Skip to main content
fortiFWuser
Explorer III
April 6, 2022
Question

Read only admin account and certificates

  • April 6, 2022
  • 8 replies
  • 7378 views

Hello,

 

I have a 101F with 7.0.2 and I created an account with super_admin_readonly 

Should he be able to see the "Certificates" under system?

 

Thanks and regards, 

Konstantinos

8 replies

sharmaj
Staff
Staff
April 6, 2022

Hi Konstantinos

Yes, he should be able to see the certificates under the system, but can not delete them.

fortiFWuser
Explorer III
April 6, 2022

Hmm 
Ok, but the menu is not showed. 

Also I created a test account with the same profile and it was not showed also. 

sharmaj
Staff
Staff
April 6, 2022

Hi

Just to confirm, are you using a customized super admin read-only profile?

 

Also, I hope for the general super admin users, the certificates are visible, if not, you need to enable feature visibility

fortiFWuser
Explorer III
April 6, 2022

Hi Jay, 

 

I use the custom profile super_admin_readonly

The other admin profiles(super admin) see the certs

sharmaj
Staff
Staff
April 6, 2022

Hi

Try to use default super_admin_readonly and see if it behaves the same.

fortiFWuser
Explorer III
April 6, 2022

Sorry I mistyped

I use the default. But I made a custom one and it is the same. 

sharmaj
Staff
Staff
April 6, 2022

What is the firmware version used?

fortiFWuser
Explorer III
April 6, 2022

It is 7.0.2 build 0234

sharmaj
Staff
Staff
April 6, 2022

What are the options user can see?

if not certificates under the system

fortiFWuser
Explorer III
April 6, 2022

fortiFWuser_0-1649247099532.png

 

fortiFWuser
Explorer III
April 7, 2022

Any ideas why it is not showed?

sharmaj
Staff
Staff
April 7, 2022

Hi

I recommend you open a TAC ticket regarding this, might be something as the lab setup is working just fine.

xsilver_FTNT
Staff
Staff
April 26, 2022

Hi fortiFWuser,

if GUI feature to show certificates is enabled, then even Read-Only admin should at least see certificates and their section under System menu.

Inability to see those when logged as read-only admin was internally discovered and is known issue.