Primeur Online Docs
Data Mover 1.20
Data Mover 1.20
  • 🚀GETTING STARTED
    • What is Primeur Data Mover
    • Main features of Primeur Data Mover
    • Primeur Data Mover deployment
    • Navigate through Primeur Data Mover
  • 👥Actors
    • Who are the actors
    • Create your first actor
    • Configure an actor 🚀
      • Users Tab
      • Groups Tab
      • VFS Tab
      • File Resource Tab
      • Connection Contract Tab
      • Client Connections Tab
    • Search files by actor
    • Actor Lineage 🚀
      • Aggregation of flows by protocol 🚀
      • Lineage with connection contracts 🚀
      • Lineage with input, mediation and output contracts 🚀
      • Lineage with any contract type 🚀
  • 🗄️VIRTUAL FILE SYSTEMS
    • Virtual File Systems (VFS) 🚀
      • Creating a VFS 🚀
      • Configuring a VFS
      • Adding Virtual Paths
      • Modifying and Deleting a VFS
    • Searching files in all VFS
    • Storage Classes 🚀
      • Storage Class: SMB v3 or later versions 🚀
      • Storage Class: Azure Blob Storage 🚀
      • Storage Class: Amazon S3 🚀
      • Storage Class: Google Storage 🚀
      • Storage Class: Local File System 🚀
    • Retention Classes
  • 📝Contracts
    • What is a contract
    • Create your first contract
      • Create an Input Contract
        • Define the contract info
        • Associate the contract with the actor
        • Define the contract actions
        • Set the contract variables
      • Create a Mediation Contract
      • Create an Output Contract
      • Create a Connection Contract
        • Create a contract clause
        • Associate the VFS with file processing rules
        • File Processing Rules
    • Managing contracts 🚀
    • File Resources
      • Creating File Resources
      • Navigating File Resources
      • How to use File Resources
  • 🧱Workflows
    • What is a workflow
    • Create your first workflow template
    • Trigger types
      • Trigger types for input contracts
      • Trigger types for mediation and output contracts
    • Service tasks
      • Standard service tasks
      • Triggerable service tasks 🚀
      • Spazio selectors and filebox metadata management
      • Error management
    • Variables
      • Variables in workflows and contracts
      • Handling process variables
    • Workflow templates
      • System workflow templates
        • Workflow templates for input contracts
        • Workflow templates for mediation contracts
        • Workflow templates for output contracts
      • Custom workflow templates
        • Workflow template toolbar
        • Workflow template Shape repository panel
        • Workflow template working area
        • Workflow template BPMN-diagram panel
      • Error workflow templates
    • Editing workflow templates
    • DataFlow Instance Context (DFIC) 🚀
  • 🧑‍⚖️FILE ROUTING
    • What is File Routing 🚀
    • Routing Rules
      • The Rules tab
      • The Categories tab
      • The Output tab
    • How to create a rule 🚀
      • Add metadata 🚀
      • Select ACTIONS
      • Select OUTPUTS
      • Policy for the selection of metadata rules
    • Configuration of the environment in Data One
      • Set up Storage Classes
      • Set up Retention Classes
      • Configure the Actor
      • Set up File Resources
    • Associate the Routing Rule with a Contract
    • Example
  • 🔓Security
    • Identity and Access Management
    • Users & Groups
      • Setting the password policy
      • Creating Internal Users 🚀
      • Creating Internal Groups
      • Creating External Users
      • Creating External Groups
    • Key Stores and Trust Stores
      • Key Store 🚀
        • Creating a Key 🚀
        • Creating a Certificate 🚀
        • Importing a Key or a Certificate
        • Creating a Symmetric key
        • Examples
      • Trust Store 🚀
        • Importing Keys 🚀
        • Importing Certificates
      • Untrusted Cache 🚀
      • Trusting Keys and Certificates
      • PGP Key Store and PGP Trust Store
        • PGP Key Store
        • Importing keys into the PGP Trust Store
    • ICAP
      • Configuring ICAP
      • Defining an ICAP rule
  • 🛸TRANSPORT PROTOCOLS AND CONNECTORS
