Thycotic Secret Server - Proxy Configuration (Maybe Launcher?)

Thycotic Secret Server - Proxy Configuration (Maybe Launcher?)

avatar

Hello!

There is some way to use RDM + SS that enforce the SS Proxy utilization?

Maybe some addon to use the SS Launcher or something like this?

All Comments (3)

avatar

Hello,

Its been a while since we worked with Thycotic on our integration, but at the time we were permitted to get only credentials that were not defined has having to go through their proxy. That was the only way they felt they could offer secure account brokering.

Looking thru their REST api, I see the commands related to their launchers, but not enough to give a clear picture of the full integration.

In this case, it works better if you ask your account rep at Thycotic to work with us on putting together a feature. We do not have a unique contact at Thycotic and it really works best if your rep is pushing.

Best regards,

Maurice

avatar

Hello,

Thank you for the information. We had tested the API Launcher options and we are able to start the SS Protocol Handler (SSPH) from API. Now we need a way to start it from RDM.

How it work:
Basically we get the secretId and with this information we are able to get the sessionGuid.
So with this sessionGuid we execute C:\Program Files\Thycotic Software Ltd\Secret Server Protocol Handler>RDPWin.Bootstrapper.exe <sessionGuid> and after this the SSPH process can start the RDP or PuTTY session even if it is a Proxied session or using the option Hide Password on SS

Is there a way to integrate the SS Protocol Handler inside RDM as a new plugin or an application in file path?

We have the Thycotic Secret Server as PAM and an old remote desktop manager from another vendor. We are studying to a new Remote Desktop Manager that supports our PAM and this integration will be the most important decisive factor to choose the RDM tool.

avatar

Hello,

We are really dependent on having a counterpart from Thycotic working with us. We will gladly give a sizeable bank of hours to make this successful, but all of our previous successes were when we worked hand in hand with a partner.

You can PM me if you're account manager is unwilling to help.

Best regards,

Maurice