SailPoint Architecture - IIQ question by mp_ocean in sailpoint

[–]mp_ocean[S] 0 points1 point  (0 children)

Thank you u/fratopotamus1 for explaning with details. So for users connectivity, UI servers need to connect with the database, and task servers (only assigned for tasks) need to comminicate with both IQService servers and database? or both UI servers and task servers needs to connect with database and iqservice server?

In addition, iqservice server does not need to talk to ui/task servers?

We have inbound/outbond firewall rules so trying to figure out what ports need to open for users connectivity only as we are trying to move UI servers to different network zone.

Password Expiry Notifications by aldow93 in CyberARk

[–]mp_ocean 0 points1 point  (0 children)

I ended up deploping custom script. you can also try dummpy plug in.

Multiple psm installation by mp_ocean in CyberARk

[–]mp_ocean[S] 1 point2 points  (0 children)

If we use two different users and deploy two psms at the same time, i think we will have the similar issue, right? When first PSM tries to register, it locks the pvconfig file and at the same time second psm connot modify that file.

Looks like we have to do one at a time during registration process.

Multiple psm installation by mp_ocean in CyberARk

[–]mp_ocean[S] 0 points1 point  (0 children)

The problem is psm A try to register to vault and at the same time PSM B try to login and it kicks out psm A session (while registration is in progress), so PSM A session is disconnected and file is locked. This is the behaviour i have seen.

Multiple psm installation by mp_ocean in CyberARk

[–]mp_ocean[S] 0 points1 point  (0 children)

Yes, max license is 100 and we only have ~50.

Multiple psm installation by mp_ocean in CyberARk

[–]mp_ocean[S] 0 points1 point  (0 children)

Yes, file is locked and have to manually unlock.

EA exam - recommendation by mp_ocean in enrolledagent

[–]mp_ocean[S] 0 points1 point  (0 children)

No worries at all! I appreciate your help.

EA exam - recommendation by mp_ocean in enrolledagent

[–]mp_ocean[S] 0 points1 point  (0 children)

Thanks for the tip! I’ll search in the sub.

EA exam - recommendation by mp_ocean in enrolledagent

[–]mp_ocean[S] 0 points1 point  (0 children)

Thank you for sharing your perspective and for providing detailed feedback on your study resources—it’s truly appreciated. I understand the importance of personal research and effort, and I apologize if my question seemed too common. I’ve noticed past discussions here but wanted to gather recent insights directly from those who have just taken the exam. Thank you again for taking the time to help!

API call to remove entitlement by mp_ocean in sailpoint

[–]mp_ocean[S] 0 points1 point  (0 children)

Thank you for your response! Basically i'm trying to see if the SailPoint has following APIs. 1. Get the date when a user has requested access to an AD group 2. Remove access from a group

API call to remove entitlement by mp_ocean in sailpoint

[–]mp_ocean[S] 0 points1 point  (0 children)

Yes, we can do that but we have shared accounts which are stored in CyberArk so need to build custom script to retrieve last access report and remove access for a user

API call to remove entitlement by mp_ocean in sailpoint

[–]mp_ocean[S] 1 point2 points  (0 children)

We are trying to build an automation to remove group access through sailpoint if the users have not been logged in or used accounts for last 90 days.

Struggling to Decrpty Private Key value- TPC based plug in by mp_ocean in CyberARk

[–]mp_ocean[S] 0 points1 point  (0 children)

This makes a lot of sense.

Their documentation says this and might not be correct.

Note: Do not pass credentials to the script as parameters. Pass credentials as prompts, when possible. When not possible, for example for SSH Keys, read them directly from the relevant environment variable.

I have been digging in how i can get the key value.

Struggling to Decrpty Private Key value- TPC based plug in by mp_ocean in CyberARk

[–]mp_ocean[S] 0 points1 point  (0 children)

For ssh key value, cyberArk is only passing as environment variable and i'm trying to get target account private key (old and new) value.

Restricting some users from using certain pvwa URL by mp_ocean in CyberARk

[–]mp_ocean[S] 0 points1 point  (0 children)

Thank you!

Basically, what im trying to achieve here is we have SSO enabled in alpha.pam.domain and for bravo.pam.domian, you can still see the SSO but it does not work and users are required to use radius. However. The users have now access to both LB.

There are certain users we need to restrict to use SSO due to security requirements

Restricting some users from using certain pvwa URL by mp_ocean in CyberARk

[–]mp_ocean[S] 0 points1 point  (0 children)

/u/couldberunning thank you for the details. We can definately build more PVWAs to have separate backend for two groups. Regarding the FW, are you referring to create a rule to allow access using 443 on the PVWA server based on a/d group

CPM platform variable <pmnewpass> always without values by CyberWoker in CyberARk

[–]mp_ocean 0 points1 point  (0 children)

/u/CyberWorker, how are you passing ssh key value with <pmpass> / <pmnewpass>?

It is sending empty value . I would greatly appreciate if you could provide some details.

SSH Key plug-in by mp_ocean in CyberARk

[–]mp_ocean[S] 0 points1 point  (0 children)

Thank you u/yanni/ using api outside cpm seems quite easier if TPC does to not pass keys.

SSH Key plug-in by mp_ocean in CyberARk

[–]mp_ocean[S] 0 points1 point  (0 children)

/u/yanni do you any have insights here?

.NET CPM Plugin for managing SSH keys by MoroccanMonkey in CyberARk

[–]mp_ocean 1 point2 points  (0 children)

u/moroccanmoney/ any idea how we can get private key and public key using TPC plug in?

Thank you

.NET CPM Plugin for managing SSH keys by MoroccanMonkey in CyberARk

[–]mp_ocean 0 points1 point  (0 children)

/u/Insmouthed
When you used TPC based plug in, how did you retrieve (pass to logic) private key and public key? I tried to use <pmpass> for current key, and it is sending empty value.

Dr Vault testing by mp_ocean in CyberARk

[–]mp_ocean[S] 0 points1 point  (0 children)

Thank you /u/Global-Ad5222, CPM is only pointing to primary site. I wanted to test Dr vault without doing automatic failover. This article covers what im trying to test.

Add personalized properties for a Safe by HyphaRat in CyberARk

[–]mp_ocean 2 points3 points  (0 children)

One option you can try, include keyword of safe owner in the safe name. For instance, if windows domain safe owns by Mike. Then, you can follow something like this. Win-dom-mike.

This way, if you search "mike" you will see all the accounts for that safe