Veritas Appliance Guide for CyberArk Plugin Configuration

Last Published:
Product(s): Appliances (6.0, 5.5.0.1, 5.3, 5.1.1, 5.1, 5.0, 4.2, 4.1, 4.0, 3.3.0.1, 3.3, 3.2, 3.1, 3.0)
Platform: NetBackup Appliance OS,Flex Appliance OS

Veritas Flex Appliance Console CPM (GEN1)

[Updated plugin; version 1.5]

The Veritas Flex Appliance Console CPM (GEN1) plugin is a CyberArk component. The plugin integrates the Flex Appliance web user interface with CyberArk and lets you manage the Flex Appliance Web Console administrator accounts. It includes the default administrator account along with other configured administrator user accounts with the Web console. The plugin enables the automation to secure privileged access by storing and retrieving privileged Flex admin accounts in the CyberArk password vault.

Note:

This GEN1 plugin version is compatible only with Flex Appliance software versions 3.x and 4.x. If you have upgraded a Flex Appliance to version 5.x or later that currently uses this GEN1 plugin version, you must also upgrade the plugin to the GEN2 version. For plugin upgrade details, see the following topic: Veritas Flex Appliance Console CPM GEN2

The following describes the supported plugin functionality:

  • Change the administrator account password.

  • Verify the administrator account password.

  • Limitations:

    • Reconciliation is not supported.

Requirements and prerequisites

The following describes the requirements and tasks that you must perform before you can configure the plugin:

Configuration

After you have downloaded and installed the plugin, perform the following configuration steps in the application on the CyberArk site.

To configure the plugin for a Flex Appliance administrator account

  1. Log in to the CyberArk PVWA.
  2. On the Account View page, click Add account and do the following:
    • For Select system type, click Imported platforms.

    • For Assign to platform, click Veritas Flex Appliance Console CPM GEN1.

    • For Store in safe, select where you want to store the configuration. You can also click Create Safe to create a new one.

    • For Define properties, enter the following:

      • Address: Enter the Flex Appliance fully qualified domain name.

      • Username: Enter the Flex Appliance administrator account username.

      • Password: Enter the associated password for the entered Flex Appliance administrator account username.

  3. For Flex Appliance configurations, add a second user account as described in step 2 as follows:
    • For appliances with software versions 3.x, you must add the default administrator user account.

    • For appliances with software versions 4.x, you must add a security administrator user account.

  4. After adding the second account, associate it with the first account that you added in step 2 as follows:
    • In the left column on the Accounts View page, select the Username that you first added in step 2, then on the right side of the page click Additional details & actions in classic interface.

    • When the Associate Account dialog appears, select the second user account that you created and click Associate to link it with the first user account.

The plugin is designed for use with an SSL certificate. If the target appliance uses a self-signed certificate, you must reconfigure the plugin to use that certificate type as follows:

To reconfigure the plugin to use a self-signed certificate

  1. Log in to the CyberArk PVWA.
  2. Navigate to the Platform Management page and do the following:
    • Click the platform named Veritas Flex Appliance API via REST.

    • On the lower right side, click Edit.

    • In the left column, expand Automatic Password Management and click Additional Policy Settings.

    • In the Properties column, click Use SSL. Then, in the Value column, right-click on Yes and select IgnoreUntrustedCertificate.