User Guide

364 Chapter 8 Managing system users and groups
320818-A
9 Remove the admin user from the certadmin group.
Again, this step is only necessary if you want to fully separate the Certificate
Administrator user role from the Administrator user role. Note however, that
once the admin user is removed from the certadmin group, only a user who is
already a member of the certadmin group can grant the admin user certadmin
group membership anew.
When the admin user is removed from the certadmin group, only the
Certificate Administrator user can access the Certificate menu (
/cfg/cert).
10 Verify and apply the changes.
>> User# edit admin
>> User admin# groups/list
1: admin
2: oper
3: certadmin
>> Groups# del 3
Note: It is critical that a Certificate Administrator user is created and
assigned certadmin group membership before the admin user is removed
from the certadmin group. Otherwise there is no way to assign certadmin
group membership to a new user, or to restore certadmin group
membership to the admin user, should it become necessary.
>> Groups# list
Old:
1: admin
2: oper
3: certadmin
Pending:
1: admin
2: oper
>> Groups# apply