Using .Net SDK
The Kron PAM .NET SDK allows developers to securely integrate Kron PAM Vault capabilities into .NET-based applications.
It enables runtime retrieval of privileged credentials, ensuring that applications, scripts, and services can authenticate dynamically without storing passwords locally or in configuration files.
The SDK is included with the Kron PAM Agent package or available as a standalone package. It supports the following framework versions:
- .NET Framework 4.7
- .NET 5.0
- .NET 6.0
- .NET 7.0
- .NET 8.0
The SDK is distributed with the Kron PAM Agent package or a seperated package.
Integration Steps
- Create or open your .NET project (e.g., Console App).
- Add the Kron PAM SDK references to the project.
- Include the SDK namespaces:
using aapm.sdk;
using Com.Kron.Aapm.Rpc;- Ensure the application has network access to the Kron PAM Secrets Management Agent and/or Kron PAM Password Vault
Example Implementation
Below is a sample test program demonstrating credential retrieval using the Kron PAM .NET SDK.
using System;
using aapm.sdk;
using Com.Kron.Aapm.Rpc;
namespace agent5
{
class Program
{
static void Main(string[] args)
{
// Vault and Agent Configuration
string token = "11cd0f62-56fb-4159-aa01-4c7194f79e16";
string aName = "lstprdodb01";
string pathName = "/Databases";
string serverAddress = "https://KRON_PAM_IP_ADDRESS/";
string agentAddress = "AgentIPAddress";
ushort agentPort = 6396;
// Define request
var request = new AccessRequestValidTypes
{
AccountName = aName,
AccountToken = token,
AccountPath = pathName,
ResponseType = ValidResponseType.Text,
ShowUsername = false,
Prettify = true,
PasswordExpirationTime = "30",
PasswordChangeRequired = false
};
// Example output
// Rpc response success = [username: aioc, password: Xhg2Vm3T]
}
}
}When executed successfully, the SDK returns live credentials from the Kron PAM Vault:
Rpc response success = [username: aioc, password: Xhg2Vm3T]
Process finished with exit code 0Configuration Parameters
Parameter | Definition |
|---|---|
serverAddress | Kron PAM Vault endpoint URL |
token | Kron PAM AAPM token assigned for account |
AccountName | Account name registered in Kron PAM Vault |
AccountPath | Account path within the Vault (e.g., /Databases/SharedAccouts, /Windows) |
Comment | Optional descriptive comment for the fetching password |
ShowUsername | Include username in response (true/false) |
PasswordExpirationTime | Duration before password expiration (in minutes) |
PasswordChangeRequired | Whether to force a new password rotation upon retrieval |
Prettify | Enables formatted response output |
ResponseType | Format of the response (Text, Json) |
agentAddress | Kron PAM Secrets Management Agent IP Address (hostname) |
agentPort | Kron PAM Secrets Management Agent Port Number |