CyberArk PSM sessions with user specific setting overrides to personal vault entries not working
Sorry in advance, this is a little bit complicated to explain, so I HAVE to be thorough to get it completely explained.
our history with RDM:
We are running RDM for years, and below worked in the past. Due to the problems with subconnections -> subentries introduced with version 2022.3.4.0 in the tool, it took us a LONG time to upgrade all instances.
So now recently we've upgraded our clients to one of the latest version 2023.3.36.0 and some have issues described below.
Cyberark cannot find the requested account in vault and gives error : 1062E The requested account does not exist in the Vault....
this DID work before !
This is our requirement:
This is high overview of our setup:
Since our upgrade (from 2022.2.21.0 to 2023.3.36.0 ) this fails, CyberArk is giving error : 1062E The requested account does not exist in the Vault, or you do not have the appropriate....
How to debug this:
I found out... we can easily debug the setting.. don't even need a CyberArk PSM server or start a session.
Temporary workaround:
Detailed configuration:
P12.PNG
P04.PNG
P11.PNG
P10.PNG
P03.PNG
P02.PNG
P01.PNG
P00.PNG
Hello Ben,
Thank you for contacting us on that matter.
I will run some tests to reproduce this on my side.
I'll keep you posted as soon as possible.
Best regards,
Patrick Ouimet
Thanks already
We note that this behaviour is not always reproducible. We don't have that in our own datasource.
it may have to do with the datasource where the entries are located... or the datasource settings.
the message box popup however already helps a lot in troubleshooting.
we found that sometimes it worked if we enabled 'always ask for password' checkbox on the (fake) credential entry in the user vault... but not always
Regards, Ben
Hello Ben05,
I sent you an email to schedule a session and have a look at this configuration.
Best regards,
Patrick Ouimet