APPENDIX 1: System Config Manager Parameters
Parameter Name | Description | Sample Parameter Value | Restart Required | Default Value |
|---|---|---|---|---|
aioc.alert.notification.mail.address | If this parameter is set, a notification is also sent to specific users. If it’s not set, the notification is only sent to the related manager. | NO | N/A | |
aioc.approval.excludeRequester.enabled | When this parameter is set to true and a group has multiple approvers, if one of those approvers performs an action that requires approval, they cannot approve their own request. In this case, they are excluded from the approver list and will not receive any approval emails or notifications. However, even if the parameter is true, if there is only a single approver, that user can approve their own request. If an approver is a member of multiple groups and performs an action that requires approval, the system evaluates the approvers within the relevant realm. If the user is the only approver in that realm, they will receive the approval email/notification and can approve their own request. If there are other approvers besides them, they are excluded from the approver list and will not receive any email or notification. | true,false | NO | false |
aioc.available.jdbc.drivers | This parameter is used to set requested database types separated by a "," comma. | oracle.jdbc.driver.OracleDriver,org.postgresql.Driver,com.microsoft.sqlserver.jdbc.SQLServerDriver,com.mysql.jdbc.Driver,org.apache.cassandra.cql.jdbc.CassandraDriver,com.teradata.jdbc.TeraDriver,org.apache.hive.jdbc.HiveDriver,org.apache.hive.jdbc.DB2Driver, cdata.jdbc.couchbase.CouchbaseDriver | NO | N/A |
aioc.backup.backupdir | Backup directory path in Kron PAM. The file path “/pam/backup” must be manually created in Kron PAM before starting backup. The backup file is created in this path first, then it is transferred to the path defined in “aioc.backup.ftp.dirname” parameter. | | YES | N/A |
aioc.backup.ftp.server.ip | Server IP the Backup file will be transferred to. | | YES | N/A |
aioc.backup.ftp.username | Username to connect to the ftp server defined with the “aioc.backup.ftp.server.ip” parameter. | | YES | N/A |
aioc.backup.ftp.password | Password of the user defined with the “aioc.backup.ftp.username” parameter. The parameter must be defined with a “yes” encryption option. | | YES | N/A |
aioc.backup.ftp.dirname | Directory path where the backup file will be sent to in the target ftp server defined with the “aioc.backup.ftp.server.ip” parameter. | | YES | N/A |
aioc.backup.diskspace.min.gbyte | Required disk space for ftp server to transfer backup file. The value should be set according to the size of the database to be backed up. | | YES | N/A |
aioc.command.provisioning.c3p0.PreferredTestQuery | Defines the query that will be executed for all connection tests if the default ConnectionTester is being used. Defining a preferredTestQuery that will execute quickly in the database may dramatically speed up Connection tests. | SELECT 1 FROM DUAL | NO | N/A |
aioc.connection.reservation.expiration.alert.before.values | This parameter sets an expiry notification to be sent n days before the end of the connection reservation. | E.x: 1 | NO | N/A |
aioc.connection.reservation.approval.requester.email.visibility | This parameter enables the display of the requester's email address in notification emails, the mobile application, and the 'My Approvals' section of the user interface. | true,false | NO | false |
aioc.connection.reservation.max.allowed.hours | This parameter is used to define the maximum duration users can request when creating a connection reservation. | E.x: 2160 | NO | N/A |
aioc.connection.reservation.reason.required | This parameter determines whether the "reason" field is mandatory when making a reservation through the Device > Reservation screen. Its default value is false, meaning the field is optional. If the parameter is set to true, users will be required to fill in this field in order to complete the reservation process. | E.x: true,false | NO | false |
aioc.date.format | This parameter defines the date and time format based on a locale value. It uses regional settings such as "en-US", "tr-TR", or "ru-RU" to automatically determine how date and time are displayed in the system. Its default behavior follows the selected locale’s standard format. If this parameter is set, the system formats date and time according to the given locale, without requiring a custom format definition. | ru-RU,tr_TR | NO | N/A[EA1] |
aioc.date.time.format | This parameter allows defining a custom date and time format directly using a format pattern (e.g., "YYYY-MM-DD HH:mm:ss"). Unlike locale-based formatting, it provides full control over how date and time values are displayed. If this parameter is set, the system uses the specified format instead of relying on locale settings, enabling more precise and customizable formatting options. | YYYY-mm-DD HH:MM:SS | NO | dd.MM.yyyy HH:mm:ss |
aioc.device.available.interface.names | This parameter is used to define an interface name for devices with the same IP address, so they can be distinguished during connection. | E.g: interface_1, interface_2 | YES | N/A |
aioc.download.android.active | This parameter is used to enable the link to the play store link. | Example values: True,false | NO | true |
aioc.download.ios.active | This parameter is used to enable the link to the app store link. | Example values: True,false | NO | true |
aioc.download.linux.active | This parameter is used to enable an application that the Linux system can download. | Example values: True,false | NO | true |
aioc.download.macos.active | This parameter is used to enable to download the desktop application to Mac computers. | Example values: True,false | NO | true |
aioc.download.windows.active | This parameter is used to enable to download the desktop application. | Example values: True,false | NO | true |
aioc.device.group.property.keys | This parameter is used to define device group properties. | Example values: tag.Name,tag.Region,addDeviceSshKeyToUserSelection | NO | null |
aioc.email.domains | Set this parameter with related email domains. (More than one domain can be added with a comma. Ex: SingleConnect.com, abc.com) | gmail.com, kronpam.com | NO | N/A |
aioc.force.end.user.to.react.interface | Set this parameter to true to force the following users to the new end-user interface. · Users that are not in the system.admins group · Users that are not in a group with the Admin Group flag · Users that are not named admin Defaults to false. | true, false | NO | true |
