Using Python SDK
The Kron PAM Python SDK provides a secure, programmatic interface for retrieving and managing privileged credentials directly from the Kron PAM Vault. It allows developers to dynamically access account passwords, ensuring that no static credentials are stored within code or configuration files.
The SDK communicates through the Kron PAM Secrets Manager Agent, providing encrypted and auditable credential delivery to applications and scripts.
It can be used in both Linux and Windows environments.
Example Implementation
Below is a sample Python script demonstrating how to retrieve credentials securely using the Kron PAM.
from password_manager import PasswordManager
import logging
def main():
account_name = "sshtest"
account_path = "/Linux SSH"
app_token = "5d8f14aa-efc4-48ea-a95d-285115fdad86"
agent_host = "AgentIPAddress:AgentPortAddress"
vault_url = "https://KronPAMIPAddress"
# Initialize the Password Manager
manager = PasswordManager(agent_host)
manager.httpAddress(vault_url)
try:
# Retrieve credentials
response = manager.getPassword(
pAccountName=account_name,
pAccountToken=app_token,
pAccountPath=account_path,
pComment="demo",
pPasswdExpirationTime="30",
pPasswordChangeRequired="false",
responseType="text/plain",
showUsername="false",
prettify="true",
tenantId=tenant_id
)
print("\n=== Password Retrieved ===")
print(f"Account Path: {account_path}")
print(f"Status: {response.status}")
print(f"Password: {response.value}")
except Exception as ex:
print("\n[Error] Unable to fetch password:", str(ex))
if __name__ == "__main__":
logging.basicConfig()
print("Starting password fetch process...\n")
main()Sample output
Starting password fetch process...
=== Password Retrieved ===
Account Path: /Linux SSH
Status: Success
Password: 9Hg2kLm3TFunction Reference
The getPassword() method retrieves the active password for a specified account from the Kron PAM Vault. It communicates securely through the configured Kron PAM Secrets Manager Agent and/or Kron PAM Vault, and then returns either a text or JSON response.
Method Definition
getPassword(
pAccountName,
pAccountToken,
pAccountPath,
pComment=None,
pPasswdExpirationTime=None,
pPasswordChangeRequired=False,
responseType="text/plain",
showUsername=False,
prettify=False,
tenantId=None
)Parameter Description
Parameter | Description |
|---|---|
pAccountName | Account name registered in Kron PAM Vault |
pAccountPath | Account path within the Vault (e.g., /Databases/SharedAccouts, /Windows) |
pAccountToken | Kron PAM AAPM token assigned for account |
pComment | Optional descriptive comment for the fetching password |
pPasswdExpirationTime | Duration before password expiration (in minutes) |
pPasswordChangeRequired | Whether to force a new password rotation upon retrieval |
responseType | Format of the response (JSON or TEXT) |
showUsername | Include username in response (true/false) |
prettify | Enables formatted response output |
tenantId | Specifies the tenant or logical domain when working in multi-tenant environments. Ensures credentials are retrieved from the correct scope. |
Initialization Explained
Before calling getPassword(), two key setup steps are required:
- PasswordManager(agent_host): Creates an SDK instance and establishes communication with the Kron PAM Secrets Manager Agent.
- manager.httpAddress(vault_url): Defines the HTTPS address of the Kron PAM Vault for credential retrieval.