    • Data Mover client and server roles
    • Client Connections
      • Client Connection: FTP
      • Client Connection: FTPS
      • Client Connection: SFTP
      • Client Connection: HTTP
      • Client Connection: HTTPS
      • Client Connection: PESIT
      • Client Connection: SMB v3 or later versions
      • Client Connection: POP3 or IMAP
      • Client Connection: SMTP
      • Client Connection: PR4/PR4S
      • Client Connection: PR5
      • Client Connection: PR5S
      • Client Connection: HDFS
      • Client Connection: HDFSS
      • Client Connection: Amazon S3 🚀
      • Client Connection: Google Cloud Storage
        • Credentials
      • Client Connection: Azure Blob Storage
      • Client Connection: IBM Sterling Connect:Direct
      • Appendix
    • Server Connections 🚀
      • Server Connection: FTP
      • Server Connection: FTPS
      • Server Connection: SFTP
      • Server Connection: HTTP
      • Server Connection: HTTPS
      • Server Connection: PeSIT
      • Server Connection: PR4
      • Server Connection: PR5
      • Server Connection: PR5S 🚀
      • Server Connection: IBM Sterling Connect:Direct
    • Stopping all servers in one go
  • 🎧FILE EVENT LISTENER
    • What is the File Event Listener
    • Configuring File Event Listeners
      • Setting the File Event Listener Engine
      • Defining a contract for the File Event Listener
      • Setting events to be monitored
    • RegEx Rules 🚀
    • Monitoring File Event Listeners
  • 📚INFRASTRUCTURE
    • STENG, Clusters and Servers
    • Adding a cluster and a STENG
    • Deleting a STENG
    • DMZ Gateways
    • DMZ Clusters
  • 🕒MONITORING
    • Jobs
      • Details about Jobs 🚀
      • jobman.sh CLI
    • Job Manager
    • Job Queues
      • Managing Job Queues
    • File Transfers
      • Ongoing
      • Finished
      • Reports
    • File Transfers Rules
      • Configuring Rules
  • 👑FILE MANAGER
    • What is the File Manager
    • Logging into File Manager
    • Managing the File Manager 🚀
      • The list of results
      • Creating new folders
      • Uploading files
      • Downloading files 🚀
      • Searching for files and folders
      • Deleting files 🚀
      • Bulk actions 🚀
    • File Manager and VFS
    • Customizing File Manager externals
      • The configuration-wui.json file 🚀
      • How to customize the Login window and the logo
      • How to customize the footer
      • How to configure the Upload with Metadata option
      • How to customize bulk actions 🚀
  • 💬LOGS & AUDIT
    • Logs 🚀
      • Logs options 🚀
      • Troubleshooting error analysis in Logs
    • Audit Options 🚀
      • Export audit logs 🚀
      • List of Audit entity types 🚀
      • Audit message codes 🚀
    • Log Notifiers 🚀
      • FEL message codes
  • 📩NOTIFICATION CHANNELS
    • What are Notification Channels
    • Configuring the default Email Notification Channel
    • Configuring a new Email Notification Channel
    • Trusting Certificates
    • Managing Templates
      • Data Watcher Macros
      • Contract Macros
      • ICAP Macros
      • Central Log Macros
      • Email Templates
      • Editing default templates
      • Loading a new template
  • 💻API
    • HTTP MFT Rest API
    • Job Manager APIs 🚀
    • SFTP Server sessions APIs 🚀
    • Audit Logs APIs 🚀
  • 🧐HOW TO...
    • ... use different DNS names - NEW! 🚀
    • ... configure a Cron Expression
    • ... configure an Application
    • ... customize a header
    • ... run searches in Data Watcher 🚀
    • ... use Data Shaper graphs in Data Mover contracts
    • ... modify DMCFG and deploy it
    • ... tune Data One data retention
    • ... fine tune Data Mover
  • 🗒️RELEASE NOTES
    • Data One 1.20.10
    • Data One 1.20.9
    • Data One 1.20.8
    • Data One 1.20.7
      • Data One 1.20.7.1
    • Data One 1.20.6
    • Data One 1.20.5
    • Data One 1.20.4
    • Data One 1.20.3
    • Data One 1.20.2
    • Data One 1.20.1
    • Data One 1.20.0
Powered by GitBook
On this page
  • Creating Internal Users
  • Setting Permissions
  • Editing User Attributes
  • Importing Users
  1. Security
  2. Users & Groups