aioc.instead.of.ad.line.manager | This parameter defines where to direct the approval request to provide the missing AD Line Manager and it will direct all the requests in case the AD Line Manager is not imported to Kron PAM or the AD Line Manager is missing | NO | N/A | |
aioc.languages | This parameter sets the preferred language as options in GUI. More than one language preference can be added with a comma separator. | en_US, ru_RU, ko_KR | NO | en_US,de_DE,ko_KR |
aioc.nsso.active | This parameter is used to activate the nsso module in aioc and grant SSH Proxy rights to Kron PAM. | true | NO | true |
aioc.portal.disallow.multi.login | This parameter enables or restricts multi login (simultaneous login) on the Kron PAM GUI | true, false | NO | false |
aioc.portal.session.idletime.minute | This parameter defines the time in minutes to disconnect the session if the user is inactive. | 45 | YES | 30 |
aioc.portal.session.idletime.warning.before.min | This parameter defines the gives warning before ending the session. | 5 | NO | N/A |
aioc.portal.allowed.ip.for.admin.users | This parameter defines the users in the admin group to only be able to access through set IP/s. | 10.20.42.55,10.20.42.50 | NO | N/A |
aioc.region.field.visibility | If this parameter is set as “true”, the region field is visible in the New Device Discovery Screen in the Device İnventory. If it is set as “false”, the region field is not visible in the New Device Discovery Screen in the Device Inventory. If this parameter is not set, a controller/controlled license is required to visualize the region field. | | | false |
aioc.locking.ad.user.enabled | This parameter defines available to make AD users lockable. AD users will be locked for failed login attempts and inactivity cases same as local users. | true | NO | false |
aioc.session.play.alert.mail.address | Users can enter one or more email addresses separated by commas in this parameter to specify where the alert notifications that when someone views a "Play Session" in the "Session Logs should be sent. | NO | N/A | |
aioc.users.default.password.strength | It sets the default password security level for users in PAM. | 5 | NO | N/A[EA1] |
aioc.users.password.strength.length | It defines the minimum password length required for users in KronPAM. | 5 | NO | N/A |
aioc.users.password.strength.symbol.count | It defines the minimum number of special characters required in the password. | 5 | NO | N/A |
aioc.users.password.strength.symbol.chars | It defines which special characters are allowed or required in the password. | 5 | NO | N/A |
aioc.users.password.strength.number.count | It defines the minimum number of digits required in the password. | 5 | NO | N/A |
aioc.users.password.strength.lowercase.count | It defines the minimum number of lowercase letters required in the password. | 5 | NO | N/A |
aioc.users.password.strength.uppercase.count | It defines the minimum number of uppercase letters required in the password. | 5 | NO | N/A |
aioc.timezone | It can be defined as "New York USA" or "GMT-5" or "Etc/GMT-5". For all those 3 definitions, time will show "... (GMT-05:00)". If the parameter is defined, time in emails will be converted to the defined time zone, otherwise, the system zone of the server sending the email will be used. | | | N/A |
aioc.user.group.property.keys | This parameter defines the user group properties. | allowSftpInSshDevices | YES | allowSftpInSshDevices,httpProxyEnabled,otpEnabled,rdpProxyEnabled,sftpProxyEnabled,sqlProxyEnabled,sshProxyEnabled,otpSmsEnabled |
aioc.user.password.algorithm | This parameter sets the preferred algorithm to encode user passwords. Possible algorithms are defined in the examples. | E. g. :MD5(default), SHA256, SHA384, SHA512, and NTLM | YES | SHA512 |
aioc.user.group.change.notifier.enabled | When a user group is edited or a user is added/deleted, a notification mail is sent to the group manager. Set this parameter to false to disable sending notification emails. Defaults to true. | false | No | true |
aioc.user.group.change.notification.email | When a user group is edited or a user is added/deleted, a notification mail is sent to the specific mail addressess. Multiple email addresses can be added to this parameter. | NO | N/A | |
aioc.user.password.log.check.count | This value checks whether the user's new password matches older passwords. (Ex: If it is 2, it checks last 2 passwords) | 2 | NO | 2 |
aioc.users.default.password.strength | This parameter is used to set the preferred User Password Strength Level according to predefined levels: 0-None 1-Password length must be at least 5 characters 2-Password length must be at least 5 characters / Number required 3-Password length must be more than 7 characters/ Upper-Lower Case, Number, Special Character required 4-Password length must be more than 15 characters / Upper-Lower Case, Number, Special Character required | 0 | NO | 1 |
allow.changing.reservation.time.by.approver | This parameter provides to change time duration during approval time by approver. | true,false | NO | false |
approval.sms.http.encoding | Encoding format. See 5.3.6 Approval Workflow SMS Settings. | Alternative Values: UTF-8, UTF-16BE | | |
approval.sms.http.headers | HTTP SMS Header. See 5.3.6 Approval Workflow SMS Settings. | Ex: Content-Type:text/xml | | N/A |
approval.sms.http.url | SMS sender http URL. See 5.3.6 Approval Workflow SMS Settings. | Ex: http://api.smsexample.com/v1/send-sms | | N/A |
approval.status.change.to.expire | When the defined time to approve the instant connection ends, the request status changes from “Waiting“ to “Expired" if not approved by approver/s. | Ex:10, | | N/A |
approval.workflow.level.timeout.period.values | The timeout period value alternatives for Approval Workflow settings, separated by commas. See 5.3.5Approval Workflow for details. Default values are: 30 minutes, 2 hours, 1 day | Ex: 30m,2h,1d | NO | 30 minutes, 2 hours, 1 day |
auto.approve.when.requester.is.approver | When the approver is also the requester, approval is automatically given. | true, false | NO | false |
cookie.warning.message.content | This parameter is used to inform users that cookies are being used. | At Kron, we deeply respect your privacy,and we are dedicated to ensuring that your journey with our product is nothing short of exceptional. Our commitment to delivering the best experience possible leads us to employ cookies. These tiny pieces of data play a crucial role in enhancing your interaction with our platform.By utilizing cookies, we can offer personalized settings and preferences that align with your unique needs.Thank you for choosing KronPAM. We look forward to continuing to enhance your experience and provide you with a product that aligns perfectly with your needs and expectations. | NO | false |
