Using Python SDK
The Kron PAM Python SDK provides a secure, programmatic interface for retrieving and managing privileged credentials directly from the Kron PAM Vault. It allows developers to dynamically access account passwords, ensuring that no static credentials are stored within code or configuration files.
The SDK communicates through the Kron PAM Secrets Manager Agent, providing encrypted and auditable credential delivery to applications and scripts.
It can be used in both Linux and Windows environments.
Example Implementation
Below is a sample Python script demonstrating how to retrieve credentials securely using the Kron PAM.
from __future__ import print_function
import logging
import time
from aapm_python_sdk import PasswordManager
def run():
for i in range(1):
pamUrl = "https://test.krontech.com"
agentHost = "10.20.30.40"
agentPort = 6396
agentAddess = f"{agentHost}:{agentPort}"
manager = PasswordManager(agentAddess)
manager.httpAddress(pamUrl)
manager.enable_debug(True)
# manager.ignore_agent_certificate()
manager.ignore_interceptor_certificate()
manager.disable_agent_certificate()
response = manager.getPassword(
'staticTestAccount',
'6d8beac9-843c-41d1-8131-0cfc09fc4899',
'/TestLinuxServers',
responseType="text",
showUsername="true",
)
print(f"[{i+1}] rpc client received: [{response.value}] [{response.status}]")
if __name__ == '__main__':
logging.basicConfig()
print("Request started...")
run()
Sample output
Starting password fetch process...
=== Password Retrieved ===
Account Path: /TestLinuxServers
Status: Success
Password: 9Hg2kLm3TFunction Reference
The getPassword() method retrieves the active password for a specified account from the Kron PAM Vault. It communicates securely through the configured Kron PAM Secrets Manager Agent and/or Kron PAM Vault, and then returns either a text or JSON response.
Method Definition
getPassword(
pAccountName,
pAccountToken,
pAccountPath,
pComment=None,
pPasswdExpirationTime=None,
pPasswordChangeRequired=False,
responseType="text/plain",
showUsername=False,
prettify=False,
tenantId=None
)Parameter Description
Parameter | Description |
|---|---|
pAccountName | Account name registered in Kron PAM Vault |
pAccountPath | Account path within the Vault (e.g., /Databases/SharedAccouts, /Windows) |
pAccountToken | Kron PAM AAPM token assigned for account |
pComment | Optional descriptive comment for the fetching password |
pPasswdExpirationTime | Duration before password expiration (in minutes) |
pPasswordChangeRequired | Whether to force a new password rotation upon retrieval |
responseType | Format of the response (JSON or TEXT) |
showUsername | Include username in response (true/false) |
prettify | Enables formatted response output |
tenantId | Specifies the tenant or logical domain when working in multi-tenant environments. Ensures credentials are retrieved from the correct scope. |
enable_debug(True) | Enables debug logs for Python SDK usage. |
apiVersion | Ensures that the AAPM Agent returns a response in the same format as Kron PAM for static credential types (default value v2) |
ignore_agent_certificate | Ignores connection errors when using a Self-signed certificate for the AAPM Agent |
ignore_interceptor_certificate | Ignores connection errors when using a Self-signed certificate defined on Kron PAM |
disable_agent_certificate | Parameter required for using the AAPM Agent without a certificate (Not Recommended) |
disable_interceptor_certificate | Parameter required for using Kron PAM without a certificate (Not Recommended) |
Initialization Explained
Before calling getPassword(), two key setup steps are required:
- PasswordManager(agent_host): Creates an SDK instance and establishes communication with the Kron PAM Secrets Manager Agent.
- manager.httpAddress(vault_url): Defines the HTTPS address of the Kron PAM Vault for credential retrieval.