Question

Ministerio
ES
Last activity: 14 Apr 2025 3:16 EDT
setting Data-Admin-Security-Keystore class access controls to 0 doesn't change anything
I'm trying to create an Accesss Group with SecurityAdministrator privileges except the access to the keystores.
Steps to reproduce the problem:
- Create a new Access Role based on the existing SecurityAdministrator. Let's call it "SANoKey."
- Edit this Access Role and add the class
Data-Admin-Security-Keystore
with all Access Controls set to 0. - Create an Access Group with the SecurityAdministrator role and replace it with the new one (SANoKey).
-
This new Access Group shouldn't be able to edit or delete any instance of
Data-Admin-Security-Keystore
, but that's not true. It can still access Records > Security > Keystore and edit everything there.
I've tried deleting the dependent role of the Access Role and cloning it to avoid conflicts, but it still doesn't work.
I've even tried deleting the SecurityAdministrator Access Role instead of replacing it. However, even when the security interface disappears, the Keystore can still be accessed through the search function in the upper right section. This Access Group only has the SysAdm4 Access Role.