> For the complete documentation index, see [llms.txt](https://docs.editran.onesait.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.editran.onesait.com/documentacion-editran/connect-v3.1-en/administradores/windows_permisos.md).

# Permissions in Windows

## Service user security and permissions

The proper functioning of Editran Connect in Windows environments depends not only on system configuration, but also on the permissions granted to the **user running the services**. This section summarizes the security and access considerations required for that user.

***

### Execution context

The Editran Connect services are developed in **Java** and use an **embedded JRE** deployed alongside the application. In addition, Editran includes:

* A **web server** (Editran Connect Server) for the user interface.
* A database service **PostgreSQL** for configuration and operations persistence.

All these components require specific permissions to operate correctly and securely.

***

### Permission requirements for the user

The user running the services (whether `LocalSystem` or a custom user) must have the following minimum permissions:

| Area / Resource                  | Required permission                             | Reason / Justification                                               |
| -------------------------------- | ----------------------------------------------- | -------------------------------------------------------------------- |
| Editran installation folder      | **Full control**                                | Read/write logs, execution of JRE and JAR files                      |
| Network and local ports          | **Open and listen on ports (e.g., 8081, 8085)** | Access to web services, digital signing, and external communications |
| Access to the PostgreSQL service | **Connection (localhost:5432)**                 | Access the configuration database                                    |
| Access to keys and certificates  | **Read access to local stores or files**        | Signature verification, secure connection to external services       |

***

### Security best practices

* 🔒 **Restrict access to sensitive folders.**\
  Only the service user should have write access to critical folders.
* 🧾 **Log relevant events.**\
  Enable security logging and monitor unauthorized access to ports or configuration files.
* 🌐 **Limit web access.**\
  Configure the firewall to restrict access to the web server to only the necessary IPs.

***

### Special considerations if a custom user is used

If the services stop working when using a user other than `LocalSystem`, make sure that:

* The user has "Log on as a service" permission.
* It has access to all directories where executables, logs, and configurations are located.
* The **environment variables** needed are correctly defined in its context (see previous section).
* It can connect to the database port and the local web server.

> ✅ *Recommendation:* Create a specific user of the type `svc_editran` and add it to a limited group with defined permissions.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.editran.onesait.com/documentacion-editran/connect-v3.1-en/administradores/windows_permisos.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
