Adding Dynamic Accounts in Password Vault
authorized users can define the target devices’ users as password vault accounts when configuring a dynamic password vault account, kron pam establishes a connection to the target system and changes the old password with a random password generated by the password vault the new password is encrypted and stored on the kron pam database to add a dynamic account navigate to secrets > vault open the vault tab click + add button and select add account select the type (dynamic), configuration (type of the target system) kron pam has pre defined configurations for password vault, but any device configuration can be added from the configuration tab this is detailed in the upcoming sections account group name, owner of vault, enter account name, private, enable /disable duallock, and additional information (description, secret notes, additional info, and account tags) click next fill in the host (ip/name), change period , username , and password information the combo box change period is available on the vault definition screen, and the admins can specify when the passwords are to be changed if the change period type is selected as periodic, the change period (day) textbox appears, and the password change frequency information (in days) can be entered in that field if the user selects recurrent as the change period value, the recurrence unit combo box appears on the screen with the following choices day week month if the recurrence unit is week , then all days of the week appear on the screen, and the days on which the password needs change can be selected it is possible to select more than one day additionally, it is possible to define the time of day at which the password is desired to be changed from the starting time field if the recurrence unit is month , day of the month on which the password is to be changed needs to be selected after selecting the day of month value, it is also necessary to choose how many months need to go by before the next password change is triggered automatically private, change the period, owner, username, password, and configuration click save if a change period value is defined in the vault configurations screen , when the relevant configuration is selected in the vault account definition screen, the parameters defined in the config are shown on the screen and cannot be changed by the user the definitions made from the vault configurations screen have absolute priority if there is a change in the values on a vault configuration , the values of all vault accounts belonging to this configuration will be updated when the first password change job runs chiefly, if a change period value is defined in the vault configuration > miscellaneous > account level properties > change period when the relevant configuration is selected in the vault definition screen, this new account level properties change period parameter will be most dominant for new accounts and can’t be changed by users