The list of audit policies. An audit policy contains settings for encrypting, timestamping, and signing audit trails. To enable auditing for a connection, select an audit policy when configuring connections, and enable auditing for the appropriate protocol channels in the connection's channel policy.
NOTE: The default audit policy is pre-selected when creating connection policies. Modify that audit policy with care.
URL
GET https://<IP-address-of-SPS>/api/configuration/policies/audit_policies
Sample request
The following command lists the audit policies.
curl --cookie cookies https://<IP-address-of-SPS>/api/configuration/policies/audit_policies
The following command retrieves the properties of a specific policy.
curl --cookie cookies https://<IP-address-of-SPS>/api/policies/audit_policies/<policy-id>
Response
The following is a sample response received when listing audit policies.
{
"items": [
{
"key": "78101850949e47437dd91d",
"meta": {
"href": "/api/configuration/policies/audit_policies/78101850949e47437dd91d"
}
},
{
"key": "9161063345713f11489305",
"meta": {
"href": "/api/configuration/policies/audit_policies/9161063345713f11489305"
}
},
{
"key": "1e089e2a-76b4-4079-94e3-c83ebc74dc2e",
"meta": {
"href": "/api/configuration/policies/audit_policies/1e089e2a-76b4-4079-94e3-c83ebc74dc2e"
}
}
],
"meta": {
"first": "/api/configuration/policies/audit_policies",
"href": "/api/configuration/policies/audit_policies",
"last": "/api/configuration/policies/usermapping_policies",
"next": "/api/configuration/policies/content_policies",
"parent": "/api/configuration/policies",
"previous": null,
"transaction": "/api/transaction"
}
}
When retrieving the endpoint of a specific audit policy, the response is the following.
{
"body": {
"encryption": {
"certificates": [
{
"certificate": "<cert1>",
"four_eyes_certificate": "<cert2>"
}
],
"different_certificates_for_upstream": {
"certificates": [
{
"certificate": "<cert3>",
"four_eyes_certificate": "<cert4>"
}
],
"enabled": true
},
"enabled": true
},
"name": "<policy-name>",
"signing": {
"enabled": true,
"x509_identity": {
"key": "ec0b6604-37f6-4df6-bd2f-d7879a75b324",
"meta": {
"href": "/api/configuration/x509/ec0b6604-37f6-4df6-bd2f-d7879a75b324"
}
}
},
"timestamping_enabled": true
},
"key": "1e089e2a-76b4-4079-94e3-c83ebc74dc2e",
"meta": {
"first": "/api/configuration/policies/audit_policies/78101850949e47437dd91d",
"href": "/api/configuration/policies/audit_policies/1e089e2a-76b4-4079-94e3-c83ebc74dc2e",
"last": "/api/configuration/policies/audit_policies/1e089e2a-76b4-4079-94e3-c83ebc74dc2e",
"next": null,
"parent": "/api/configuration/policies/audit_policies",
"previous": "/api/configuration/policies/audit_policies/9161063345713f11489305",
"transaction": "/api/transaction"
}
}
key |
|
|
string |
Top level element, contains the ID of the policy. |
body |
|
|
Top level element (string) |
The configuration elements of the policy. |
|
encryption |
|
Top level element |
Audit trail encryption settings. |
|
name |
|
string |
The name of the policy. This name is also displayed on the SPS web interface. It cannot contain whitespace. |
|
signing |
|
Top level element |
Audit trail signing settings. |
|
|
enabled |
boolean |
Set to true to enable audit trail signing.
If signing is enabled, the x509_identity element is also required. |
|
|
x509_identity |
string |
Required for signing audit trails.
References the identifier of the X.509 certificate stored on SPS. You can configure certificates at the /api/configuration/x509/ endpoint.
To modify or add an X.509 host certificate, use the value of the returned key as the value of the x509_identity element, and remove any child elements (including the key). |
|
timestamping |
|
boolean |
Set to true to timestamp the audit trail. |
certificates |
|
|
Top level list |
Contains the encrypting certificates. |
|
certificate |
|
string |
The encrypting certificate. You can replay an encrypted audit trail with the private key of the encrypting certificate. |
|
four_eyes_certificate |
|
string |
Additional certificate for joint (4-eyes) encryption. You can only replay a jointly encrypted audit trail with the private keys of both certificates. |
different_certificates_for_upstream |
|
|
Top level item |
Configures encrypting upstream traffic separately. |
|
certificates |
|
Top level list |
The certificates for encrypting upstream traffic. |
|
|
certificate |
string |
The encrypting certificate. You can replay an encrypted upstream with the private key of the encrypting certificate. |
|
|
four_eyes_certificate |
string |
Additional certificate for joint (4-eyes) encryption. You can only replay a jointly encrypted upstream with the private keys of both certificates. |
|
enabled |
|
boolean |
Set to true to encrypt the upstream traffic with separate certificate(s).
If upstream encryption is enabled, the certificates element is required. |
enabled |
|
|
boolean |
Set to true to enable encrypting audit trails.
If encryption is enabled, the certificates and different_certificates_for_upstream elements are required. |
Examples:
Disable encryption, signing, and timestamping.
{
"encryption": {
"enabled": false
},
"name": "default",
"signing": {
"enabled": false
},
"timestamping_enabled": false
}
Encrypt upstream traffic only (single certificate).
{
"encryption": {
"certificates": [],
"different_certificates_for_upstream": {
"certificates": [
{
"certificate": "<cert>",
"four_eyes_certificate": null
}
],
"enabled": true
},
"enabled": true
},
"name": "Upstream_only",
"signing": {
"enabled": false
},
"timestamping_enabled": false
}
Enable signing and timestamping, no traffic encryption.
{
"encryption": {
"enabled": false
},
"name": "Sign_and_timestamp",
"signing": {
"enabled": true,
"x509_identity": {
"key": "9508db81-4a3f-45a7-a2b1-a86f71c56416",
"meta": {
"href": "/api/configuration/x509/9508db81-4a3f-45a7-a2b1-a86f71c56416"
}
}
},
"timestamping_enabled": true
}
Enable signing and timestamping, and encrypt traffic with a single certificate (no separate upstream encryption).
