Support for linked account credentials in propagation script parameters
1 vote
Hello,
Would it be possible to accommodate using linked PAM accounts for the credential properties of propagation scripts? Similar to how DVLS allows a linked account to be used for connecting to a PAM identity provider.
Being limited to explicit static credentials is somewhat incompatible with PAM lifecycle password rotation of all of a systems' privileged credentials. For example, if the built in Windows Administrator is used for a propagation script to update the password for a system service, the script parameters need to be manually updated whenever the Administrator password changes.
Another way this feature would be useful is when multiple propagation scripts use the same credential. Without being able to use a linked account, the use of propagation scripts at scale becomes problematic because a password needs to be manually updated in multiple locations every time it changes.
Please let me know if any additional info is required.
Thanks
Joe
Hi @jm2,
It should be possible for us to implement this yes. I've created an internal ticket and linked it to this post.
Cheers,
Luc Fauvel
sounds good, thanks Luc