Using Java SDK
The Kron PAM Java SDK provides a simple interface for integrating Kron PAM Vault’s credential retrieval and management functions directly into Java-based applications.
It enables applications to securely fetch dynamic credentials, interact with the PAM Vault, and maintain compliance with automated password rotation policies—without embedding static credentials in code.
The SDK uses gRPC for communication with the AAPM Agent and supports direct HTTP(S) communication with the Kron PAM server when the Agent is unavailable.
It is compatible with OpenJDK 8 or later and included with the Kron PAM Secrets Management Agent package or available as a standalone library (aapm-sdk-1.0.0.jar).
Key Features
- Secure retrieval of dynamic credentials without embedding passwords in code.
- Transparent integration with Kron PAM Vault for compliance with password rotation policies.
- Dual communication support:
- gRPC with AAPM Agent (preferred)
- HTTP(S) direct access to Kron PAM if Agent is offline
- Built-in error handling and response formatting via Response class.
Example Implementation
Below is an example test class demonstrating how to call the SDK and retrieve credentials dynamically.
package org.example;
import com.kron.aapm.access.PasswordManager;
import com.kron.aapm.access.Response;
import com.kron.aapm.rpc.AccessRequestValidTypes;
import com.kron.aapm.rpc.ValidResponseType;
import java.util.HashMap;
import java.util.Map;
public class Main {
public static void main(String[] args) {
String pamUrl = "https://test.krontech.com";
String agentHost = "10.20.30.40";
Integer agentPort = 6396;
String accountToken = "6d8beac9-843c-41d1-8131-0cfc09fc4899";
String accountName = "dynamicTestAccount";
String accountPath = "/TestServers";
Map<String, String> account = new HashMap<>();
account.put("token", accountToken);
account.put("name", accountName);
account.put("path", accountPath);
PasswordManager passwordManager = PasswordManager.instance(agentHost, agentPort);
passwordManager.httpAddress(pamUrl);
Response response = makeRequest(passwordManager, account);
if (!response.hasError()) {
System.out.println("Response Value: " + response.getValue());
} else {
System.out.println("Error Value: " + response.getErrValue());
}
}
private static Response makeRequest(PasswordManager passwordManager, Map<String, String> account) {
String accountToken = account.get("token");
String accountName = account.get("name");
String accountPath = account.get("path");
AccessRequestValidTypes request = AccessRequestValidTypes.newBuilder()
.setAccountName(accountName)
.setAccountToken(accountToken)
.setAccountPath(accountPath)
.setResponseType(ValidResponseType.TEXT)
.setShowUsername(false)
.setApiVersion("v2")
.setPasswordChangeRequired(true)
.setPasswdExpirationTime("5")
.build();
return passwordManager.getPassword(request);
}
}
If using Maven, define your dependency as follows:
<dependency>
<groupId>com.kron.aapm</groupId>
<artifactId>aapm-sdk</artifactId>
<version>1.0.0</version>
</dependency>When executed successfully, the SDK retrieves the live credentials from the PAM Vault and returns them in the RPC response:
Rpc response success = [username: aioc, password: l1g3hs0J]
Process finished with exit code 0Configuration Parameters
Parameter | Description |
|---|---|
serverAddress | Kron PAM endpoint URL |
token | Kron PAM AAPM token assigned for account |
accountName | Account name registered in Kron PAM Vault |
accountPath | Account path within the Vault (e.g., /Databases/SharedAccouts, /Windows) |
comment | Optional descriptive comment for the fetching password |
passwdExpirationTime | Duration before password expiration (in minutes) |
passwdChangeRequired | Whether to force a new password rotation upon retrieval (true/false) |
responseType | Format of the response (JSON or TEXT) |
prettify | Enables formatted response output |
setApiVersion | Ensures that the AAPM Agent returns a response in the same format as Kron PAM for static credential types (default value v2) |
showUsername | Include username in response (true/false) |
agentAddress | Kron PAM Secrets Management Agent IP Address (hostname) |
agentPort | Kron PAM Secrets Management Agent Port Number |
ignoreAgentCertificate | Ignores connection errors when using a Self-signed certificate for the AAPM Agent (true/false) |
ignoreInterceptorCertificate | Ignores connection errors when using a Self-signed certificate defined on Kron PAM (true/false) |
disableAgentSecureChannel | Parameter required for using the AAPM Agent without a certificate (Not Recommended) (true/false) |
disableInterceptorSecureRequest | Parameter required for using Kron PAM without a certificate (Not Recommended) (true/false) |