{
"encryption": {
"certificates": [
{
"certificate": "<cert>",
"four_eyes_certificate": null
}
],
"different_certificates_for_upstream": {
"enabled": false
},
"enabled": true
},
"name": "API_audit_pol",
"signing": {
"enabled": true,
"x509_identity": {
"key": "d0286f64-41aa-45e1-ab19-830ac2f99f57",
"meta": {
"href": "/api/configuration/x509/d0286f64-41aa-45e1-ab19-830ac2f99f57"
}
}
},
"timestamping_enabled": true
}
Encrypting certificates
Encrypting certificates must not contain any metadata. SPS uses only the key part of the certificate, no other data (expiry, etc.) are relevant for encryption.
To use a certificate with the SPS API, remove all metadata, and substitute line breaks with \n.
The following is an example certificate, as used on the SPS web interface:
-----BEGIN CERTIFICATE-----
MIIDnDCCAoQCCQDc536Ob5tPQTANBgkqhkiG9w0BAQUFADCBjzELMAkGA1UEBhMC
Q0ExEDAOBgNVBAgTB09udGFyaW8xEDAOBgNVBAcTB1Rvcm9udG8xEDAOBgNVBAoT
B0JhbGFiaXQxFjAUBgNVBAsTDURvY3VtZW50YXRpb24xEDAOBgNVBAMTB2JhbGFi
aXQxIDAeBgkqhkiG9w0BCQEWEWNhdGFpbEBiYWxhYml0Lmh1MB4XDTE2MDQyMjE2
MDAyNloXDTE3MDQyMjE2MDAyNlowgY8xCzAJBgNVBAYTAkNBMRAwDgYDVQQIEwdP
bnRhcmlvMRAwDgYDVQQHEwdUb3JvbnRvMRAwDgYDVQQKEwdCYWxhYml0MRYwFAYD
VQQLEw1Eb2N1bWVudGF0aW9uMRAwDgYDVQQDEwdiYWxhYml0MSAwHgYJKoZIhvcN
AQkBFhFjYXRhaWxAYmFsYWJpdC5odTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCC
AQoCggEBAOGa9I2jmVlVdVWEI/Wy7ahTeyaIjK52FQUXqxG8okOSD+nV74ZFUuiS
59X+2Ow1aDqVGrDMgPNhSVpYXUvDUAUOILJW4rAIoxDY6vDU9/4v9dDiQfEPlauw
0qNRjPS1MLzjSOQDSKqPkdivkS6HKZeX3+TFq3OxO+vIrF9zFfp9T+eDG2oSobPc
3mV2zkvtD61CXzbezAVdArDl6WnysRyzxyH8WEhFwZepWxFD9Y5N1dzKody7Hncs
X5kVIv0+Z6bBHfg/7wHWysJdwNuLr0ByTOvPM6WdA83k3Fy2gYNk7Rc0BbRFbQTX
hJVfUzSUWHVhFQtAb4diKU5voqepfNMCAwEAATANBgkqhkiG9w0BAQUFAAOCAQEA
R5DIwOHsEKoGkiI3cHC2VMnxP2rRhpTneh6El+DFnQPdjrXa+tnqV4TdnNaD+FvP
AB1kqbmC4hJAsjMLU2b1ne6m+SLmzhRuMxcA6x+fnYvcQT57IbRdq2E/4oJGeyuy
0jQE+nmoVD3lDytIOxCfQvZhl1tcbBE5hp5USme4PmNhY6QfUlgjsFjPfoVG7XDB
uNaUoWS6RvZPmL5IuvF9tqe96ES6DTjC8rBfQYvSoVNjjPnUMx0C8xstRSEG7oJc
N5+4ImYnFNxSG20hZpFy0OFDf2g7Fx+W50/NtXamUF1Sf8WlPZc03oVl1/Fzo7mt
qYyyD1ld89OUEYZ+aJQd/A==
-----END CERTIFICATE-----
The same certificate, as accepted by the SPS API:
"certificate": "-----BEGIN CERTIFICATE-----\nMIIDnDCCAoQCCQDc536Ob5tPQTANBgkqhkiG9w0BAQUFADCBjzELMAkGA1UEBhMC\nQ0ExEDAOBgNVBAgTB09udGFyaW8xEDAOBgNVBAcTB1Rvcm9udG8xEDAOBgNVBAoT\nB0JhbGFiaXQxFjAUBgNVBAsTDURvY3VtZW50YXRpb24xEDAOBgNVBAMTB2JhbGFi\naXQxIDAeBgkqhkiG9w0BCQEWEWNhdGFpbEBiYWxhYml0Lmh1MB4XDTE2MDQyMjE2\nMDAyNloXDTE3MDQyMjE2MDAyNlowgY8xCzAJBgNVBAYTAkNBMRAwDgYDVQQIEwdP\nbnRhcmlvMRAwDgYDVQQHEwdUb3JvbnRvMRAwDgYDVQQKEwdCYWxhYml0MRYwFAYD\nVQQLEw1Eb2N1bWVudGF0aW9uMRAwDgYDVQQDEwdiYWxhYml0MSAwHgYJKoZIhvcN\nAQkBFhFjYXRhaWxAYmFsYWJpdC5odTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCC\nAQoCggEBAOGa9I2jmVlVdVWEI/Wy7ahTeyaIjK52FQUXqxG8okOSD+nV74ZFUuiS\n59X+2Ow1aDqVGrDMgPNhSVpYXUvDUAUOILJW4rAIoxDY6vDU9/4v9dDiQfEPlauw\n0qNRjPS1MLzjSOQDSKqPkdivkS6HKZeX3+TFq3OxO+vIrF9zFfp9T+eDG2oSobPc\n3mV2zkvtD61CXzbezAVdArDl6WnysRyzxyH8WEhFwZepWxFD9Y5N1dzKody7Hncs\nX5kVIv0+Z6bBHfg/7wHWysJdwNuLr0ByTOvPM6WdA83k3Fy2gYNk7Rc0BbRFbQTX\nhJVfUzSUWHVhFQtAb4diKU5voqepfNMCAwEAATANBgkqhkiG9w0BAQUFAAOCAQEA\nR5DIwOHsEKoGkiI3cHC2VMnxP2rRhpTneh6El+DFnQPdjrXa+tnqV4TdnNaD+FvP\nAB1kqbmC4hJAsjMLU2b1ne6m+SLmzhRuMxcA6x+fnYvcQT57IbRdq2E/4oJGeyuy\n0jQE+nmoVD3lDytIOxCfQvZhl1tcbBE5hp5USme4PmNhY6QfUlgjsFjPfoVG7XDB\nuNaUoWS6RvZPmL5IuvF9tqe96ES6DTjC8rBfQYvSoVNjjPnUMx0C8xstRSEG7oJc\nN5+4ImYnFNxSG20hZpFy0OFDf2g7Fx+W50/NtXamUF1Sf8WlPZc03oVl1/Fzo7mt\nqYyyD1ld89OUEYZ+aJQd/A==\n-----END CERTIFICATE-----\n"
Add an audit policy
To add an audit policy, you have to:
-
Create the JSON object for the new audit policy.
