Kron PAM Server Configuration
1.   Update the CORS configuration in web.xml:
Linux CLI | [root@pam~]# sudo vi /pam/gui/conf/web.xml |
|---|
2.   Locate and update the following lines:
Linux CLI | /cors … <param-name>cors.allowed.origins</param-name> <param-value> {RAP URL} e.g., https://remote.cloudpam.com</param-value> … |
|---|
Using the * wildcard allows all access, but is not recommended for production environments.
3.   Set the necessary and optional parameters to configure the Kron PAM Remote Privileged Access Management. The following parameters are defined on the System Config Man. screen of the Kron PAM Web GUI.
The necessary parameter:
Parameter Name | Default Parameter Value | Description |
|---|---|---|
rap.cloud.server | http://localhost:7777/connect | This parameter defines the Remote Access Portal (RAP) address. The parameter can be defined as URL with IP (e.g., https://34.234.69.53/connect) or as URL with domain name (e.g., https://cloudpam.com/connect) |

Optional parameters:
Parameter Name | Default Parameter Value | Description |
|---|---|---|
rap.rdp.session.duration.limit.warning.before.min | 1 | This parameter defines how many minutes before the RDP session expires that the timeout warning will be sent. |
rap.ssh.session.duration.limit.warning.before.min | 1 | This parameter defines how many minutes before the SSH session expires that the timeout warning will be sent. |
rap.http.session.duration.limit.warning.before.min | 1 | This parameter defines how many minutes before the HTTP container session expires that the timeout warning will be sent. |
rap.token.expiration.period | 1 | This parameter indicates the lifespan of a token and is used to prevent the creation of long-term invitation links. |
rap.client.otp.enabled | false | This parameter defines whether the MFA feature is used during the login process of Remote Privileged Access Management. |
rap.passcode.characters.count | 8 | This parameter shows how many characters are used in the passcode definition. This parameter's value should be numeric, and the default value is 8. If the system admin defines this parameter as 4 or fewer, the passcode is created with 4 characters. |
rap.passcode.only.numeric.text | false | This parameter's value should be a boolean, and the default value is false. If this parameter's value is set as true, the passcode only contains numeric values; however, if this parameter's value is set as false, the passcode contains alphanumeric values. |
Optional parameters for SMS feature in Kron PAM Remote Privileged Access Management:
Parameter Name | Example Parameter Value | Description |
|---|---|---|
rap.sms.http.url | https://api.XXXXXXX.com/v1/send-sms | This parameter defines the URL of SMS service that is used to send SMS via HTTP for Kron PAM Remote Privileged Access Management tokens. |
rap.sms.http.body | <request><authentication><username>11111111</username><password>2222222</password></authentication><order><sender>KRON</sender><sendDateTime></sendDateTime><message><text> <![CDATA[Dear %userEid%, Please use the passcode below during login phase of your Kron PAM Remote Privileged Access Management connection. Passcode: %passcode% Kron PAM Remote Privileged Access Management Connection (Access On Web Browser): %connURL%]]> </text><receipents><number>%phoneNumber%</number></receipents></message></order></request> | This parameter defines the SMS message content using HTTP protocol for Kron PAM Remote Privileged Access Management tokens. |
rap.sms.smpp.body (Alternative to the previous parameter) | {example SMPP body} | This parameter defines the SMS message content when using the SMPP protocol for Kron PAM Remote Privileged Access Management tokens. |
rap.sms.http.headers | Content-Type:text/xml | This parameter defines the headers that are included in the SMS for Kron PAM Remote Privileged Access Management tokens. |
rap.sms.http.encoding | UTF-8 | This parameter defines a character encoding used in the SMS for Kron PAM Remote Privileged Access Management tokens. |
rap.sms.http.method | POST OR GET | This parameter defines the HTTP method used in SMS for Kron PAM Remote Privileged Access Management tokens. |
rap.sms.http.delimiter | & | This parameter defines the delimiter character used in the SMS for Kron PAM Remote Privileged Access Management tokens. |
rap.sms.channel | http OR smpp | This parameter defines the SMS channel typefor Kron PAM Remote Privileged Access Management tokens. |
4.   Set the users to have at least the following portal functions in order to list devices on the Remote Access Portal and make sessions through them:
-Â Â Â Â Â Â single.connect.rdp.client.moduleVisibility
-Â Â Â Â Â Â single.connect.cli.moduleVisibility
-Â Â Â Â Â Â remote.access.config.moduleVisibility
-Â Â Â Â Â Â desktop.device.group.moduleVisibility (not required for Remote Privileged Access Management, but it is needed if the user lists the devices on the Kron PAM GUI or Desktop Client.)