Creating Internal Users 🚀

Creating Internal Users

To create an internal user, go to Setup → Users & Groups → Internal Users → New User.

In the dialog window that appears, fill in the fields in the two tabs:

  1. User Details: credentials and details of the user.

  2. Permissions: permissions granted to the user.

User Details:

Field
Description

NAME

Name of the user

SURNAME

Last name of the user

EMAIL

Email of the user

GROUPS

Group/s to which the user will belong

USERNAME (*)

Username to log into the application

PASSWORD / CONFIRM PASSWORD (*)

ENABLED / DISABLED

The user can be enabled or disabled in the system

Setting Permissions

By default, all permissions are disabled! Only Administrators can set and change permissions granted to users and groups.

Parameter
Description (Value)

AUDITLOGSVIEW 🚀

Permission to view audit logs. Users with this permission can access the audit menu and table (Can Read/Can Write)

AUDITLOGSMANAGE 🚀

Permission to modify audit configurations (Can Read/Can Write)

A3

Permission to add and/or edit users and groups (Can Read/Can Write) The user must have this permission to access Data Mover

ACTORS

Permission to add and/or edit external users and groups (Can Read/Can Write)

APPLICATION-SERVER

Permission to read and/or write the logs on the back-end (Can Read/Can Write)

B2B-REPUTATION

Permission to view the ranking of an Actor, provided by Bitsign (Can Read)

BINDGROUPTOACTOR

Permission to bind groups from IAM or LDAP (Can Read/Can Write)

BINDUSERTOACTOR

Permission to bind users from IAM or LDAP (Can Read/Can Write)

CLUSTERS

Permission to edit infrastructure details within the Company profile (Can Read/Can Write)

COMPANY

Permission to read/edit company profile (Can Read/Can Write) The user must have this permission to access Data Mover

CONFIG

Permission to edit Advanced Settings (Can Read/Can Write) The user must have this permission to access Data Mover

CONFIGURATOR

Permission to import and/or export business object configurations (back-end) (Can Read/Can Write)

CONTRACTS

Permission to add and/or edit contracts (Can Read/Can Write)

CUSTOM-ATTRIBUTES

Permission to add custom attributes to Actor (back-end) (Can Read/Can Write)

DATAWATCHER

Permission to access DATA WATCHER (Can Read/Can Write) Important Note: This permission will be automatically available in new installations and in installations of Customers migrating from previous versions of the software. The read and write DATAWATCHER Permissions will be automatically set to ON for all users belonging to the Administrators’ group. All other Users will not have automatic access to DATA WATCHER and permission will have to be granted by the Administrator manually. 🚀 Starting from TF8, new permissions have been added for Data Watcher when it is in a bundle with Data Mover. See DW* permissions below. To ensure compatibility with earlier versions of the software, the DATAWATCHER permission remains in the list and is only overwritten if at least one permission from the new list (i.e. the one starting with DW) is selected.

DMZ

Permission to edit DMZ infrastructure details (Can Read/Can Write)

DWFLOWATTRIBUTE 🚀

Permission to edit/view flow attributes (Can Read/Can Write)

DWRUNSAVEDQUERY 🚀

Permission to run a saved query (Can Read/Can Write)

DWATTRIBUTE 🚀

Permission to view/edit attributes (Can Read/Can Write)

DWMODEL 🚀

Permission to view/edit Dataflow models (Can Read/Can Write)

DWSAVEDQUERY 🚀

Permission to view/edit saved queries (Can Read/Can Write)

DWFLOW 🚀

Permission to view/edit all flow instances (Can Read/Can Write)

DWCUTOFF 🚀

Permission to view/edit Cut-Offs (Can Read/Can Write)

DWCALENDAR 🚀

Permission to view/edit Calendars (Can Read/Can Write)

DWRESUMEDATAFLOW 🚀

Permission to resume Dataflows in the Dataflow Inquiry (Can Read/Can Write)

ENVIRONMENT

The user must have this permission to access Data Mover

FILERESOURCES

Permission to add/edit File Resource profiles (Can Read/Can Write)

GBI

Permission to invoke GBI services (back-end) (Can Read)

GROUPS

Permission to edit groups (Can Read/Can Write)

IDENTITY-ACCESS-MANAGEMENT

Permission to read/edit Identity Access Management (IAM) settings (Can Read/Can Write)

INCCALLS

Permission to configure incoming calls (Can Read/Can Write)

KEYSTORE

Permission to read/write keys in the system store (Can Read/Can Write)