POST the JSON object to the https://<IP-address-of-SPS>/api/configuration/policies/audit_policies endpoint. You can find a detailed description of the available parameters listed in Element .
If the POST request is successful, the response includes the key of the new audit policy. For example:
{
"key": "1e089e2a-76b4-4079-94e3-c83ebc74dc2e",
"meta": {
"href": "/api/configuration/policies/audit_policies/1e089e2a-76b4-4079-94e3-c83ebc74dc2e",
"parent": "/api/configuration/policies/audit_policies",
"transaction": "/api/transaction"
}
}
Modify an audit policy
To modify an audit policy, you have to:
-
Modify the JSON object of the audit policy.
PUT the modified JSON object to the https://<IP-address-of-SPS>/api/configuration/policies/audit_policies/<policy-key> endpoint. You can find a detailed description of the available parameters listed in Element .
201 |
Created |
The new resource was successfully created. |
401 |
Unauthenticated |
The requested resource cannot be retrieved because the client is not authenticated and the resource requires authorization to access it. The details section contains the path that was attempted to be accessed, but could not be retrieved. |
403 |
Unauthorized |
The requested resource cannot be retrieved because the client is not authorized to access it. The details section contains the path that was attempted to be accessed, but could not be retrieved. |
404 |
NotFound |
The requested object does not exist. |
Backup policies define the address of the backup server, which protocol to use to access it, and other parameters. To list the available Backup policies, use the following command.
curl --cookie cookies https://<IP-address-of-SPS>/api/configuration/policies/backup_policies/
The following sections detail the properties of Backup policy objects.
URL
GET https:<IP-address-of-SPS>/api/configuration/policies/backup_policies/<object-id>
Sample request
The following command lists the properties of a specific Backup policy object.
curl --cookie cookies -https:<IP-address-of-SPS>/api/configuration/policies/backup_policies<object-id>
Response
The following is a sample response received, showing the properties of Backup policy objects.
{
"key": "99275192754364c2b1bd01",
"body": {
"name": "backup_all_with_filelist",
"include_node_id_in_path": false,
"notification_event": {
"type": "all",
"send_filelist": true,
"file_count_limit": 123456
},
"target": {
"type": "nfs",
"server": {
"selection": "ip",
"value": "1.2.3.5"
},
"path": "/data/backup"
},
"start_times": [
"10:10"
]
}
}
name |
|
string |
Top level element, the name of the object. This name is also displayed on the SPS web interface. It cannot contain whitespace. |
include_node_id_in_path |
|
boolean |
Include the Cluster Node ID in the path. Recommended to set to True if the SPS instance is a node in a cluster. This ensures that the ID of the node is included in the path of the relevant directory, which is required to prevent cluster nodes from backing up data to the same location, and so overwriting each other's data and resulting in data loss. |
notification_event |
|
Top level element |
|
|
type |
string (all | errors-only | none) |
- all: Sends notification emails on all backup-related events.
- errors-only: Sends notification emails only on backup-related errors.
- none: Sends no backup-related notification emails.
|
|
send_filelist |
boolean |
This is meaningful only if notification_event is set to all.
True if the list of files are included in the notification e-mail. |
|
file_count_limit |
integer |
This is meaningful only if notification_event is set to all and send_filelist is set to True.
The maximum number of files that are included in the notification e-mail. |
target |
|
Top level element |
Defines the address of the backup server, which protocol to use to access it, and other parameters. SPS can be configured to use the Rsync, SMB/CIFS, and NFS protocols to access the backup server. |
|
type |
string (rsync | smb | nfs) |
- rsync: Rsync over SSH
- smb: Copy data to a remote server using SMB/CIFS
- nfs: Copy data to a remote server using NFS
|
|
server |
Top level element |
|
|
domain |
string |
Only if type is set to smb.
The domain name of the target server |
|
protocol_version |
string |
Only if type is set to smb.
The SMB protocol to use when SPS connects to the server. Servers are usually backwards compatible with earlier protocol versions (for example, a server that supports version 2.1 supports versions 2.0 and 1.0 as well). |
|
share |
string |
Only if type is set to smb.
The name and directory path of the share in the following format: share_name/path/to/directory |
|
authentication |
Top level element |
Only if type is set to smb. |
|
username |
string |
Only if type is set to rsync.
The username used to log on to the remote server |
|
path |
string |
The path to the backup directory on the target server |
|
auth_key |
JSON object |
Only if type is set to rsync.
