External PAM Configurations
The External PAM Configurations enables System Admininstrators to integrate their existing Privileged Access Management (PAM) providers into their
From the External PAM Configurations page, System Administrators can create, update, test, and manage External PAM Server Configurations. The currently supported PAMs are:
-
Beyond Trust
-
CyberArk
-
Delinea
-
HashiCorp
-
Imprivata PAM
PAM Server Configurations
The Privileged Access Management (PAM) Server Configurations are connection profiles that allow the system to connect to and communicate with remote, third-party PAM servers and vaults. Each configuration contains:
- Connection Details: The PAM server URL and authentication credentials.
- Provider Type: Which PAM system is connected.
- Configuration Parameters: Provider-specific settings for credential retrieval.
- Connection Validation: Optional tunneling through managed Sites.
Requirements
System Administrators that configure External PAM Configurations, must have the following assets at hand:
-
PAM Server URL
-
Certificate Chain File in a PEM File
Read PEM, DER, CRT, and CER: X.509 Encodings and Conversions for more information.
-
Provider-based additional requirements:
-
BeyondTrust: Requires API Key, an approved username, and time out rules.
-
CyberArk: Application ID.
-
Delinea Platform: Client ID and Client Secret.
-
Delinea/Thycotic Secret Server: Server's domain, organization, password, and secret server username.
-
HashiCopr Vault: AppRole Name, AppRole Path, Role ID, SecretID, Client token, password, password auth path.
-
Imprivata PAM: Password, Token, and username.
-
-
Internal Users require the following additional permissions:
-
MANAGE_PLUGINS
-
Delinea (previously Thycotic) Secret Server is rolling out a new platform that is not currently supported to integrate with
-
Integrating Imprivata with Secret Server in Delinea documentation
-
Vaulting Secrets on the Platform in Delinea documentation
Legacy Plugin functionality is still supported. Contact Imprivata Support for more information.
Configure External PAM Connections
An Administrator can only create Global PAM configurations, which assume that the remote PAM vault is directly accessible by the
Customer users, particularly Gatekeeper or Application administrators, can create PAM Configurations that use one of their managed Sites as a tunnel for the PAM provider to reach the vault, allowing the
After you configure the External PAM Configurations, these settings persist during the upgrades to the
To create a new External PAM Configuration:
-
Navigate to System Administration > External PAM Configurations.
-
Click Add PAM Server Configurations.
-
Complete the form.
Ensure you have the assets described in the requirements.
IMPORTANT:Use Ignore SSL Certificates only for testing purposes. Not attaching SSL creates vulnerabilities in the system.
-
Click Test Configuration to validate connectivity. (Optional)
-
Click Create New External PAM Configuration.
To view your external PAM Configurations, navigate to System Administration > External PAM Configurations.
The configuration list displays:
- Name: User-defined identifier.
- Description: User-defined comment.
- PAM Type: The PAM System provider.
- URL: The PAM server's address.
- Actions: Edit button to update the configuration.
To update an External PAM Configuration:
-
Navigate to System Administration > External PAM Configurations.
-
Select the configuration you want to update.
-
Click Edit.
-
Update any field.
-
Click Test Configuration to validate connectivity. (Optional)
-
Click Save External PAM Configuration.
To delete an External PAM Configuration:
-
Navigate to System Administration > External PAM Configurations.
-
Select the configuration you want to delete.
-
Click Edit.
-
Click Delete.
-
Confirm the deletion.