Hello,
After adding a Sensitive Data type property to an AnyIdentity provider account attributes, the property can be populated when adding the credential to a PAM vault, but afterwards it cannot be viewed or edited using either the web gui or powershell cmdlet Get-DSPamAccount.
Using DVLS v2023.3.12
Please let me know if you would like any additional info.
Thanks
Joe
Hello Joe,
Any account properties of an AnyIdentity provider that are set as Password (sensitive) cannot be viewed afterward, they can only be replaced:
To modify the information, you would need to enable the password field, but it is only to replace it:
Best regards,
Richard Boisvert
bca799d5-7303-470e-987b-a38bec19a3a3.png
e126f8a9-0ff8-4c32-944e-1c8b9ce06137.png
Hello Joe,
After discussing your issue with a developer, he mentioned that "Sensitive Data" is a different type than password:
That said, passwords and sensitive data are the same thing in the backend; it's just that you usually only have one password. This is only to specify that it will enter the script with a secureString.
Can you please provide more details about your use case for retrieving sensitive data afterward?
Best regards,
Richard Boisvert
dc3a2c08-a2d9-460e-bc99-63e8144c568b.png
Hi Richard,
Thanks for your assistance.
The use case is an AnyIdentity template for storing Master Keys and/or pass phrases that dont have a corresponding username. If I change the property type to 'Password' instead of 'Sensitive Data', then then value is retrievable.
However, what is the purpose of having a data type of 'Sensitive Data' if it cannot be checked out and retrieved for use? I had expected it to work the same way the passphase and certicate properties are viewable after checking out the builtin PAM credential type called 'certificate'.
Pls let me know if you would ike any additional information.
Thanks
Joe
16e1e1e0-5911-4be9-9ae2-a8e408cb71b3.png
Hello Joe,
I talked with Richard and we thought you wanted to see the sensitive data when you edit the account. But you would like to see it after the checkout, that would make sense I think. My question is : Do you expect a rotation on that sensitive ? I guess not, you only want to see it during the checkout than nobody can see that sensitive data, but I want to be sure to understand what you expect.
Best regards,
François Dubois
Hi François,
Thanks for confirming. With the use case I described, there is no need to rotate the sensitive data, just need to be able to view it after checkout.
Joe
Hello Joe,
That makes sense, I'm opening a ticket for that.
Best regards,
François Dubois