This key will be used to authenticate SPS on the remote server. The public key of this keypair must be imported to the remote server. For details on private keys, see Private keys stored on SPS. For example: "auth_key": {
"key": "XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX",
"meta": {
"href": "/api/configuration/private_keys/XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX"
}
}, |
|
host_key |
Top level element or string |
Only if type is set to rsync. |
|
port |
integer |
Only if type is set to rsync.
The port number of the SSH server running on the remote machine |
start_times |
|
list of strings |
The time when the archive process starts in H:MM or HH:MM format. |
server |
|
Top level element |
|
|
selection |
string (ip | fqdn) |
- ip: IP address
- fqdn: Hostname
|
|
value |
string |
The IP address or the hostname of the remote server |
authentication |
|
Top level element |
Only if type is set to smb. |
|
selection |
string (password | anonymous) |
- password: To log on using a username and password.
- anonymous: To log on anonymously.
|
|
username |
string |
Only if selection is set to password.
The username used to log on to the remote server |
|
password |
string |
Only if selection is set to password.
The password corresponding to the username |
host_key |
|
Top level element or string |
Only if type is set to rsync.
When editing this policy, for usability purposes, you can enter the public key of the host in the host_key element without using the selection and value elements. For example: "host_key": "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQDmIDa1PuJFzgvZvPs9hzgvMd/9WIn4J7RBFuO769g/OgTvCRTgrF8IM/0iN0YzcUM3IGyPnJ1OlLE2Gb6CxVvEcjP6pme7JroAWo039wQHR3Rxl1KoEmC+0EOImQycIdAS7grWNwD2VB2S7iyFErZhqRxhGJPKbR/kF3lQ3dGtt3pr4+R6wnU9lZ7RSETfB+N09FE4f5Nqy+VEShgdc66ElFRXXVilmiTnIMAyim3T7UVNgRdZYIUAZ79tkyTp6I+DZ7k7BG9TYwdBjhwr0eVL56ILxpXylpzWONuMhHxLKsL42NfmeagjVUD1CJVOrfaGjCVGEeS3iQs6GVVxe78n"
When querying, the public key of the host will always be displayed in the selection and value elements. |
|
selection |
string (dsa | dss | rsa) |
The algorithm the key is based on. |
|
value |
string |
The public key of the host. |
Example: querying an Rsync backup policy
When the query is the following:
curl --cookie cookies "https://<IP-address-of-SPS>/api/configuration/policies/backup_policies/99275192754364c2b1bd04"
The response is the following:
{
"key": "99275192754364c2b1bd04",
"body": {
"name": "backup_rsync",
"include_node_id_in_path": true,
"notification_event": {
"type": "none",
"send_filelist": true,
"file_count_limit": 10240
},
"target": {
"type": "rsync",
"server": {
"selection": "ip",
"value": "192.168.122.1"
},
"username": "user1",
"path": "/data/backup",
"auth_key": {
"key": "XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX",
"meta": {
"href": "/api/configuration/private_keys/XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX"
}
},
"host_key": {
"selection": "rsa",
"value": "AAAAB3NzaC1yc2EAAAADAQABAAAAYQCsU80IBrJbOlqCi03qZK+FtgS783VKE1TVZBtDQlsXJ9FXu6KNBvqvSAjcXiWY+izqn+P14UVRY1vOdz7WwLIWOUoTKHfPMqv3bdjwM4Bhd26POWSFyDf46yx1YzvMwgc="
},
"port": 1122
},
"start_times": [
"8:00"
]
}
}
You can monitor the traffic of certain connections in real time, and execute various actions if a certain pattern (for example, a particular command or text) appears in the command line or on the screen, or if a window with a particular title appears in a graphical protocol. Since content-monitoring is performed real-time, One Identity Safeguard for Privileged Sessions (SPS) can prevent harmful commands from being executed on your servers. SPS can also detect numbers that might be credit card numbers. The patterns to find can be defined as regular expressions. In case of ICA, RDP, and VNC connections, SPS can detect window title content.
The following actions can be performed:
-
Log the event in the system logs.
-
Immediately terminate the connection.
-
Send an e-mail or SNMP alerts about the event.
-
Store the event in the connection database of SPS.
SPS currently supports content monitoring in SSH session-shell connections, Telnet connections, RDP and Citrix ICA Drawing channels, and in VNC connections.
NOTE: Command, credit card and window detection algorithms use heuristics. In certain (rare) situations, they might not match the configured content. In such cases, contact our Support Team to help analyze the problem.
Real-time content monitoring in graphical protocols is not supported for Arabic and CJK languages.
To list the available Content policies, use the following command.
curl --cookie cookies https://<IP-address-of-SPS>/api/configuration/policies/content_policies
The following sections detail the properties of Content policy objects.
URL
GET https:<IP-address-of-SPS>/api/configuration/policies/content_policies/<object-id>
Sample request
The following command lists the properties of a specific Content policy object.
curl --cookie cookies -https:<IP-address-of-SPS>/api/configuration/policies/content_policies/<object-id>
Response
The following is a sample response received, showing the properties of Content policy objects.
{
"body": {
"name": "example-content-policy-window-title",
"rules": [
{
"actions": {
"log": true,
"notify": true,
"store_in_connection_database": true,
"terminate": false
},
"event": {
"ignore": [],
"match": [
"mmc.exe"
],
"selection": "window_title"
},
"gateway_groups": [],
"remote_groups": []
}
]
}
}
name |
|
string |
Top level element, the name of the object. This name is also displayed on the SPS web interface. It cannot contain whitespace. |
rules |
|
JSON object |
Top level element, contains the configuration properties of the object. |
|
actions |
JSON object |
The list of actions to perform when the Content policy matches the analyzed traffic. All actions are boolean values (true or false) |
|
event |
JSON object |
Specifies the event that triggers an action. |
|
gateway_groups |
list |
To apply the Content policy only for users belonging to specific groups, list those groups in the gateway_groups or remote_groups fields. If the gateway_groups or remote_groups field is set, the content policy is applied only to connections of these usergroups.
