Veritas Appliance Guide for CyberArk Plugin Configuration

Last Published:
Product(s): Appliances (6.0, 5.5.0.1, 5.3, 5.1.1, 5.1, 5.0, 4.2, 4.1, 4.0, 3.3.0.1, 3.3, 3.2, 3.1, 3.0)
Platform: NetBackup Appliance OS,Flex Appliance OS

Veritas Flex Appliance Console PSM

The Veritas Flex Appliance Console PSM is a CyberArk plugin component. The plugin enables you to initiate, monitor, and record privileged login sessions, and usage of administrative and user accounts for the web user passwords that are stored in a CyberArk password vault. A Remote Desktop connection starts up in Windows and records the entire session.

Requirements and prerequisites

The following describes the requirements and tasks that you must perform before you can configure the plugin:

Architecture

The PSM uses the password from a vault for the user logons. A Remote Desktop Session is invoked to log in. The login is fully automatic as it matches the form elements in the Web UI login and then clicks on Login. The architecture uses the standard CyberArk architecture where it records the sessions that are stored in the vault.

Configuration

After you have downloaded and installed the plugin, perform the following configuration steps in the application on the CyberArk site.

To configure the plugin for a Flex Appliance with a configured web interface

  1. Log in to the CyberArk PVWA and verify that the Record and save session activity is Active, as follows:
    • After logging in, on the left side of the main page, click the Policies icon, then click Policies > Master Policy.

    • In the Master Policy window, click the arrow next to Session Management to expand it and verify that Record and save session activity is Active.

    • If it is not active, on the lower right of the window, click Edit Settings and change it to Active.

  2. Verify that the IP address of the PSM server you want to connect to is correct, as follows:
    • On the left side of the main page, click the Administration icon, then click Configuration Options > Options.

    • In the left column of the Options window, expand Privileged Session Management > Configured PSM Servers > Connection Details > Servers to verify the IP address.

  3. Set the EnforceCertificateValidation option to No, as follows:
    • In the left column of the Options window, expand Connection Components.

    • Scroll down and expand PSM-VeritasFlexApplianceWeb > Target Settings > Web Form Settings .

    • In the Properties section, in the Value column, set EnforceCertificateValidation to No, then click Apply.

  4. Add the ID value of PSM-VeritasFlexApplianceWeb as a connection component, as follows:
    • In the left column of the Options window, scroll down and click PSM-VeritasFlexApplianceWeb.

    • In the Properties section, in the first row for the ID, click and drag to highlight the ID in the Value column, then right-click and select Copy.

    • On the left side of the main page, click the Administration icon, then click Platform Management > Veritas Flex Appliance API Via REST > Edit.

    • Click on the following elements in the order as shown:

      Right click on UI & Workflows and select Add Privileged Session Management.

      Right click again on UI & Workflows and select Add Connection Components.

      Right click on Connection Components and select Add Connection Component.

      Paste the ID content, then click Apply and OK.

  5. Restart the Cyber-Ark Privileged Session Manager as follows:

    Navigate to Services [Local], right-click on Cyber-Ark Privileged Session Manager and select Restart.