Running Scripts at The Beginning of an SSH Session
In some use cases, running automated commands at the beginning of the SSH session may be necessary.
To give an example of one of these scenarios, the end user may be requested to use an account with restricted access to start an SSH session. In this case, a privilege escalation script can be written using the auth-script feature.
Thanks to this, even if that particular account isn't allowed to reach the device with SSH protocol, the user will be able to connect to the device with another account's credentials in the background (via global username or a Vault credential). As a result, the user will be able to use the restricted account's privileged commands on that device through the SSH protocol.
To use this feature, an authScript property key should be configured at the Device Group level, and the defined script runs on the target SSH device at the beginning of the user's SSH session:
In authScript, 2 new parameters have been added so that the user and password of the user connected to the device can be used.
These parameters are:
- connectedUserName
- connectedUserPassword
For this authScript that is executed when connected to the device, a switch called Show Without authScript Option has been added to the Device Group Options - Miscellaneous panel. If this switch is turned ON, when the user is connected to the device with SSHv2 protocol, there will be a choice to connect without running authScript. Even if this switch is ON for more than one Device Group, only one extra choice will be shown on the screen for selection when the connection is made.



Accounts on the Vault can also be used in the script. The following format is used for this:
- ${sapm:<Username of Vault Account>}
This allows all devices in the device group to use their own Vault account password.
Device Group level property keys apply to all of the devices in it.