Managerial Approval for Connections
Kron PAM supports Just-In-Time (JIT) privileged access through managerial approval and connection reservation workflows for SSH, RDP, SFTP and HTTPS connections. Privileged access can be granted temporarily for a specific work requirement and for a defined period. Once the approved access period expires, the temporary privilege is automatically revoked, supporting a Zero Standing Privileges (ZSP) security model and minimizing persistent privileged access.
Admins can configure an approval process so that users will require managerial approval to connect devices. Connection approvals may be given by managers or members of user groups.
To disable instant approval connections and use only connection reservation, the following parameters need to be set to true on System Config Manager. Their default value is false.
disable.instant.approval.for.ssh disable.instant.approval.for.rdp disable.instant.approval.for.sftp disable.instant.approval.for.http
Refer to the APPENDIX 1: System Config Manager Parameters
If you want to set up an approval process to manage connections of a specific user group to a specific device group, you should configure an Approval Workflow. Refer to the Approval Workflow section for details.
If the requester is also the manager of the group and auto.approve.when.requester.is.approver is set as true, approval will be given automatically and the connection will be established. Thus, the manager does not need to actively approve. aioc.approval.excludeRequester.enabled=true does the opposite, and blocks the managers from approving their own requests, requiring approval from another manager.
When you want to approve or reject connections via email, the manager receives an email including the header as this: <instanceName> - Connection Approval Notification - #<approvalID>

My Approvals list shows request details and the Approver Manager, which helps involved parties know who will be approving the request. With the advanced filtering feature, incoming connection and command requests can be searched based on specific criteria and easily viewed.
If the manager does not approve or reject connection requests and approval.status.change.to.expire is in effect (value in minutes), the request status changes from Waiting to Expired on my Approvals Page.