The Cryptographic Security Platform Vault for KMIP supports Role-based Access Control (RBAC) Policies. Access to KMIP objects is denied by default, and must be explicitly granted through Access Control Policies.

Roles

Roles define actions or operations that can be performed on the KMIP Cryptographic Security Platform Vault for KMIP and KMIP objects. The following pre-defined roles are supported: 

  • KMIP Administrators have full access to all aspects of the Cryptographic Security Platform Vault for KMIP. This access includes:

    • KMIP objects—Can view and perform actions on KMIP objects.
    • Client certificates—Can create and manage KMIP client certificates that will be used by KMIP clients to create or access the KMIP objects.
    • Policy management—Can create role-based access control policies to allow users or applications the ability to access the Cryptographic Security Platform Vault for KMIP webGUI.
    • Audit logs—Can view audit logs.
    • Settings—Can view and modify Active Directory, KEK wrapping, and other settings.
  • Audit Administrators have minimal access and can only view audit logs.

Policies

KMIP Administrators can create and manage access control policies that manage access to the KMIP objects. Policies consist of the following: 

  • Security principle—The list of users and groups governed by this policy. This can be an individual Local User, AD user or a group.

  • Security principle—The list of users and groups governed by this policy. This can be an individual AD user or a group.
  • Role—The permissions or a list of actions and operations that are granted to the user. The role can be KMIP Administrator or Audit Administrator.

Default Admin Policy

Cryptographic Security Platform Vault creates a default admin policy that grants the KMIP administrator role to the Local User, AD user or group that is set as the first KMIP administrator. This policy can be edited to add and remove AD groups or users but cannot be deleted.