For example: "gateway_groups": ["group1", "group2"], |
|
remote_groups |
list |
To apply the Content policy only for users belonging to specific groups, list those groups in the gateway_groups or remote_groups fields. If the gateway_groups or remote_groups field is set, the content policy is applied only to connections of these usergroups.
For example: "remote_groups": ["group1", "group3"], |
actions |
|
JSON object |
The list of actions to perform when the Content policy matches the analyzed traffic. All actions are boolean values (true or false) |
|
log |
boolean |
Log the event in the system logs. Possible values: true or false |
|
terminate |
boolean |
Immediately terminate the connection. Possible values: true or false |
|
notify |
boolean |
Send an e-mail or SNMP alerts about the event. Possible values: true or false |
|
store_in_connection_database |
boolean |
Store the event in the connection database of SPS. Possible values: true or false |
event |
|
JSON object |
Specifies the event that triggers an action. |
|
ignore |
list |
A list of strings or regular expressions. SPS will perform an action if the match expression is found in the connection, unless it is listed in the ignore list. For example: "ignore": [
"mmc.exe",
"cmd.exe"
Use Perl Compatible Regular Expressions (PCRE). The following characters must be escaped using a backslash character: '(single-quote). For example, instead of .*' use .*\' SPS uses substring search to find the expression in the content. That is, SPS finds the expression even if there is more content before or after the matching part. For example, the conf pattern will match the following texts: conf, configure, reconfigure, arcconf, and so on. Using complicated regular expressions or using many regular expressions will affect the performance of SPS. If the multiple expressions are set, SPS processes them one after the other, and stops processing the content if the first match is found, even if other expressions would also match the content. Therefore, when using multiple expressions, start with the most specific one, and add general expressions afterward.
|
|
match |
list |
A list of strings or regular expressions. SPS will perform an action if the match expression is found in the connection, unless it is listed in the ignore list. For example: "match": [
"mmc.exe",
"cmd.exe"
Use Perl Compatible Regular Expressions (PCRE). The following characters must be escaped using a backslash character: '(single-quote). For example, instead of .*' use .*\' SPS uses substring search to find the expression in the content. That is, SPS finds the expression even if there is more content before or after the matching part. For example, the conf pattern will match the following texts: conf, configure, reconfigure, arcconf, and so on. Using complicated regular expressions or using many regular expressions will affect the performance of SPS. If the multiple expressions are set, SPS processes them one after the other, and stops processing the content if the first match is found, even if other expressions would also match the content. Therefore, when using multiple expressions, start with the most specific one, and add general expressions afterward.
|
|
selection |
string |
The type of event that you want to monitor.
-
command: The commands executed in the session-shell channel of SSH connections, or in Telnet connections.
|
Caution:
During indexing, if a separate certificate is used to encrypt the upstream traffic, command detection works only if the upstream key is accessible on the machine running the indexer. |
-
screen_content: Every text that appears on the screen. For example, every text that is displayed in the terminal of SSH or Telnet connections. This includes the executed commands as well, unless echoing is turned off for the terminal.
-
creditcard: Process every text that appears on the screen and attempt to detect credit card numbers in SSH or Telnet connections. SPS performs an action if the number of detected credit card numbers exceeds the value set as Permitted number of credit card numbers.
Credit card number detection is based on the Luhn algorithm and lists of known credit card number prefixes.
-
window_title: Text appearing as window titles in case of RDP, Citrix ICA, and VNC connections. Only Windows Classic Themes are supported. Themes with rounded corners, or Windows Aero themes are not supported.
For example: "selection": "window_title" |
Add a content policy
To add a content policy, you have to:
-
Create the JSON object for the new content policy.
POST the JSON object to the https://<IP-address-of-SPS>/api/configuration/policies/content_policies endpoint. You can find a detailed description of the available parameters listed in Element .
If the POST request is successful, the response includes the key of the new policy. For example:
{
"key": "1e089e2a-76b4-4079-94e3-c83ebc74dc2e",
"meta": {
"href": "/api/configuration/policies/content_policies/1e089e2a-76b4-4079-94e3-c83ebc74dc2e",
"parent": "/api/configuration/policies/content_policies",
"transaction": "/api/transaction"
}
}
Modify a content policy
To modify a content policy, you have to:
-
Modify the JSON object of the content policy.
PUT the modified JSON object to the https://<IP-address-of-SPS>/api/configuration/policies/content_policies/<policy-key> endpoint. You can find a detailed description of the available parameters listed in Element .
201 |
Created |
The new resource was successfully created. |
401 |
Unauthenticated |
The requested resource cannot be retrieved because the client is not authenticated and the resource requires authorization to access it. The details section contains the path that was attempted to be accessed, but could not be retrieved. |
403 |
Unauthorized |
The requested resource cannot be retrieved because the client is not authorized to access it. The details section contains the path that was attempted to be accessed, but could not be retrieved. |
404 |
NotFound |
The requested object does not exist. |
SPS can authenticate the users of the controlled SSH or RDP connections to LDAP databases.
URL
GET https://<IP-address-of-SPS>/api/configuration/policies/ldap_servers
Sample request
The following command lists the available LDAP server configurations.
curl --cookie cookies https://<IP-address-of-SPS>/api/configuration/policies/ldap_servers
The following command retrieves the properties of a specific LDAP server.
curl --cookie cookies https://<IP-address-of-SPS>/api/configuration/policies/ldap_servers/<object-id>
Response
The following is a sample response received when listing LDAP servers.
{
"items": [
{
"key": "3548834825727acc530407",
"meta": {
"href": "/api/configuration/policies/ldap_servers/3548834825727acc530407"
}
}
],
"meta": {
"first": "/api/configuration/policies/audit_policies",
"href": "/api/configuration/policies/ldap_servers",
"last": "/api/configuration/policies/usermapping_policies",
"next": "/api/configuration/policies/signing_cas",
"parent": "/api/configuration/policies",
"previous": "/api/configuration/policies/indexing",
"transaction": "/api/transaction"
}
}
When retrieving the endpoint of a specific LDAP server, the response is the following.