LOCALNODES

Permission to see the configuration for Spazio2 (Can Read/Can Write)

LOCALPROTOCOLS

Permission to edit the protocol server infrastructure details (Can Read/Can Write)

METADATA

Permission to read file metadata (Can Read)

PERMISSIONGRANT

Permission to set the permission on users/groups and VFS (ACL) (Can Read/Can Write)

REMOTEPROTOCOLS

Permission to edit the details of the remote connection to Actors (Can Read/Can Write)

SPENG

Permission to invoke the API for Steng (Can Read/Can Write)

SPENGCEMANJOBCHANGEQUEUEOP

The user can change the execution queue of a suspended or submitted Job by using the change queue command (Can Read/Can Write) Note that the change queue option in the resume and abort and resubmit actions is not affected by this permission.

SPENGCEMANJOBS

The user can access the Jobs section of Data One (Can Read/Can Write)

SPENGCEMANJOBSABORTOP

The user can execute the abort action on a Job (Can Read/Can Write)

SPENGCEMANJOBSABORTRESUBMITOP

The user can execute the abort and resubmit action on a Job (Can Read/Can Write)

SPENGCEMANJOBSRESUBMITOP

The user can execute the resubmit action on a Job (Can Read/Can Write)

SPENGCEMANJOBSRESUMEOP

The user can execute the resume action on a Job, WITHOUT changing the status of the execution queue (Can Read/Can Write)

SPENGCEMANJOBSRESUMEQUEUEOP

The user can execute the resume action on a Job and change the status of the execution queue (Can Read/Can Write)

SPENGCEMANJOBSSUSPENDOP

The user can execute the suspend action on a Job (Can Read/Can Write)

SPENGJOBQUEUES

The user can access the Job Queues section of Data One (Can Read/Can Write)

STORAGECLASS

Permission to add/edit Storage Class profiles (Can Read/Can Write)

TMPOLICIES

Permission to add and/or edit the TMPolicy (Can Read/Can Write)

TRUSTSTORE

Permission to read/write keys or certificates of trusted SSH/SSL Actors in the system store (Can Read/Can Write)

UNTRUSTEDCACHE

Permission to read/write keys or certificates of untrusted SSH/SSL Actors in the system store (Can Read/Can Write)

UPLOAD

Permission to import files (Can Read/Can Write)

UPLOADTEMPLATE

Permission to import email templates (Can Read/Can Write)

USERCLASS

Permission to add/edit Retention Class profiles (Can Read/Can Write)

USERGROUPASSIGNMENT

Permission to add user to a group (Can Read/Can Write)

USERPUBKEY

Permission to associate a user with a key in the Trust Store (Can Read/Can Write)

USERS

Permission to manage internal and external users (Can Read/Can Write)

VFS

Permission to add/edit VFS profiles (Can Read/Can Write)

VFSEXPLORER

Permission to navigate the Virtual File System (VFS) via File Search functionality (Can Read)

WHO-DOES-WHAT

AUDIT for workflow (Can Read/Can Write)

WORKFLOW

Permission to add/edit workflows (Can Read/Can Write)

You can filter Permissions by their name in the Filter Permission edit box at the top of the panel.

Once you have created the User and configured its permissions, press Create.

Editing User Attributes

On the right of the screen, clicking the three-dot icon, the following options will appear:

UNBIND FROM REPOSITORY

Select this option, the user will no longer have access to external configuration of user permissions such as LDAP and IAM. Once selected, the user will be removed from the Result list. To bind the user again, select the BIND USER button.

DISABLE

Selecting this option, the user will no longer be able to authenticate in PRIMEUR Data Mover. Once confirmed, the entry will change to ENABLE.

DELETE

Select this option, the user will be removed from PRIMEUR Data Mover.

Importing Users

To import a user, go to Setup → Users & Groups → Internal Users → BIND USER. In the drop-down list, select the user you want to import. When done, choose the BIND button to confirm.

A maximum of 10 Internal Users will be listed. If the Internal User you are looking for is not included in the list, enter the name of the User and run the search again.

PreviousSetting the password policyNextCreating Internal Groups

Last updated 17 days ago

Password to log into the application. See .

To Edit the attributes of a user, click the icon on the right of the screen. The dialog window with User Details and Permissions entered for the User will be loaded and you will be able to modify attributes as needed. Click Save to confirm your changes.

🔓
Setting the password policy