There's no per-command breakdown, the one-line role descriptions in the User Guide (Behavior and Defaults, "Understanding Default Management User Roles") are all that exists. Look at the standard role: it's root minus the ability to change management users, so cert import should fall in scope. Test it first, HPE doesn't document cert rights per role.
Bigger catch: the config API can't upload the cert anyway. copy and crypto pki-import are action commands and the API guide says those aren't supported. Plan on SSH for the import step, API for the config that references it.
------------------------------
Dustin Burns
Lead Mobility Engineer @Worldcom Exchange, Inc.
ACCX 1271| ACMX 509| ACSP | ACDA | MVP Guru 2022-2023
If my post was useful accept solution and/or give kudos
------------------------------