{
"key": "posix-simple",
"body": {
"name": "posix-simple",
"schema": {
"selection": "posix",
"membership_check": {
enabled": true,
"member_uid_attribute": "memberUid"
},
"memberof_check": {
"enabled": true,
"memberof_user_attribute": "memberOf",
"memberof_group_objectclass": "groupOfNames"
},
"username_attribute": "uid",
"user_dn_in_groups": []
},
"servers": [
{
"host": {
"selection" : "ip",
"value": "10.110.0.1"
},
"port": 389
}
],
"user_base_dn": "ou=People,dc=example,dc=com",
"group_base_dn": "ou=Groups,dc=example,dc=com",
"bind_dn": null,
"bind_password": null,
"memberof_attribute": null,
"encryption": {
"selection": "disabled"
},
"publickey_attribute": "sshPublicKey",
"generated_publickey_attribute": null
}
}
key |
|
|
string |
Top level element, contains the ID of the LDAP server configuration. |
body |
|
|
Top level element (string) |
Contains the properties of the LDAP server. |
|
user_base_dn |
|
string |
Name of the DN to be used as the base of queries regarding users.
NOTE: You must fill in this field. It is OK to use the same value for user_base_dn and group_base_dn.
However, note that specifying a sufficiently narrow base for the LDAP subtrees where users and groups are stored can speed up LDAP operations. |
|
group_base_dn |
|
string |
Name of the DN to be used as the base of queries regarding groups.
NOTE: You must fill in this field. It is OK to use the same value for user_base_dn and group_base_dn.
However, note that specifying a sufficiently narrow base for the LDAP subtrees where users and groups are stored can speed up LDAP operations. |
|
bind_dn |
|
string |
The Distinguished Name that SPS should use to bind to the LDAP directory. |
|
bind_password |
|
string |
References the password SPS uses to authenticate on the server. You can configure passwords at the /api/configuration/passwords/ endpoint.
To modify or add a password, use the value of the returned key as the value of the password element, and remove any child elements (including the key). |
|
encryption |
|
Top level item |
Configuration settings for encrypting the communication between SPS and the LDAP server. |
|
generated_publickey_attribute |
|
string |
Set this element to null if you use passwords to authenticate.
Configure this element if you want SPS to generate server-side encryption keys on-the-fly, and store them in a separate attribute on the LDAP server. |
|
name |
|
string |
Top level element, the name of the object. This name is also displayed on the SPS web interface. It cannot contain whitespace. |
|
publickey_attribute |
|
string |
Set this element to null if you use passwords to authenticate.
The name of the LDAP attribute that stores the public keys of the users. |
|
schema |
|
Top level item |
Contains the configuration settings for the AD schema. |
|
servers |
|
Top level list |
Contains the addresses and ports of the LDAP servers. |
selection |
|
string |
Defines the type of encryption SPS uses to communicate with the LDAP server. Possible values are:
-
disabled
The communication is not encrypted.
-
ssl
TLS/SSL encryption. To use a TLS-encrypted with certificate verification to connect to the LDAP server, use the full domain name (for example ldap.example.com) as the server address, otherwise the certificate verification might fail. The name of the LDAP server must appear in the Common Name of the certificate.
TLS-encrypted connection to Microsoft Active Directory is supported only on Windows 2003 Server and newer platforms. Windows 2000 Server is not supported.
-
starttls
Opportunistic TLS. |
client_authentication |
|
Top level item |
Must be used with the selection child element.
Configures the X.509 certificate SPS uses to authenticate on the LDAP server. |
|
enabled |
boolean |
Must be used with the client-authentication parent element.
Set to true if the LDAP server requires mutual authentication. |
|
x509_identity |
string |
Must be used if the enabled element is set to true.
References the identifier of the X.509 certificate stored on SPS. You can configure X.509 certificates at the /api/configuration/x509/ endpoint.
To modify or add an X.509 host certificate, use the value of the returned key as the value of the x509_identity element, and remove any child elements (including the key). |
selection |
|
string |
Defines the type of encryption SPS uses to communicate with the LDAP server. Possible values are:
-
disabled
The communication is not encrypted.
-
ssl
TLS/SSL encryption. To use a TLS-encrypted with certificate verification to connect to the LDAP server, use the full domain name (for example ldap.example.com) as the server address, otherwise the certificate verification might fail. The name of the LDAP server must appear in the Common Name of the certificate.
TLS-encrypted connection to Microsoft Active Directory is supported only on Windows 2003 Server and newer platforms. Windows 2000 Server is not supported.
-
starttls
Opportunistic TLS. |
server_certificate_check |
|
Top level item |
Must be used with the enabled child element.
Configuration settings for verifying the LDAP server's certificate. |
|
enabled |
boolean |
Must be used with the server_certificate_check parent element.
Set to true to verify the LDAP server's certificate using the certificate of a Certificate Authority (CA). |
|
server_certificate_ca |
string |
Must be used if the enabled element is set to true.
The certificate of the CA. |
host |
|
Top level item |
Contains the address of the LDAP server. |
|
selection |
string |
Defines the address type (IP or domain name). Possible values are:
|
|
value |
string |
The address of the LDAP server. |
port |
|
int |
The port of the LDAP server. |
selection |
|
string |
Configures which LDAP schema to use: AD or POSIX. Possible values are:
-
ad: Microsoft Active Directory server. For details and examples, see LDAP servers.
-
posix: The server uses the POSIX LDAP scheme.
Must be used with the member_uid_attribute and username_attribute elements. For details and examples, see LDAP servers. |
membership_check |
|
Top level element |
|
|
enabled |
boolean |
POSIX: Enables POSIX primary and supplementary group membership checking.