command.approval.sms.http.body | Template for SMS messages to be sent for command approval through HTTP. See 5.3.6 Approval Workflow SMS Settings. | | | N/A |
command.approval.sms.smpp.body | Template for SMS messages to be sent for command approval through SMPP. See 5.3.6 Approval Workflow SMS Settings. | | | N/A |
connection.approval.sms.http.body | Template for SMS messages to be sent for connection approval through http. See 5.3.6 Approval Workflow SMS Settings. | | | N/A |
connection.approval.sms.smpp.body | Template for SMS messages to be sent for connection approval through SMPP. See 5.3.6 Approval Workflow SMS Settings. | | | N/A |
desktop.client.otp.enabled | This parameter is used to enable or disable multi factor authentication (MFA) for the desktop client application login for its online functions. Default value is false. | true, false | NO | false |
disable.instant.approval.for.http | This parameter checks WF level check box.("disable instant approval") All HTTP approvals disabled when this parameter set as true | true,false | NO | false |
disable.instant.approval.for.rdp | This parameter checks WF level check box.("disable instant approval") All RDP approvals disabled when this parameter set as true. | true,false | NO | false |
disable.instant.approval.for.sftp | This parameter checks WF level check box.("disable instant approval") All SFTP approvals disabled when this parameter set as true. | true,false | NO | false |
disable.instant.approval.for.ssh | This parameter checks WF level check box.("disable instant approval") All SSH approvals disabled when this parameter set as true. | true,false | NO | false |
export.securecrt.role.groups | This parameter determines whether to include the roles of device groups in the exporting folder. The parameter is used to export device lists for SecureCRT. SecureCRT is a commercial SSH, Telnet client, and terminal emulator. | true | YES | true |
export.securecrt.script.extension | This parameter determines the type of script file of the exporting devices. The parameter is used to export device lists for SecureCRT. SecureCRT is a commercial SSH, Telnet client, and terminal emulator. | js | YES | js |
export.securecrt.shorten.names | If this parameter is saved as true, the parent device group name is discarded from the device group names. The parameter is used to export device lists for SecureCRT. SecureCRT is a commercial SSH, Telnet client, and terminal emulator. | true | YES | true |
export.securecrt.single.script | This parameter determines whether to include a script file in the exporting folder. The parameter is used to export device lists for SecureCRT. SecureCRT is a commercial SSH, Telnet client, and terminal emulator. | true | YES | true |
export.securecrt.templates.dir | This parameter defines the directory folder for devices. The parameter is used to export device lists for SecureCRT. SecureCRT is a commercial SSH, Telnet client, and terminal emulator. | ${netright.home}/templates/securecrt | YES | ${netright.home}/templates/securecrt |
hsm.enabled | true | YES | | |
hsm.method | Client | YES | | |
hsm.provider.classname | com.ncipher.provider.km.nCipherKM | YES | | |
hsm.keystore.type | nCipher.sworld | YES | | |
hsm.keystore.alias | secureworld | YES | | |
hsm.keystore.load.password | xxx | YES | | |
hsm.keystore.entry.password | xxx | YES | | |
hsm.secretkey.algorithm | AES | YES | | |
iga.2fa.token.timestep | Defines the token validity period | (in seconds) Default is 30 | YES | 30 |
iga.2fa.sms.http.body | HTTP request body for sending SMS | HTTP body value | NO | N/A |
iga.2fa.sms.http.headers | Headers included in the SMS HTTP request | HTTP headers value | NO | N/A |
iga.2fa.sms.http.secret.body | Secret data added to the HTTP request for security | HTTP secret data value | NO | N/A |
iga.2fa.sms.http.url | URL used for sending SMS via HTTP | HTTP URL | NO | N/A |
iga.2fa.sms.smpp.body | SMS message content when using the SMPP protocol | SMPP body value | NO | N/A |
iga.2fa.sms.smpp.secret.body | Secret data in the SMPP SMS message body | SMPP secret data value | NO | N/A |
iga.2fa.use.external.mobile.app | Allows MFA Client applications such as Google Authenticator or Microsoft Authenticator to run. | true | YES | false |
kron.cripto.aes.key | This parameter defines the key to hide sensitive data. | IQtn5Fh70qhOeKnEDNKLcIZREHoWwhWdfmG0uOyKMtc= | YES | N/A |
kill.session.on.reservation.end | This parameter is used to automatically kill sessions after the specified time for reservation connections such as RDP, SSH, and SFTP Proxy. | true,false | NO | false |
legal.notice.enabled | Customers can set up a legal disclaimer message to appear at the start of RDP or VNC sessions. This parameter must be set as “true” to show the message. This parameter is used to set up a legal disclaimer message. Restart of the web portal service is needed after configurations. | true, false | NO | false |
legal.notice.text | The text to be shown as a legal disclaimer message. This parameter is used to set up a legal disclaimer message. Restart of the web portal service is needed after configurations. | <text> | NO | N/A |
mail.templates.dir | This parameter defines the default mail template directory. Kron PAM sends emails to group admins to notify them of new user requests, password manager actions, command authorization requests, etc. Kron PAM also sends password reset emails and MFA activation token emails. In order to achieve these actions, email settings have to be configured on Kron PAM using the Mail Config screen in the System Config Manager menu. | ${netright.home}/templates/mail | YES | ${netright.home}/templates/mail |
max.push.count.to.send.in.one.time | This parameter limits the notifications to be sent in the Mobile App. to prevent overactivity of the notification system. | 10 | NO | |
mobile.application.otp.enabled | This parameter is used to enable or disable multi factor authentication (MFA) for the mobile application login for its online functions. | true, false | NO | false |
mobile.application.register.token.otp.validity.seconds | The validity period for one-time passwords sent for Register Token operation (in seconds) | Integer (default value = 60) | NO | 60 |
mobile.tomcat.url | This parameter defines the Kron PAM Mobile Application Server address. | https://sc251.SingleConnect.com:9443/mobile-api/rest | NO | http://localhost:9080/mobile-api/rest |
multitenancy.enabled | This parameter enables Kron PAM’s multitenancy function. | true | NO | false |
