This tutorial describes how you can connect One Identity Safeguard for Privileged Sessions (SPS) and your Hashicorp Vault with a Credential Store Plugin.
SPS can interact with Hashicorp Vault and can automatically retrieve the password or SSH key of the target host to form a comprehensive Privileged Access Management solution to protect critical assets and meet compliance requirements.
To successfully connect SPS with Hashicorp Vault, you need the following components:
A valid, working Hashicorp Vault server or cluster of servers with the following configuration:
A proxy user must be created on the
SPS reuses the username/password from the gateway authentication to authenticate on the
A SPS appliance (virtual or physical), at least version 6.2.0.
A Credential Store plugin for Hashicorp Vault.
SPS uses plugins to interact with third-party credential stores and password vaults. One Identity provides the sample Hashicorp Vault plugin free of charge, and provides help to customize it for your environment.
The plugin can use either explicit or gateway-based credentials.
A proxy user must be created on the
SPS reuses the username/password from the gateway authentication to authenticate on the
Interactive scenario: If the secrets in Hashicorp are stored in an unstructured way, SPS will have to retrieve the path to the secret from the end-user.
Alternatively, you can pass the vault path to the plugin by including vp= in the username. For example: vp=secret/linux/webserver/root@gu=exampleusername@root
The proxy will tokenize the above username by the @ delimiter, and parse out the following information:
Target username: root
Gateway username: exampleusername
Vault path: secret/linux/webserver/root
Automatic scenario: If the secrets are organized around server user names in Hashicorp Vault, then the path to the secret is generated from configuration and the server user name.
The following scenarios are the most common methods to use SPS and Hashicorp Vault together.
© 2024 One Identity LLC. ALL RIGHTS RESERVED. 利用規約 プライバシー Cookie Preference Center