AD: Enables Active Directory specific non-primary group membership checking. |
|
nested_groups |
boolean |
Must be used if the selection element is set to ad.
Enable nested groups allows AD nested group support. |
|
member_uid_attribute |
string |
Must be used if the value of the selection element is set to posix.
The POSIX group membership attribute name is the name of the attribute in a posixGroup group object, which lists the plain usernames that are members of the group. These groups are usually referred to as supplementary groups of the referred user. Can be null. |
memberof_check |
|
Top level element |
The Enable checking for group DNs in user objects setting allows checking a configurable attribute in the user object. This attribute contains a list of group DNs the user is additionally a member of. This user attribute is usually memberOf. |
|
enabled |
boolean |
To enable memberof_check, set it to true. |
|
memberof_user_attribute |
string |
Must be used if the memberof_check is set it to true. The name of the user attribute (for example, memberOf) that contains the group DNs. |
username_attribute |
|
string |
Must be used if the selection element is set to posix.
Attribute name of the username (user ID). |
user_dn_in_groups |
|
Top level list |
Add object_class / attribute pairs. SPS will search for the user DN in the group's attribute defined here. If it finds the user DN there, SPS considers the user the member of that group.
For example: "user_dn_in_groups": [
{
"object_class": "groupOfNames",
"attribute": "member"
},
{
"object_class": "groupOfUniqueNames",
"attribute": "uniqueMember"
}
] |
|
object_class |
string |
Consider groups of this objectClass. |
|
attribute |
string |
Name of the group attribute which contains the user DN. |
Example: Configure a POSIX server without communication encryption
{
"name": "<name-of-ldap-policy>",
"schema": {
"selection": "posix",
"username_attribute": "<uid>",
"membership_check": {
"enabled": true,
"member_uid_attribute": "<memberUid>"
},
"memberof_check": {
"enabled": true,
"memberof_user_attribute": "<memberOf>",
"memberof_group_objectclass": "<groupOfNames>"
},
"user_dn_in_groups": [
{
"object_class": "<groupOfNames>",
"attribute": "<member>"
},
{
"object_class": "<groupOfUniqueNames>",
"attribute": "<uniqueMember>"
}
]
},
"servers": [
{
"host": {
"selection": "fqdn",
"value": "<server-name>"
},
"port": <server-port>
}
],
"user_base_dn": "<basedn>",
"group_base_dn": "<basedn>",
"bind_dn": "<binddn>",
"bind_password": "<bind-password>",
"encryption": {
"client_authentication": {
"enabled": false
},
"selection": "ssl",
"server_certificate_check": {
"enabled": false
}
},
"publickey_attribute": "<sshPublicKey>",
"generated_publickey_attribute": null
}
Example: Configure a Microsoft Active Directory server with mutual authentication, and the verification of the server's X.509 certificate
{
"name": "<name-of-ldap-policy>",
"schema": {
"selection": "ad",
"membership_check": {
"enabled": true,
"nested_groups": false
},
"memberof_check": {
"enabled": true,
"memberof_user_attribute": "<memberOf>"
},
"user_dn_in_groups": [
{
"object_class": "<groupOfNames>",
"attribute": "<member>"
},
{
"object_class": "<groupOfUniqueNames>",
"attribute": "<uniqueMember>"
}
]
},
"servers": [
{
"host": {
"selection": "ip",
"value": "<server-ip>"
},
"port": <server-port>
}
],
"user_base_dn": "<basedn>",
"group_base_dn": "<basedn>",
"bind_dn": "<binddn>",
"bind_password": "<key-of-password>",
"encryption": {
"client_authentication": {
"enabled": true,
"x509_identity": "<key-of-cert>"
},
"selection": "starttls",
"server_certificate_check": {
"enabled": true,
"server_certificate_ca": "<ca-cert>"
}
},
"publickey_attribute": "<sshPublicKey>",
"generated_publickey_attribute": null
}
CA certificates
CA certificates must not contain any metadata. SPS uses only the key part of the certificate.
To use a certificate with the SPS API, remove all metadata, and substitute line breaks with \n.
The following is an example certificate, as used on the SPS web interface:
-----BEGIN CERTIFICATE-----
MIIDnDCCAoQCCQDc536Ob5tPQTANBgkqhkiG9w0BAQUFADCBjzELMAkGA1UEBhMC
Q0ExEDAOBgNVBAgTB09udGFyaW8xEDAOBgNVBAcTB1Rvcm9udG8xEDAOBgNVBAoT
