EJBCA provides default Role Templates designed to cover most use cases and be easily extendable. If none of these fit your needs, you can create a custom role using the Custom template and manually configure the role in Advanced Mode.
For a full list of access rules, see Access Rules.
    
        
                    
                                    
                                    
                            
            
            | Role Template Name | Rights | 
    
            | Super Administrator | Has overall access to EJBCACan edit system configurationCan manage CAsCan manage publishers (LDAP, AD, custom)Can create CA administrators
 | 
    
            | CA Administrator | manages certificate profilesmanages end entity profilesmanages log configurationmanages publishersmanages key validatorscan create RA administratorscan renew a CA using an existing keycan have full read access to the audit log
 
                            
                
CA Administrators are not authorized to generate new keys, only renew using existing ones. 
 | 
    
            | RA Administrator |  | 
    
            | Supervisor |  | 
    
            | Auditor | has full read access to the Audit Loghas full read access to authorized CAshas full read access to authorized Certificate Profileshas full read access to Crypto Tokens and keyshas full read access to authorized Publishershas full read access to authorized End Entitieshas full read access to authorized End Entity Profileshas full read access to authorized Key Validatorshas limited read access to Roles and Access Ruleshas full read access to Internal Key Bindingshas full read access to Peer Systemshas full read access to Serviceshas full read access to SCEP aliases and authorized CMP aliaseshas full read access to all system configuration
 |