multitenancy.tacacs.port.range | The port range to be used for the TACACS devices for the tenants should be defined with this parameter. | 50000-50100 | NO | N/A |
netright.alias | This parameter determines which modules to use in AIOC. You can set the system as Kron PAM, Single Monitor or Single Command using this parameter. | sc | NO | sc |
netright.auth.ldap | This parameter enables or disables LDAP/AD authentication. | false | YES | false |
netright.auth.ldap.baseDN | This parameter defines the LDAP Base DN. Base DN is the section of the directory where the application will start searching for Users and Groups. | DC=example,DC=com | NO | DC=example,DC=com |
netright.auth.ldap.principal | Security principal of context set from the expression defined as uid. | uid=?,DC=example,DC=com | NO | uid=?,DC=example,DC=com |
netright.auth.ldap.url | This parameter determines the Active Directory/LDAP hostname/ip address, port number and LDAP/LDAPS protocol. If more than one URL is used, the parameters should be separated by “,”. (e.g., ldap://10.10.10.10:389, ldaps://10.10.10.20:636) | ldap://1.1.1.1:389 | NO | ldap://1.1.1.1:389 |
netright.auth.ldap.timeout | Timeout duration for a response from the AD/LDAP server | 1200 | NO | 1000 (default value in ms) |
netright.auth.ldap.socket.timeout | Timeout period for socket connection with the AD/LDAP server | 6000 | NO | 5000 (default value in ms) |
netright.auth.tacacs | This parameter determines the use of the TACACS+ authorization. | true | YES | false |
netright.auth.tacacs.server | This parameter defines the address of the TACACS+ server. | 127.0.0.1 | NO | 127.0.0.1 |
netright.auth.tacacs.server.key | This parameter defines the key of the TACACS+ server. | z7i/Z15wXHgEJRwGFAQO3A== | NO | N/A |
netright.autoddl | This parameter is set as true while upgrading Kron PAM. The value of this parameter remains false while using the system. | false | YES | false |
netright.baseurl | This parameter is used to configure the base URL to provide connection from a proxy service. | http://127.0.0.1:80 | NO | N/A |
netright.cache.enable | This parameter determines whether the User Interface has cache. | false | YES | false |
netright.content.root | This parameter defines the folder of the root content. | ${netright.home}/filerepo | YES | ${netright.home}/filerepo |
netright.hidden.property.keys | This parameter stores the hidden properties. | .*.password | NO | .*.password |
netright.home | This parameter defines the netright.home directory. | /pam/gui/netright | YES | /pam/gui/netright |
netright.instancename | This parameter defines the Kron PAM instance name. You can use different names if you use more than one instance. Instance name info to the WEB GUI is made visible by default. | KronPAM | NO | N/A |
netright.jdbc.database | This parameter defines the type of Kron PAM database. | postgresql | NO | postgresql |
netright.jdbc.password | This parameter defines the password of the Kron PAM database. | ***** | NO | N/A |
netright.jdbc.url | This parameter defines the address of the Kron PAM database. | jdbc:postgresql://localhost:5444/aioc | NO | N/A |
netright.jdbc.username | This parameter defines the name of the Kron PAM database. | aioc | NO | aioc |
netright.license.file.path | This parameter defines the path of the license file. | ${netright.home}/licence.properties | NO | ${netright.home}/licence.properties_1 |
netright.name | This parameter defines the header in the Kron PAM GUI. | KronPAM | YES | KronPAM |
netright.version | This parameter defines the version shown in GUI. | 2.14.3 | NO | N/A |
notify.user.before.TTL.password.expire | This parameter is used for users to receive expiration notifications a certain number of days before the expiration date (Password TTL) of the passwords they set through the user group. | 3 | NO | N/A |
nsso.nsso.ssl.port | This parameter defines the SSL port of the link between the SSH Proxy and Kron PAM. | 4443 | NO | 4443 |
nsso.remote.desktop.base.dir | This parameter defines the folder in Kron PAM where files transferred during an RDP session are stored. | /tmp | NO | /pam/RDPShare |
nsso.remote.desktop.daemon.host | This parameter defines the host address of the RDP Proxy. | 127.0.0.1 | NO | 127.0.0.1 |
nsso.remote.desktop.daemon.port | This parameter defines the port of the RDP Proxy. | 4822 | NO | 4822 |
nsso.remote.desktop.drive.sharing.enabled | This parameter is used to transfer files between RDP endpoints. When this property is set, a special folder on Kron PAM (/tmp/<username>) is shared with all the RDP endpoints as a shared drive named “G on SC RDP”. | true, false | NO | N/A |
nsso.remote.desktop.idle.threshold | Time limit to start calculation of idle time (millisecond). | Example:40000 | NO | 30000ms(30seconds) |
nsso.remote.desktop.key.logger.enabled | This parameter grants rights to see the RDP session logs as Key Logger. Mouse and keyboard inputs during RDP sessions can be accessed in this page. | true | NO | true |
nsso.remote.desktop.key.logger.hidden.key. | The Key logger of RDP sessions logs all the key motions in clear text. This feature must be stopped to obscure certain data. When the users press the defined key twice in a session, the key logger hides the key motions by the limit defined in this parameter. | 20 | YES | 15 |
nsso.remote.desktop.key.logger.key.hiding.shortcut | This parameter is used to define the key that will disable key logging for the defined hidden limited keys. The default key is "ESC". | ESC | YES | “ESC” |
nsso.remote.desktop.ocr.enabled | This parameter grants rights to see the RDP session logs as OCR Logs. You can see the activities performed by the user during an RDP session. | true | NO | true |
nsso.remote.desktop.ocr.lang | This parameter is used to get OCR logs in the required language. Codes for the supported languages can be found in the Admin Guide. Multiple languages must be separated by "+". | eng+kor+tur+spa | NO | N/A |
nsso.remote.desktop.ocr.threads | This parameter defines the maximum number of threads allocated to OCR processes in multitenant environments. | Ex: 2 | NO | 2 |
nsso.remote.desktop.session.duration.limit.warning.before.min | This parameter is used to determine the time a warning is shown before the session times out. | Example:4 | NO | N/A |
otp.rest.url | This parameter is used to enable MFA. The rest URL should be set as the Kron PAM Public IP and port. | Ex:http://127.0.0.1 | NO | |
pam.auth.username.case-sensitive | When this parameter is true, the system checks the username with case sensitivity and blocks logins that do not exactly match the defined username. | true,false | NO | false |
rdp.idle.session.timeout | User sessions can be terminated based on their idle duration. This parameter is used to set a timeout limit (minute). | Example:5 | NO | 60 |
