0 vote
We have a requirement where our passwords are generated for us every 12 hours. Unfortunately they have locked down the API to CyberArk so we cannot even use that feature to get the new password each time. What I did though was just manually create a username/password credential and each day I go in and update the password that I manually get from CyberArk. What I am hoping for though was for there to be some option in the credentials that says your password expires after x hours/days/etc. Would this be something that is possible to add to the Password Management section of the credential to have something like "Password Expires After [x] hours"? Then if the credential is used again after say 12 hours, the password will be invalid and the user will be prompted for a new one?
Again, not sure if something like that would be possible, but this would fix many issues and unnecessary lockouts when attempting to use the credential after CyberArk has changed the password on us.
Am thinking something like the screenshot:
Hello,
Currently, the closest thing we have to this is the "expiration" function, which can be found in the Description tab:
Once the entry is expired, it will be marked as expired in the entry list. The feature doesn't support an hourly configuration, but I would like to know if the effect achieved by this feature is what you're looking for.
Regards,
Hubert Mireault
2020-10-07_9-30-26.png
I have just set this now with the expiry of "tomorrow" and I will see what happens with it. My only concern with this type of a solution is that you have to set the new entry for when it expires. So it could very well be right on the right track, but some slight modification in that you just tell it that each new password is valid for say 12 hours and after that point, the password would get wiped out
You could also test how the feature works by setting the date to a value in the past (you just have to choose it manually with the date picker).
I understand what you mean though, you would want the entry to expire based on when you have last set its password, without needing to manually set an expiration. I'm not sure if clearing the password automatically is easy to do, but we could make it so that when you edit the entry, a message lets you know that the password is expired, so you would know to change it.
It's an interesting feature for sure, I'll open a ticket for this. If you have any other details you'd like to see regarding this, please let us know.
Regards,
Hubert Mireault
I just tried setting that the password expires yesterday but it is still allowing me to use the credential & current password.
I see what you mean, it looks like you can't do a "view password" on the credential itself, but you can still use it in your entries.
Well for now, there isn't a great workaround for your scenario, but we will update this thread once we have more information on the new feature.
Regards,
Hubert Mireault
thank you for this. Yeah it would be a useful feature to prevent accidentally locking out your account if you know how long your password is good for.