Control-M Automation API Agent Certificate Management Authorization Changes


28 May 2026

From Control-M/EM 9.0.27, planned for release in October 2026, BMC is changing the role authorization (Access Control) categories and levels for the Control-M Automation API operations that enable you to configure certificates on SSL/TLS-configured Agents and manage and rotate Certificate Authorities (CA). These changes enable Control-M to maintain consistent security and improve role-based access control (RBAC).

The functionality of these API operations remains unchanged. Only the Access Control categories, Access Levels, authorization metadata, and audit classifications will change.

Control-M Automation API Agent Certificate Management Operation Authorization Categories and Levels

The following table describes the current and upcoming (in Control-M 9.0.27) categorization and authorization levels for all Control-M Automation API Agent certificate management operations.

Control-M Automation API OperationAccess Control CategoryAccess Level
CurrentControl-M 9.0.27CurrentControl-M 9.0.27
config server:agent:csr::createConfigurationSecurity   ChangeBrowseUpdate   Change
config server:agent:crt::deployConfigurationSecurity   ChangeBrowseFull         Change
config server:agent:crt:expiration::getConfigurationSecurity   ChangeBrowseBrowse
config ca:server:agent:list::getConfigurationSecurity   ChangeBrowseBrowse
config ca:server:agent::addConfigurationSecurity   ChangeBrowseBrowse
config ca:server:agent::deleteConfigurationSecurity   ChangeFullFull

BMC recommends that you do the following:

  • Review the roles that are assigned to users or service accounts that call Control-M Automation API Agent certificate management operations. For more information, see Control-M Automation API Authorizations.
  • Change the role authorizations to the new Access Control categories and levels after you upgrade to Control-M 9.0.27, as described in Adding a Role.

 

Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*

Control-M