rdp.min.reason.character.limit | This parameter is used to specify the minimum character limit required for the connection. | Min:5 | NO | N/A |
rdp.timeout.server.response.time | This parameter is used to set timeout for the response time of the server. The connection timeout parameter can be configured as per the requirements (second). | Ex: 10 | NO | 15 |
sapm.job.password.change.thread.count | This parameter is used to change the number of threads running the SAPM Auto Import jobs. | 5 | YES | 5 |
sapm.create.parent.group.right | This parameter allows end users to create or restrict their own Password Vault Parent groups. | true,false | NO | false |
sapm.show.password.expiration.time.values | This parameter defines the password reservation times of SAPM Accounts. When a user makes a password reservation for an SAPM account, these time options are presented to reserve a time. | 5m,30m,2h,24h | NO | 5m,30m,2h,24h |
sc.aaa.freeradius.password | This parameter defines the password to connect to the RADIUS server. | ***** | NO | N/A |
sc.aaa.freeradius.url | This parameter defines the URL address of the RADIUS server. | jdbc:postgresql://127.0.0.1:5444/aioc | NO | jdbc:postgresql://127.0.0.1:5444/aioc |
sc.aaa.freeradius.username | This parameter defines the username to connect to the RADIUS server. | aioc | NO | aioc |
sc.aaa.radius.ldap.conf.path | This parameter is used to set the path of the RADIUS configuration file to insert Active Directory/LDAP parameters. | /etc/raddb/mods-available/ldap | NO | /etc/raddb/mods-available/ldap |
sc.aaa.radius.restart.command | This parameter defines the command to restart the RADIUS server. The server needs to be restarted with this command to apply changes. | systemctl restart pam-radius | NO | systemctl restart pam-radius |
sc.aaa.tacacs.conf.path | This parameter is used to set the path of theTACACS+ configuration file to insert Active Directory/LDAP parameters. | /pam/tacacs/etc/kron_tacacs.conf | NO | /pam/tacacs/etc/kron_tacacs.conf |
sc.aaa.tacacs.restart.command | This parameter defines the command to restart the TACACS+ server. The server needs to be restarted with this command to apply changes. | systemctl restart pam-tacacs | NO | systemctl restart pam-tacacs |
sc.freeradius.server | This parameter defines the address of the Free RADIUS Server. If this parameter is not equal to the requested remote address, the program will return an authorization error. | 127.0.0.1 | YES | 127.0.0.1 |
sc.policy.xml.dir | This parameter defines the location of the policy.xml file. | /u01/nssoapp/conf/xml | YES | /u01/nssoapp/conf/xml |
sc.portal.otp.enabled | This parameter is used to enable or disable multi factor authentication (MFA) for the Kron PAM GUI login. | true, false | NO | false |
sc.rdp.connection.otp.enabled | This parameter is used to enable or disable multi factor authentication (MFA) for RDP connections. (true=enabled, false=disabled) | false | NO | false |
sc.rdp.otp.cache.enabled | If this parameter is saved as true, the user will not be asked for OTP during the cache duration after entering OTP. | true | NO | true |
sc.rdp.otp.cache.seconds | This parameter defines the cache time in seconds. | 300 | NO | 300 |
sc.rdp.page.list.element.length | This parameter defines the length of the accounts and remote app names. Sometimes names can be long and do not fit in the screen. | Value : Length 1 : 29 characters 2 : 36 characters 3 : 56 characters 4 : 89 characters | NO | 1 |
sc.user.group.manager.obligated.member.of.group | This parameter is used to determine whether managers will belong to the user group or not. | true, false | NO | true |
selenium.chrome.binary | This parameter specifies the exact file path to the Google Chrome executable on your system. It ensures Selenium launches the correct browser instance, which is especially important in custom or server environments. | /usr/bin/google-chrome | NO | |
selenium.side.runner.binary | This setting points to the command-line tool used to execute Selenium IDE (.side) project files. It allows the automation framework to locate and run your pre-recorded test suites directly from the terminal. | selenium-side-runner | NO | |
selenium.chrome.args | This parameter defines the specific command-line arguments and flags passed to Google Chrome upon launch. It allows you to completely customize the browser's behavior for your testing environment, such as running it in headless mode or bypassing sandbox restrictions. | --headless, --disable-infobars, --no-sandbox, --enable-javascript, --disable-dev-shm-usage, --disable-gpu, --remote-debugging-port=9222, --incognito, --user-data-dir=/tmp/selenium-profil | NO | |
selenium.side.runner.ss.directory | Specifies the local directory path where screenshots are automatically saved during test execution, providing a centralized location for visual logs. | /pam/gui/templates | NO | |
selenium.side.runner.debug.mode | Activates an enhanced logging state that prints detailed browser console logs and internal execution steps to the terminal, facilitating deeper technical troubleshooting. | true, false | NO | |
show.wiretosessionWarning | This parameter can be used to set whether or not the notification sent to the user when the wire to session process starts will be displayed. | false, true | NO | |
smpp.addressRange | The destination address range to be served by this ESME account. This parameter is optional, and SMSC settings will be applied if it is not defined. | Example: 1* (for numbers starting with 1 | YES | N/A |
smpp.addrNpi | Numeric Plan Indicator (NPI) to be used for address range parameters. This parameter is optional, and SMSC settings will be applied if it is not defined. | Alternative values: 0: Unknown 1: ISDN (E163/E164) 3: Data (X.121) 4: Telex (F.69) 6: Land Mobile (E212) 8: National 9: Private 10: ERMES 14: Internet (IP) 18: WAP Client ID | YES | N/A |
smpp.addrTon | Type of Number (TON) to be used for address range parameter. This parameter is optional, and SMSC settings will be applied if it is not defined. | Alternative values: 0: Unknown 1: International 2: National 3: Network Specific 4: Subscriber Number 5: Alphanumeric 6: Abbreviated | YES | N/A |
smpp.bindMode | Bind mode for the ESME account. This parameter is mandatory for sending/receiving SMS over SMPP. | Alternative values: t: transmitter r: receiver tr: transceiver (transmitter and receiver) | YES | N/A |
smpp.destinationNpi | Numeric Plan Indicator (NPI) parameter to be used for destination address. This parameter is optional, and SMSC settings will be applied if it is not defined. | Alternative values: 0: Unknown 1: ISDN (E163/E164) 3: Data (X.121) 4: Telex (F.69) 6: Land Mobile (E212) 8: National 9: Private 10: ERMES 14: Internet (IP) 18: WAP Client ID | YES | N/A |
