Using C++ SDK
This guide explains how to integrate the Kron PAM C++ SDK into your application, configure the client, and retrieve secrets programmatically. The example below demonstrates a minimal working pattern for requesting a password from the Kron PAM Password Vault.
Example Implementation
Below is a complete example demonstrating password retrieval.
#include "pch.h"
#include <string>
#include <iostream>
#include "password_manager.h"
using namespace winrt;
using namespace Windows::Foundation;
class AccessServiceClient {
public:
AccessServiceClient() : manager(PasswordManager::instance("10.20.30.40", 6396)) {
manager.setScAddress("https://test.krontech.com");
}
Response* sendRequest() {
AccessRequestBuilder builder("staticTestAccount", "6d8beac9-843c-41d1-8131-0cfc09fc4899", "/TestLinuxServers");
builder.setComment("try to see the comment").setShowUserName("true").setapiVersion("v2").setResponseType("json");
return manager.getPassword(&builder);
}
private:
PasswordManager manager;
};
void Run() {
std::cout << "Getting Password..." << std::endl;
std::cout.flush();
AccessServiceClient client;
Response* response = client.sendRequest();
if (response->hasError()) {
std::cout << "rpc error response [" << response->getErrValue() << "]" << std::endl;
std::cout.flush();
}
else {
std::cout << "rpc ss response [" << response->getValue() << "]" << std::endl;
std::cout.flush();
}
}
int main(int argc, char* argv[]) {
Run();
std::cout.flush();
return 0;
}
Configuration Parameters
Parameter | Definition |
|---|---|
setScAddress | Kron PAM Vault endpoint URL |
instance | AAPM Agent Address |
token | Kron PAM AAPM token assigned for account |
setAccountName | Account name registered in Kron PAM Vault |
setAccountPath | Account path within the Vault (e.g., /Databases/SharedAccouts, /Windows) |
setComment | Optional descriptive comment for the fetching password |
setShowUserName | Include username in response (true/false) |
PasswordExpirationTime | Duration before password expiration (in minutes) |
PasswordChangeRequired | Whether to force a new password rotation upon retrieval |
Prettify | Enables formatted response output |
setResponseType | Format of the response (Text, Json) |
agentAddress | Kron PAM Secrets Management Agent IP Address (hostname) |
agentPort | Kron PAM Secrets Management Agent Port Number |
setapiVersion | Ensures that the AAPM Agent returns a response in the same format as Kron PAM for static credential types (default value v2) |
DisableAgentSecureChannel | Ignores connection errors when using a Self-signed certificate for the AAPM Agent |
DisableInterceptorSecureRequest | Ignores connection errors when using a Self-signed certificate defined on Kron PAM |
IgnoreAgentCertificate | Parameter required for using the AAPM Agent without a certificate (Not Recommended) |
IgnoreInterceptorCertificate | Parameter required for using Kron PAM without a certificate (Not Recommended) |