon.
-
In the Add Admin Type dialog, select API.
-
Click Next.
-
Complete the Add New Admin fields based on the information provided in the following table.
Field Description Username
The administrator’s username for the purpose of identification and access
Email
The administrator’s email address
Forename, Surname
The administrator’s first name (forename) and last name (surname)
Title
The administrator’s title
Telephone Number
The administrator’s phone number
Street, Locality, State/Province, Postal Code, Country
The administrator’s address details
Relationship
The nature of the administrator’s relationship with the organizations or departments that they are delegated to (such as, employee or third party)
-
Click Next.
-
Complete the Roles & Privileges tab fields.
-
Select an administrator role.
-
For RAO and DRAO administrators, select the certificate types and organizations or departments that can be managed.
-
Assign administrator privileges based on the information provided in the following table.
Field Description Allow creation of peer admin users
The administrator can create other administrators of their own level or lower
Allow editing of peer admin users
The administrator can edit other administrators of their own level or lower
Allow deleting of peer admin users
The administrator can remove other administrators of their own level or lower
Allow to manage organizations/departments
The administrator can do the following:
-
Create new organizations
-
View, edit, and delete delegated organizations
-
Create new departments under delegated organizations
-
Manage certificate settings, notification templates, access control lists, and EV details for delegated organizations
Allow DCV
The administrator can initiate domain control validation for newly created domains
Allow SSL details changing
The administrator can change SSL certificate request details prior to approval
Automatically approve certificate requests
Certificate requests initiated by the administrator are automatically approved
Allow certificate revocation
The administrator can revoke certificates
MS AD Discovery
The administrator can access the
page, download and install MS Agents, and view the certificates and web servers discovered by MS Agents by scanning respective AD serversAllow download keys from Key Vault
The administrator can download certificate private keys stored in Sectigo Key Vault
Approve domain delegation
The administrator can approve domain delegation requests by other administrators of their own level or lower
-
-
-
Complete the Authentication tab fields.
-
Enter and confirm a password for the new administrator.
-
(Optional) Select a valid client certificate for use in authentication.
-
-
Click Save.