B0JhbGFiaXQxFjAUBgNVBAsTDURvY3VtZW50YXRpb24xEDAOBgNVBAMTB2JhbGFi
aXQxIDAeBgkqhkiG9w0BCQEWEWNhdGFpbEBiYWxhYml0Lmh1MB4XDTE2MDQyMjE2
MDAyNloXDTE3MDQyMjE2MDAyNlowgY8xCzAJBgNVBAYTAkNBMRAwDgYDVQQIEwdP
bnRhcmlvMRAwDgYDVQQHEwdUb3JvbnRvMRAwDgYDVQQKEwdCYWxhYml0MRYwFAYD
VQQLEw1Eb2N1bWVudGF0aW9uMRAwDgYDVQQDEwdiYWxhYml0MSAwHgYJKoZIhvcN
AQkBFhFjYXRhaWxAYmFsYWJpdC5odTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCC
AQoCggEBAOGa9I2jmVlVdVWEI/Wy7ahTeyaIjK52FQUXqxG8okOSD+nV74ZFUuiS
59X+2Ow1aDqVGrDMgPNhSVpYXUvDUAUOILJW4rAIoxDY6vDU9/4v9dDiQfEPlauw
0qNRjPS1MLzjSOQDSKqPkdivkS6HKZeX3+TFq3OxO+vIrF9zFfp9T+eDG2oSobPc
3mV2zkvtD61CXzbezAVdArDl6WnysRyzxyH8WEhFwZepWxFD9Y5N1dzKody7Hncs
X5kVIv0+Z6bBHfg/7wHWysJdwNuLr0ByTOvPM6WdA83k3Fy2gYNk7Rc0BbRFbQTX
hJVfUzSUWHVhFQtAb4diKU5voqepfNMCAwEAATANBgkqhkiG9w0BAQUFAAOCAQEA
R5DIwOHsEKoGkiI3cHC2VMnxP2rRhpTneh6El+DFnQPdjrXa+tnqV4TdnNaD+FvP
AB1kqbmC4hJAsjMLU2b1ne6m+SLmzhRuMxcA6x+fnYvcQT57IbRdq2E/4oJGeyuy
0jQE+nmoVD3lDytIOxCfQvZhl1tcbBE5hp5USme4PmNhY6QfUlgjsFjPfoVG7XDB
uNaUoWS6RvZPmL5IuvF9tqe96ES6DTjC8rBfQYvSoVNjjPnUMx0C8xstRSEG7oJc
N5+4ImYnFNxSG20hZpFy0OFDf2g7Fx+W50/NtXamUF1Sf8WlPZc03oVl1/Fzo7mt
qYyyD1ld89OUEYZ+aJQd/A==
-----END CERTIFICATE-----
The same certificate, as accepted by the SPS API:
"certificate": "-----BEGIN CERTIFICATE-----\nMIIDnDCCAoQCCQDc536Ob5tPQTANBgkqhkiG9w0BAQUFADCBjzELMAkGA1UEBhMC\nQ0ExEDAOBgNVBAgTB09udGFyaW8xEDAOBgNVBAcTB1Rvcm9udG8xEDAOBgNVBAoT\nB0JhbGFiaXQxFjAUBgNVBAsTDURvY3VtZW50YXRpb24xEDAOBgNVBAMTB2JhbGFi\naXQxIDAeBgkqhkiG9w0BCQEWEWNhdGFpbEBiYWxhYml0Lmh1MB4XDTE2MDQyMjE2\nMDAyNloXDTE3MDQyMjE2MDAyNlowgY8xCzAJBgNVBAYTAkNBMRAwDgYDVQQIEwdP\nbnRhcmlvMRAwDgYDVQQHEwdUb3JvbnRvMRAwDgYDVQQKEwdCYWxhYml0MRYwFAYD\nVQQLEw1Eb2N1bWVudGF0aW9uMRAwDgYDVQQDEwdiYWxhYml0MSAwHgYJKoZIhvcN\nAQkBFhFjYXRhaWxAYmFsYWJpdC5odTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCC\nAQoCggEBAOGa9I2jmVlVdVWEI/Wy7ahTeyaIjK52FQUXqxG8okOSD+nV74ZFUuiS\n59X+2Ow1aDqVGrDMgPNhSVpYXUvDUAUOILJW4rAIoxDY6vDU9/4v9dDiQfEPlauw\n0qNRjPS1MLzjSOQDSKqPkdivkS6HKZeX3+TFq3OxO+vIrF9zFfp9T+eDG2oSobPc\n3mV2zkvtD61CXzbezAVdArDl6WnysRyzxyH8WEhFwZepWxFD9Y5N1dzKody7Hncs\nX5kVIv0+Z6bBHfg/7wHWysJdwNuLr0ByTOvPM6WdA83k3Fy2gYNk7Rc0BbRFbQTX\nhJVfUzSUWHVhFQtAb4diKU5voqepfNMCAwEAATANBgkqhkiG9w0BAQUFAAOCAQEA\nR5DIwOHsEKoGkiI3cHC2VMnxP2rRhpTneh6El+DFnQPdjrXa+tnqV4TdnNaD+FvP\nAB1kqbmC4hJAsjMLU2b1ne6m+SLmzhRuMxcA6x+fnYvcQT57IbRdq2E/4oJGeyuy\n0jQE+nmoVD3lDytIOxCfQvZhl1tcbBE5hp5USme4PmNhY6QfUlgjsFjPfoVG7XDB\nuNaUoWS6RvZPmL5IuvF9tqe96ES6DTjC8rBfQYvSoVNjjPnUMx0C8xstRSEG7oJc\nN5+4ImYnFNxSG20hZpFy0OFDf2g7Fx+W50/NtXamUF1Sf8WlPZc03oVl1/Fzo7mt\nqYyyD1ld89OUEYZ+aJQd/A==\n-----END CERTIFICATE-----\n"
Add an LDAP server
To add an LDAP server, you have to:
-
Create the JSON object for the new LDAP server.
POST the JSON object to the https://<IP-address-of-SPS>/api/configuration/policies/ldap_servers endpoint. You can find a detailed description of the available parameters listed in Element .
If the POST request is successful, the response includes the key of the new LDAP server. For example:
{
"key": "f9f9783c-1e28-4ce8-a650-fc4c7311ac52",
"meta": {
"href": "/api/configuration/policies/ldap_servers/f9f9783c-1e28-4ce8-a650-fc4c7311ac52",
"parent": "/api/configuration/policies/ldap_servers",
"transaction": "/api/transaction"
}
}
Modify an LDAP server
To modify the configuration of an LDAP server, you have to:
-
Modify the JSON object of the LDAP server.
PUT the modified JSON object to the https://<IP-address-of-SPS>/api/configuration/policies/ldap_servers/<key-of-the-object> endpoint. You can find a detailed description of the available parameters listed in Element .
201 |
Created |
The new resource was successfully created. |
400 |
InvalidQuery |
The requested filter or its value is invalid. |
401 |
Unauthenticated |
The requested resource cannot be retrieved because the client is not authenticated and the resource requires authorization to access it. The details section contains the path that was attempted to be accessed, but could not be retrieved. |
403 |
Unauthorized |
The requested resource cannot be retrieved because the client is not authorized to access it. The details section contains the path that was attempted to be accessed, but could not be retrieved. |
404 |
NotFound |
The requested object does not exist. |