smpp.destinationTon | Type of Number (TON) parameter to be used for destination address. This parameter is optional, and SMSC settings will be applied if it is not defined. | Alternative values: 0: Unknown 1: International 2: National 3: Network Specific 4: Subscriber Number 5: Alphanumeric 6: Abbreviated | YES | N/A |
smpp.enquireLinkPeriodMs | Period in milliseconds to make EnquireLink requests to the SMSC. EnquireLink requests are used to check the health of the status of the connection between the ESME and target SMSC. Any value less than or equal to “0” will be defaulted to 5000 ms (5 seconds). The SMPP connection will be automatically re-established in case of SMPP connection failures during Enquire Link requests. | Ex: 10000 (In milliseconds | YES | N/A |
smpp.ip | IP address of the SMSC. This parameter is mandatory for sending/receiving SMS over SMPP. | Ex: 10.20.40.95 | YES | N/A |
smpp.password | The password used to authenticate an ESME account defined in SMSC. This parameter is mandatory for sending/receiving SMS over SMPP. | Ex: netright | YES | N/A |
smpp.port | Binding port for SMPP, listened on SMSC. This parameter is mandatory for sending/receiving SMS over SMPP. | Ex: 16000 | YES | N/A |
smpp.receiveTimeout | Timeout duration for trying to receive a message from the SMSC. This parameter is optional. | Alternative values: -1 (Infinite wait until a PDU is received. 1,2,3…. (number of seconds) | YES | N/A |
smpp.serviceType | SMS Application service associated with the message. This parameter is optional and sent as Default, if not defined. | Alternative values: (NULL): Default CMT: Cellular Messaging CPT: Cellular Paging VMN: Voice Mail Notification VMA: Voice Mail Alerting WAP: Wireless Application Protocol USSD: Unstructured Supplementary Services Data | YES | N/A |
smpp.sourceAddress | The source address to be used when sending messages. This parameter is mandatory for sending/receiving SMS over SMPP. | Ex: PAM, +12348372939 | YES | N/A |
smpp.sourceNpi | Numeric Plan Indicator (NPI) to be used in the SME source address parameters. This parameter is mandatory for sending/receiving SMS over SMPP. It should be defined as Unknown (0), if an alphanumeric source address is tobe used to send messages (Ex: SingleCon) | Alternative values: 0: Unknown 1: ISDN (E163/E164) 3: Data (X.121) 4: Telex (F.69) 6: Land Mobile (E212) 8: National 9: Private 10: ERMES 14: Internet (IP) 18: WAP Client ID | YES | N/A |
smpp.sourceTon | Type of Number (TON) to be used in the SME source address parameters. This parameter is mandatory for sending/receiving SMS over SMPP. It should be defined as Alphanumeric, if an alphanumeric source address is to be used to send messages (Ex: SingleCon) | Alternative values: 0: Unknown 1: International 2: National 3: Network Specific 4: Subscriber Number 5: Alphanumeric 6: Abbreviated | YES | N/A |
smpp.syncMode | Receiving mode. If set to sync, the application waits for a response after sending a request PDU. If set to async, the application doesn't wait for responses, rather they are passed to and implementation of ServerPDUListener by the Receiver. The listener is also passed every request PDU received from the SMSC. This is an optional parameter and default value is sync. | Alternative values: sync – Synchronous async - Asynchronous | YES | sync |
smpp.systemId | The system ID used to identify an ESME defined in SMSC. It is used for SMPP sender authentication. This parameter is mandatory for sending/receiving SMS over SMPP. | Ex: netright | YES | netright |
smpp.systemType | The system type used to categorize the type of ESME binding to the SMSC. This parameter is optional for sending/receiving SMS over SMPP, and if not defined the system type is sent as null. | Alternative values: VMS: Voice Mail System OTA: Over-the-air Activation system (NULL): Default | YES | N/A |
sms.channel | Which channel is to be used to send SMS. | Alternative values: http: for using http-based SMS Proxy smpp: for using SMPP towards SMPP | YES | http |
ssh.min.reason.character.limit | This parameter is used to specify the minimum character limit required for the connection. | Min: 5 | NO | |
sso.geosites | This parameter defines the location of the server. |
| NO | |
sso.ip | This parameter defines the IP address of the SSH proxy. | 127.0.0.1 | NO | IP_address of SSH Proxy |
sso.port | This parameter defines the port of the IP address of the SSH proxy. | 2222 | NO | 2222 |
syslog.message.rfcFormat | RFC_5424 and RFC_3164 formats are supported in SIEM configuration. This parameter determines the RFC format and must be set as one of these values. | RFC_5424, RFC_3164 | NO | RFC_5424 |
syslog.message.content.format | This parameter is used to determine content format. | KEY_VALUE, CEF, LEGACY_CEF | NO | KEY_VALUE |
syslog.server.hostName | Kron PAM can send logs to SIEM systems. This parameter is used to set the SIEM Host IP address. | 10.10.20.20 | YES | - |
syslog.server.port | This parameter is used to set the port of the SIEM host. | 514 | YES | 514 |
tfa.otp.issuer | The name of the MFA server. This string is shown on top of the Offline Token value on the mobile app, when a QR code that is issued from the server is scanned on a mobile app. | String | NO | |
user.forceManagerUserInGroup | If this parameter is saved as true, you must define a manager for a user group. Otherwise, user groups can be created without a manager. | true | NO | true |
user.lock.afterFailedLoginAttempts | Users are locked after a certain number of failed login attempts. This parameter defines the number of failed login attempts before locking the user account. | 5.10,20 | YES | 20 |
aioc.locking.ad.user.enabled | This parameter defines available to make AD users lockable. AD users will be locked for failed login attempts and inactivity cases same as local users. | true,false | NO | false |
user.lock.afterInactiveMillis | Kron PAM locks inactive users. This parameter defines the maximum inactive time before locking a user. The user password must be reset to unlock the user account. | 2629743000 | NO | 2629743000 |
user.mail.from | This parameter defines the sender mail address for MFA. | change_it@change_it.com | YES | N/A |
user.registration.enabled | This parameter is to hide the new user button on the Login screen. Default value is false. | true,false | NO | false |
user.suspend.afterFailedLoginAttempts | Users are suspended after a certain number of failed login attempts. This parameter defines the number of failed login attempts before suspending the user. | 10 | YES | 10 |
