Using .Net SDK
The Kron PAM .NET SDK allows developers to securely integrate Kron PAM Vault capabilities into .NET-based applications.
It enables runtime retrieval of privileged credentials, ensuring that applications, scripts, and services can authenticate dynamically without storing passwords locally or in configuration files.
The SDK is included with the Kron PAM Agent package or available as a standalone package. It supports the following framework versions:
- .NET Framework 4.7
- .NET 5.0
- .NET 6.0
- .NET 7.0
- .NET 8.0
The SDK is distributed with the Kron PAM Agent package or a seperated package.
Integration Steps
- Create or open your .NET project (e.g., Console App).
- Add the Kron PAM SDK references to the project.
- Include the SDK namespaces:
using aapm.sdk;
using Com.Kron.Aapm.Rpc;- Ensure the application has network access to the Kron PAM Secrets Management Agent and/or Kron PAM Password Vault
Example Implementation
Below is a sample test program demonstrating credential retrieval using the Kron PAM .NET SDK.
using aapm_sdk;
using Com.Kron.Aapm.Rpc;
String token = "6d8beac9-843c-41d1-8131-0cfc09fc4899";
String aName = "staticTestAccount";
String pathName = "/TestLinuxServers";
String serverAddress = "https://test.krontech.com";
String agentAddress = "http://10.20.30.40";
ushort agentPort = 6396;
try
{
Console.WriteLine("Application Started!");
var request = new AccessRequestValidTypes
{
AccountName = aName,
AccountToken = token,
AccountPath = pathName,
ResponseType = ValidResponseType.Json,
ShowUsername = true,
ApiVersion = "v2"
};
Console.WriteLine("Request Object created!");
// PasswordManager passwordManager = PasswordManager.Instance(agentAddress, agentPort);
// passwordManager.HttpAddress(serverAddress);
// PasswordManager passwordManager = PasswordManager.Instance(agentAddress, agentPort);
// passwordManager.DisableAgentSecureChannel();
// passwordManager.DisableInterceptorSecureRequest();
// passwordManager.IgnoreAgentCertificate();
// passwordManager.IgnoreInterceptorCertificate();
Response response = PasswordManager.Instance(agentAddress, agentPort)
.HttpAddress(serverAddress)
.DisableAgentSecureChannel()
// .DisableInterceptorSecureRequest()
//.IgnoreAgentCertificate()
.IgnoreInterceptorCertificate()
.GetPassword(request);
if (!response.HasError())
Console.WriteLine("Rpc response success = [" + response.GetValue() + "]");
else
Console.WriteLine("Rpc response error = [" + response.GetErrValue() + "]");
}
catch (Exception e)
{
Console.WriteLine(e);
throw;
}When executed successfully, the SDK returns live credentials from the Kron PAM Vault:
Rpc response success = [username: aioc, password: Xhg2Vm3T]
Process finished with exit code 0Configuration Parameters
Parameter | Definition |
|---|---|
serverAddress | Kron PAM Vault endpoint URL |
token | Kron PAM AAPM token assigned for account |
AccountName | Account name registered in Kron PAM Vault |
AccountPath | Account path within the Vault (e.g., /Databases/SharedAccouts, /Windows) |
Comment | Optional descriptive comment for the fetching password |
ShowUsername | Include username in response (true/false) |
PasswordExpirationTime | Duration before password expiration (in minutes) |
PasswordChangeRequired | Whether to force a new password rotation upon retrieval |
Prettify | Enables formatted response output |
ResponseType | Format of the response (Text, Json) |
agentAddress | Kron PAM Secrets Management Agent IP Address (hostname) |
agentPort | Kron PAM Secrets Management Agent Port Number |
ApiVersion | Ensures that the AAPM Agent returns a response in the same format as Kron PAM for static credential types (default value v2) |
DisableAgentSecureChannel | Ignores connection errors when using a Self-signed certificate for the AAPM Agent |
DisableInterceptorSecureRequest | Ignores connection errors when using a Self-signed certificate defined on Kron PAM |
IgnoreAgentCertificate | Parameter required for using the AAPM Agent without a certificate (Not Recommended) |
IgnoreInterceptorCertificate | Parameter required for using Kron PAM without a certificate (Not Recommended) |