A custom platform script identifies the platform's commands and associated details. Scripts are written in JSON. Scripts include meta-data, parameters, function blocks, operations, and if/then constructs to authenticate to the platform and perform password validation and reset. The custom platform script is uploaded when adding the custom platform.
You can create an asset and accept default values in the associated custom script. If you later upload a new version of the custom platform script with different defaults, the asset defaults are not changed.
Sample custom platform scripts and command details are available at the following links available from the on GitHub:
|
CAUTION: Example scripts are provided for information only. Updates, error checking, and testing are required before using them in production. Safeguard for Privileged Passwords checks to ensure the values match the type of the property which include: a string, boolean, integer, or password (which is called secret in the API scripts). Safeguard for Privileged Passwords cannot check the validity or system impact of values entered for custom platforms. |
During development, check your JSON using a validator.
It is the responsibility of the Asset Administrator to configure the rules so Safeguard for Privileged Passwords handles custom platforms. The custom platform script must be available for uploading. For more information, see Creating a custom platform script.
To add a custom platform
Platform Script: Click Browse. Navigate to and select the script file. Click Open. The selected custom platform script file displays.
Asset Administrators can define rules that will dynamically add tags to assets and asset accounts so that they can be easily identified and added to dynamic groups. Use the Administrative Tools | Settings | Asset Management | Tags pane to create and manage dynamic tags for assets and asset accounts.
In addition, Asset Administrators can manually add static tags to assets and accounts on the General tab of the Assets or Accounts view. For more information, see Manually adding a tag to an asset and Manually adding a tag to an account.
The Tags pane provides a centralized view of all the tags defined for assets and asset accounts, regardless of how they were assigned. It displays the following details.
Property | Description |
---|---|
Name |
The name assigned to the tag when it was created. |
Asset Partition |
The asset partition to which the tag belongs. |
Rules |
Indicates whether there is a rule associated with the selected tag. A check mark in this column indicates that the tag has an asset or asset account rule. |
Description |
Information about the tag. |
Use these toolbar buttons to manage tags.
Option | Description | ||
---|---|---|---|
|
Add a dynamic tag. For more information, see Adding a tag for dynamic tagging of assets or asset accounts. | ||
|
Remove the selected tag. For more information, see Deleting an asset or asset account tag. | ||
|
Update the list of tags. | ||
|
Modify the selected tag. For more information, see Modifying an asset or asset account tag.
| ||
|
Clone the selected tag and assign it to one or more additional partitions. For more information, see Copying an asset or asset account tag to another partition.
| ||
|
View a list of assets and asset accounts that are assigned to the selected tag. For more information, see Viewing asset and asset account tag assignments. | ||
Search |
Search for a specific tag or set of tags in this list. |
When does the rules engine run for dynamic grouping and tagging
Use the New button on the Tags pane in the Asset Management settings page to add a dynamic tag for an asset or asset account.
To add an asset or asset account dynamic tag
Click the New toolbar button.
The Tag dialog displays.
On the General tab, enter the following information:
On the Account Rules tab, enter the conditions for an account rule.
Rule editor: Use the rule editor to define conditions for tagging asset accounts.
Property | Description |
---|---|
AND | OR |
Click AND to "and" multiple search criteria together; where all criteria must be met in order to be included. Click OR to "or" multiple search criteria together; where at least one of the criteria must be met in order to be included. |
Attribute |
In the first query clause box, select the attribute to be searched. Valid attributes include:
|
Operator |
In the middle clause query box, select the operator to be used in the search. The operators available depend upon the data type of the attribute selected. For string attributes, the operators may include:
For boolean attributes, the operators may include:
|
Search string |
In the last clause query box, enter the search string or value to be used to find a match. |
|
Click Click |
Add Grouping | Remove |
Click the A new grouping is added under the last query clause in a group and appears in a bordered pane showing that it is subordinate to the higher level query conditions. Click the Remove button to remove a grouping from the search criteria. |
Preview |
Click Preview to run the query in order to review the results of the query before adding the dynamic tag. |
On the Asset Rules tab, enter the conditions for an asset rule.
Rule editor: Use the rule editor to define conditions for tagging assets.
Property | Description |
---|---|
AND | OR |
Click AND to "and" multiple search criteria together; where all criteria must be met in order to be included. Click OR to "or" multiple search criteria together; where at least one of the criteria must be met in order to be included. |
Attribute |
In the first query clause box, select the attribute to be searched. Valid attributes include:
|
Operator |
In the middle clause query box, select the operator to be used in the search. The operators available depend upon the data type of the attribute selected. For string attributes, the operators may include:
For boolean attributes, the operators may include:
|
Search string |
In the last clause query box, enter the search string or value to be used to find a match. |
|
Click Click |
Add Grouping | Remove |
Click the Add Grouping button to add an additional set of conditions to be met. A new grouping is added under the last query clause in a group and appears in a bordered pane showing that it is subordinate to the higher level query conditions. Click the Remove button to remove a grouping from the search criteria. |
Preview |
Click Preview to run the query in order to review the results of the query before adding the dynamic tag. |
On the Summary tab, review your selections.
© 2021 One Identity LLC. ALL RIGHTS RESERVED. Feedback Terms of Use Privacy