SuperAdmin Role
Administrator Role
Introduction
EJBCA Roles - Create Training Superadmin role
Slide Deck: EJBCA Roles
Overview: This section creates the "training superadmin" role, and adds this user to the existing superadmin role.
Slide Reference

Create a certificate for the role

User is granted access based on role membership

Permission matrix by role
Reminder you can visit the Accessing Your Environment page for details on how to connect to your RA web portal
Create the SuperAdmin Certificate
Open a browser and click RA Web, from the ribbon menu across the top of page
Click Enroll >> Make New Request
In the Certificate Type drop-down list, select AdministratorEndEntityProfile
In the Key-pair generation selection, select By the CA
In the CN, Common name field, enter training_SuperAdmin
In the Username field, enter training_SuperAdmin
In the Enrollment code field, enter foo123
In the Confirm enrollment code field, enter foo123
Click Download PKCS#12
Save the file and import it in the browser (see below for a refresher)
Create the Matching Rule
Open a browser and access your Admin Web Portal
Click System Functions >> Roles and Access Rules
On Super Administrator Role click Members
In the Match With list, select X509: CN, Common name
In the CA list, select ManagementCA
In the Match value field, enter training_SuperAdmin
Click Add
Click Back to Roles Management
Refresher on importing certificates into Firefox

Import certificate using FF preferences option(s)
Open a new tab in Firefox, and locate the settings using one of the following:
on the address line type about:preferences,
OR
select from the 3 horizontal lines (a.k.a the burger menu) located on the right hand side of the Firefox browser (shown below).
Click on Privacy & Security
Scroll down and click on View Certificates...
Click on Your Certificates tab
Click on Import...
Locate your p12 Firefox will place them in the Downloads folder, select this folder
Select the training_SuperAdmin.p12 file to import into Firefox, click Select
Type the training_SuperAdmin password foo123, click Sign in
Click OK, to close the certificate manager window
Close the about:preferences tab

Or use the Burger menu to import certificates