user.suspend.forMillis | After a certain amount of failed login attempts, users are suspended for the time determined in this parameter. This value is in milliseconds. | 60 | NO | 60_1 |
windows.auth.keytab.path | These parameters are used to configure the Windows Authentication settings. (The abovementioned parameters should be set for respective UI). | = /pam/gui/conf/sc.keytab | NO | |
windows.auth.spn | | =HTTP/ Kron PAM ServerName | NO | |
| | | | |
aioc.auth.rdc | This parameter enables Windows Authentication feature for Desktop Client. | true | YES | false |
aioc.auth.windows | This parameter enables Windows Authentication for Kron PAM Web GUI. | true | YES | false |
rdp.idle.session.timeout.warning.before.min | This parameter is used to configure the warning pop-up display. | 5 | YES | 5 |
rdp.hide.top.menu.by.default | When this parameter is true, the bar in the RDP connections will be hidden by default. | true | NO | false |
aioc.portal.client.ip.header | This property will be available. The default value is null, so no header will be checked to detect the client IP (TCP source IP will be used by default). You can define it with the value "X-Forwarded-For". | X-Forwarded-For | YES | null |
session.record.encryption.enabled | This parameter allows RDP/VNC and SSH video recordings to be securely stored in an encrypted format in a database. The recordings remain encrypted until the user replays them, ensuring data protection and confidentiality. | true | NO | false |
sc.rdp.reason.mail.recipient | If the reasonRequiredForConnection parameter is set and if this parameter is available in systemconfig, the written reason will be mailed to the recipients. More than one email address can be used, with a comma separator. | | | |
NO | N/A | | | |
ssh.client.kex.algorithms | This parameter specifies the key exchange algorithms used by the SSH client when Vault accounts make SSH connections. Key exchange algorithms determine how the client and server negotiate a shared secret key for the session. . | ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256,diffie-hellman-group18-sha512,diffie-hellman-group17-sha512,diffie-hellman-group16-sha512,diffie-hellman-group15-sha512,diffie-hellman-group14-sha256,diffie-hellman-group-exchange-sha1,diffie-hellman-group14-sha1,diffie-hellman-group1-sha1 | | N/A |
ssh.client.host.key.algorithms | This parameter specifies the host key algorithms used by the SSH client to authenticate the server when making an SSH connection to the Vault account. | [email protected],[email protected],[email protected],[email protected],[email protected],[email protected],ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,ssh-ed25519,[email protected],[email protected],rsa-sha2-512,rsa-sha2-256,ssh-rsa,ssh-dss | | N/A |
ssh.client.encryption.algorithms | This parameter specifies the encryption algorithms used by the SSH client to encrypt the data transferred between the client and the server. | [email protected],aes128-ctr,aes192-ctr,aes256-ctr,[email protected],[email protected],aes128-cbc,aes192-cbc,aes256-cbc,arcfour256,arcfour128,3des-cbc,blowfish-cbc | | N/A |
ssh.client.mac.algorithms | This parameter specifies the message authentication code (MAC) algorithms used by the SSH client to ensure the integrity and authenticity of the data. | [email protected],[email protected],[email protected],hmac-sha2-256,hmac-sha2-512,hmac-sha1,hmac-md5,hmac-sha1-96,hmac-md5-96 | | N/A |
aioc.rest.api.rate.limiter. active | Parameter whether the limit value is active or passive | True | NO | true |
aioc.rest.api.rate.limiter.threshold | The number of requests. | RequestCount | | 300 |
aioc.rest.api.rate.limiter.unit | The future of the requests will be defined as daily, hourly, minute or secondly | Day/Hour/Minute/Second | | minute |
rap.cloud.server | This parameter defines the Remote Access Portal address. The parameter can be defined as URL with IP (e.g., https://34.234.69.53/connect) or as URL with domain name (e.g., https://cloudpam.com/connect) | http://cloudpam.com/connect | NO | http://localhost:7777/connect |
rap.rdp.session.duration.limit.warning.before.min | This parameter defines how many minutes before the RDP session expires that the timeout warning will be sent on the Remote Access Portal. | 1 | NO | 1 |
rap.ssh.session.duration.limit.warning.before.min | This parameter defines how many minutes before the SSH session expires that the timeout warning will be sent on the Remote Access Portal. | 1 | NO | 1 |
rap.http.session.duration.limit.warning.before.min | This parameter defines how many minutes before the HTTP/HTTPS session expires that the timeout warning will be sent on the Remote Access Portal. | 1 | NO | 1 |
rap.token.expiration.period | This parameter indicates the lifespan of a token and is used to prevent the creation of long-term RPAM invitation links. | 1 | NO | 1 |
rap.sms.http.url | URL is used to send SMS via HTTP for Remote Privileged Access Management tokens. | https://api.iletimerkezi.com/v1/send-sms | NO | N/A |
rap.sms.http.body | The SMS message content when using HTTP protocol for Remote Privileged Access Management tokens. | <request><authentication><username>XXXphonenumberXXX</username><password>XXXpasswordXXX</password></authentication><order><sender>KRON</sender><sendDateTime></sendDateTime><message><text> <![CDATA[ Dear %userEid%, Please use the passcode below during login phase of your Secure Remote Access connection. Passcode: %passcode% Secure Remote Access Connection (Access On Web Browser): %connURL% ]]> </text><receipents><number>%phoneNumber%</number></receipents></message></order></request> | NO | N/A |
rap.sms.smpp.body | The SMS message content when using the SMPP protocol for Remote Privileged Access Management tokens. | ---SMPP body value--- | NO | N/A |
rap.sms.http.headers | The headers included in the SMS for Remote Privileged Access Management tokens. | Content-Type:text/xml | NO | Content-Type:text/xml |
rap.sms.http.encoding | A character encoding used in the SMS for Remote Privileged Access Management tokens. | UTF-8 | NO | UTF-8 |
rap.sms.http.method | The HTTP method used in SMS for Remote Privileged Access Management tokens. | POST, GET | NO | POST |
rap.sms.http.delimiter | The delimiter character used in the SMS for Remote Privileged Access Management tokens. | & | NO | & |
rap.sms.channel | The SMS channel used for Remote Privileged Access Management tokens. | http, smpp | NO | http |
rap.client.otp.enabled | The MFA parameter for entering Remote Access Portal. If the parameter is set to true, the user needs to enter a 6-digit OTP code on the Remote Access Portal Login Page. | true/ false | NO | false |
