Using Java SDK
The Kron PAM Java SDK provides a simple interface for integrating Kron PAM Vault’s credential retrieval and management functions directly into Java-based applications.
It enables applications to securely fetch dynamic credentials, interact with the PAM Vault, and maintain compliance with automated password rotation policies—without embedding static credentials in code.
The SDK uses gRPC for communication with the AAPM Agent and supports direct HTTP(S) communication with the Kron PAM server when the Agent is unavailable.
It is compatible with OpenJDK 8 or later and included with the Kron PAM Secrets Management Agent package or available as a standalone library (aapm-sdk-1.0.0.jar).
Key Features
- Secure retrieval of dynamic credentials without embedding passwords in code.
- Transparent integration with Kron PAM Vault for compliance with password rotation policies.
- Dual communication support:
- gRPC with AAPM Agent (preferred)
- HTTP(S) direct access to Kron PAM if Agent is offline
- Built-in error handling and response formatting via Response class.
Example Implementation
Below is an example test class demonstrating how to call the SDK and retrieve credentials dynamically.
package com.sample;
import com.kron.aapm.access.PasswordManager;
import com.kron.aapm.access.Response;
import com.kron.aapm.access.ValidResponseType;
public class ApplicationTest {
public static void main(String[] args) {
// Kron PAM Server Configuration
String serverAddress = "https://KRON_PAM_IP_ADDRESS";
String token = "7bbb10be-83d2-44e2-9a08-b0951deabfe5";
// Account and Vault Parameters
String accountName = "lstprdodb01";
String accountPath = "/Databases";
String comment = "Production DB password";
String passwdExpirationTime = "5";
boolean passwdChangeRequired = false;
boolean prettify = false;
ValidResponseType responseType = ValidResponseType.TEXT;
boolean showUsername = true;
// Secrets Management Agent Configuration (Optional)
String agentAddress = "AgentIPAddress";
int agentPort = 6396;
try {
// Initialize PasswordManager with Agent address and port
PasswordManager manager = PasswordManager.instance(agentAddress, agentPort);
// (Optional) Direct fallback to PAM server
manager.httpAddress(serverAddress);
// Retrieve credentials from Kron PAM Vault
Response passwdResponse = manager.getPassword(accountName, token, accountPath);
// Print the result
if (!passwdResponse.hasError()) {
System.out.println("Rpc response success = [" + passwdResponse.getValue() + "]");
} else {
System.out.println("Rpc response error = [" + passwdResponse.getErrValue() + "]");
}
} catch (Exception e) {
e.printStackTrace();
}
}
}
If using Maven, define your dependency as follows:
<dependency>
<groupId>com.kron.aapm</groupId>
<artifactId>aapm-sdk</artifactId>
<version>1.0.0</version>
</dependency>When executed successfully, the SDK retrieves the live credentials from the PAM Vault and returns them in the RPC response:
Rpc response success = [username: aioc, password: l1g3hs0J]
Process finished with exit code 0Configuration Parameters
Parameter | Description |
|---|---|
serverAddress | Kron PAM endpoint URL |
token | Kron PAM AAPM token assigned for account |
accountName | Account name registered in Kron PAM Vault |
accountPath | Account path within the Vault (e.g., /Databases/SharedAccouts, /Windows) |
comment | Optional descriptive comment for the fetching password |
passwdExpirationTime | Duration before password expiration (in minutes) |
passwdChangeRequired | Whether to force a new password rotation upon retrieval |
responseType | Format of the response (JSON or TEXT) |
prettify | Enables formatted response output |
showUsername | Include username in response (true/false) |
agentAddress | Kron PAM Secrets Management Agent IP Address (hostname) |
agentPort | Kron PAM Secrets Management Agent Port Number |