Safeguard for Privileged Passwords supports SonicOS Internet appliances. Safeguard for Privileged Passwords uses the SSH protocol to connect to SonicOS devices.
To prepare a SonicOS device for Safeguard for Privileged Passwords
Add the service account to the SonicWALL Administrators group. This allows the service account to access the device with SSH to manage users.
|
Important: Safeguard for Privileged Passwords can only manage passwords for users that are members of the SonicWALL Administrators group. |
Here are some important notes about configuring a SonicWALL SMA or CMS appliance for Safeguard for Privileged Passwords:
To prepare a Microsoft SQL Server for Safeguard for Privileged Passwords, refer to the documentation for your SQL server for information about how to setup and secure encryption.
To enable SSL server certificate validation, add the server’s signing authority certificate to the Trusted Certificates store in Safeguard for Privileged Passwords. For more information, see Trusted Certificates.
For more information about how Safeguard for Privileged Passwords database servers use SSL, see How do Safeguard for Privileged Passwords database servers use SSL.
To configure a SQL Server for Safeguard for Privileged Passwords (with an authentication type of Local System Account)
|
NOTE: To manage a Microsoft SQL server asset with the authentication type of Local System Account, you need a local Windows account that is a Security Admin in SQL. In order to use this authentication type, you must add a Windows asset and an SQL Server asset to Safeguard for Privileged Passwords. |
Add other accounts as needed.
Save the asset.
On the Connection tab,
Service Account: Click Select Account and select a local system account from the list.
The accounts available for selection are Windows accounts that are linked to the Windows asset you added in Step 3.
Save the asset.
To configure a SQL Server for Safeguard for Privileged Passwords (with an authentication type of Directory Account)
|
NOTE: To mange a Microsoft SQL asset with the authentication type of Directory Account, you need a domain account that is a Security Admin in SQL. In order to use this authentication type, you must add a directory and directory users to Safeguard for Privileged Passwords. |
On the Connection tab, complete the following:
Service Account: Click Select Account and select a domain user account from the list.
The accounts available for selection are domain user accounts that are linked to the directory you added in Step 1.
Save the asset.
Safeguard for Privileged Passwords can manage authorized Top Secret users who have a valid accessor ID (ACID) with the facility ‘TSO’ who can log on to the TSO interface.
This applies to both Top Secret- Mainframe and Top Secret - Mainframe LDAP platforms.
To prepare CA Top Secret mainframe systems for Safeguard for Privileged Passwords
|
Note: Please refer to your IBM z/OS system documentation for details on installing and configuring the telnet server (and SSL). |
Safeguard for Privileged Passwords automatically accepts any server certificate that the connection offers and does not verify the trust chain on the telnet certificate. In addition, Safeguard for Privileged Passwords does not support client certificate selection so if telnet requires that the client present a certificate that is signed by a recognized authority, Safeguard for Privileged Passwords cannot support that configuration.
© 2021 One Identity LLC. ALL RIGHTS RESERVED. Feedback Terms of Use Privacy