rap.passcode.characters.count | This parameter shows how many characters are used in the passcode definition. This parameter's value should be numeric, and the default value is 8. If the system admin defines this parameter as 4 or fewer, the passcode is created with 4 characters. | 12 | NO | 8[DT1] |
rap.passcode.only.numeric.text | This parameter's value should be a boolean, and the default value is false. If this parameter's value is set as true, the passcode only contains numeric values; however, if this parameter's value is set as false, the passcode contains alphanumeric values. | true / false | NO | false |
show.wiretosessionWarning | This parameter, whose default value is true, is added to the System Config. Manager in order to display the "Your session is monitored by Admin" warning to the user who started the SSH/Telnet or RDP/VNC session when the admin connects to an active session via wire to session. When the parameter value is defined as false, no warning will appear on the screen of the user who starts the session. With this feature, even if the user does not see the warning, "Your session has been monitored by admin" log in is displayed in the Session Log. | true/ false | NO | true |
resources.of.containers | With this parameter, it is defined whether the Container used for Http Proxy will run on the Local machine or on another machine. | Remote/Local /All | NO | Local/Remote/All |
rdp.time.restriction.warning.before.min | Specifies the number of minutes before the scheduled session end time that a warning message is displayed to the user in an RDP session. This parameter is part of the time restriction policy and allows administrators to configure how early users are notified before their session is terminated. | 7 | NO | 1 |
aioc.hide.on.behalf.of.tenant.switch | This parameter is used in both non-host and host tenants for hiding tenant-to-switch feature, if the parameter is set as true. The default value of this parameter is false, it means that until this parameter is set as true, the access on behalf feature is used as in the usual scenario. | true / false | NO | false |
sapm.duallock.option.hide | It determines whether the Enable Duallock switch box on the Vault definition screen will appear or not. If it is not defined as default value or defined as False, this value will appear on the screen, if True, this switch box will not appear on the screen. | true/false | No | N/A |
connector.tunnel.port.range | This parameter is used to set the tenant connector’s tunnel port range. | 10000-11000 | NO | 10000-11000 |
connector.tunnel.subnet.base | This parameter is used to define the subnet base value of the tenant connector. | 192.168.0.0 | NO | 192.168.0.0 |
connector.heartbeat.check.interval | This parameter is used to set the heartbeat check interval. If heartbeat messages cannot be sent to the Kron PAM server for the number of minutes specified by this value, the connector status becomes Failed. (For example, if this value is set to 5, if no heartbeat messages are received for 5 consecutive minutes, the connector status becomes Failed.) | 5 | NO | 5 |
connector.port.range | This parameter is used to define the virtual port range for devices which are reached by the tenant connector. These ports are not used to reach these devices from outside of the connector, but these ports are only used for device mapping. | 40000-50000 | NO | 40000-50000_1 |
netright.job.master.instance.name | | | | |
netright.job.master.instance.name.$region_name | | | | |
mfa.provider | This parameter defines the external MFA provider used by the system. If this parameter's value is set to radius, the system initiates the MFA process via a RADIUS server. | radius | NO | |
mfa.external.provider.radius.addresses | This parameter is used to define the host and port information of the RADIUS server(s). Multiple definitions can be specified as a comma-separated list for redundancy; if one is unreachable, the next will be tried. | 10.20.30.40 | NO | |
mfa.external.provider.radius.secret | This parameter, which must be defined by selecting the Encryption checkbox, contains the shared secret key used for secure communication between Kron PAM and the RADIUS server. | ******** | NO | |
mfa.external.provider.radius.timeout | This parameter defines the maximum time, in milliseconds, the system waits for a response from the RADIUS server before timing out. | 3000 | NO | 3000 |
mfa.external.provider.radius.retry-count | This parameter determines the number of retry attempts the system will perform if no response is received from the RADIUS server within the specified timeout period. | 3 | NO | 3 |
mfa.external.provider.radius.proto | This parameter specifies the authentication protocol type used in the RADIUS request packet. | pap | NO | pap |
mfa.external.provider.radius.user-field | This parameter determines which user attribute is sent in the RADIUS request's username field. Available values include username, phone, email, or UserPrincipalName. | username | NO | username |
mfa.external.provider.radius.nas-id | This parameter is used to define the NAS-Identifier RADIUS attribute in the request packet, which is provided when specifically required by the RADIUS server. | | | |
mfa.external.provider.radius.nas-ip-address | This parameter defines the NAS-IP-Address RADIUS attribute sent in the request packet to identify the client's IP address to the RADIUS server. | | NO | |
mfa.external.provider.radius.factor | This parameter, when its value is set to push, enables the system to utilize Multi-Factor Authentication specifically through push notifications. | push | | |
allow.changing.reservation.time.by.approver | This parameter is used to allow approver to change the reservation time on the mobile apps before approving the requests. | true / false | NO | false |
tenant.expiration.warning.before.day | This parameter is used to show a warning message on the Web GUI, XX days before the tenant's expiration. | 15 | NO | 15 |
aioc.login.different.methods.enabled | This parameter is used to have a new button called “Login with Different Methods” on the Kron PAM server and Desktop Client. The new button allows users to log in to the system different than (e.g., SAML) the conventional login process. | true / false | NO | false |
aioc.hide.on.behalf.of.tenant.switch | This parameter is used to in the both tenant and host environments for hiding tenant-to-switch feature, if the parameter is set as true. The default value of this parameter is false, it means that until this parameter is set as true, the access on behalf feature is used as in the usual scenario. | true / false | YES | false |