External PAM Configurations

The External PAM Configurations enables System Admininstrators to integrate their existing Privileged Access Management (PAM) providers into their CPAM server.

From the External PAM Configurations page, System Administrators can create, update, test, and manage External PAM Server Configurations. The currently supported PAMs are:

  • Beyond Trust

  • CyberArk

  • Delinea

  • HashiCorp

  • Imprivata PAM

PAM Server Configurations

The Privileged Access Management (PAM) Server Configurations are connection profiles that allow the system to connect to and communicate with remote, third-party PAM servers and vaults. Each configuration contains:

  • Connection Details: The PAM server URL and authentication credentials.
  • Provider Type: Which PAM system is connected.
  • Configuration Parameters: Provider-specific settings for credential retrieval.
  • Connection Validation: Optional tunneling through managed Sites.

Requirements

System Administrators that configure External PAM Configurations, must have the following assets at hand:

  • PAM Server URL

  • Certificate Chain File in a PEM File

    Read PEM, DER, CRT, and CER: X.509 Encodings and Conversions for more information.

  • Provider-based additional requirements:

    • BeyondTrust: Requires API Key, an approved username, and time out rules.

    • CyberArk: Application ID.

    • Delinea Platform: Client ID and Client Secret.

    • Delinea/Thycotic Secret Server: Server's domain, organization, password, and secret server username.

    • HashiCopr Vault: AppRole Name, AppRole Path, Role ID, SecretID, Client token, password, password auth path.

    • Imprivata PAM: Password, Token, and username.

  • Internal Users require the following additional permissions:

    • MANAGE_PLUGINS

IMPORTANT:

Delinea (previously Thycotic) Secret Server is rolling out a new platform that is not currently supported to integrate with CPAM. To configure a secret and credentials plugin, consider an alternative while we integrate with Delinea Secret Server. For more information, navigate to:

NOTE:

Legacy Plugin functionality is still supported. Contact Imprivata Support for more information.

Configure External PAM Connections

An Administrator can only create Global PAM configurations, which assume that the remote PAM vault is directly accessible by the CPAM Server.

Customer users, particularly Gatekeeper or Application administrators, can create PAM Configurations that use one of their managed Sites as a tunnel for the PAM provider to reach the vault, allowing the CPAM server to use vaults that reside within that Customer's networks and would otherwise be unreachable.

NOTE:

After you configure the External PAM Configurations, these settings persist during the upgrades to the CPAM server. and they persist f your External PAM releases a new version.