Description
Manage AWS Aurora PostgresSQL privileged accounts. The plug-in will authenticate to an AWS Aurora PostgresSQL RDS Instance via ODBC.
Vendor
This platform is designed for remote account management for the following target:
| Vendor | Postgres |
|---|---|
| Product | PostgresSQL |
| Product Category | Database |
| Product Versions | 14.6 |
CyberArk
This platform works with the following CyberArk versions:
| CyberArk Solution | Privileged Credentials Management |
|---|---|
| CyberArk Product | Central Policy Manager (CPM) |
| CyberArk Versions | 9.x, 10.x, 11.x, 12.x |
| Artifact Version | 1.0 |
| Out of the Box | NO |
| Out of the Box in versions | N/A |
| Available in Privilege Cloud | YES |
Support & Certification
| Support Level | STANDARD |
|---|---|
| Developed by | CyberArk |
| Certification Level | CERTIFIED |
| Connection Methods | HTTP/HTTPS |
Actions
The following table lists the supported management actions for this platform:
| Action | Supported | Permissions |
|---|---|---|
| Verify | YES | |
| Change | YES | |
| Reconcile | YES | |
| Delete | NO |
Linked Accounts
The following linked accounts are in use by the plugin.
Logon Account
| Supported | NO |
|---|---|
| Required | NO |
| Platforms | |
| Permissions |
Reconcile Account
| Supported | YES |
|---|---|
| Required | NO |
| Platforms | |
| Permissions |
Prerequisites
The following prerequisites are required on the machine that runs this plugin :
PostgresSQL ODBC Driver (v16.0) installed on the CPM machine. The ODBC driver can be found on postgres' website. Verify that the firewall rules \ ports are opened to the AWS Aurora PostgresSQL instance by testing the ODBC Driver on the CPM machine.
Additional resources for installation can be found on Microsoft's website.
Configuration
Platform Settings
Specify the following parameters at the platform level:
| Parameter Name | Description | Acceptable Values | Default Value |
|---|---|---|---|
| Port | The port used to connect to the AWS MSSQL instance | Integer | 5432 |
| ConnectionCommand | The ODBC connection string which will include the ODBC Driver and connection details | Driver={PostgreSQL UNICODE};Server=%ADDRESS%;[Database=%DATABASE%;]Uid=%USER%;Pwd=%LOGONPASSWORD%;Port=%PORT% | |
| ChangeCommand | The legal SQL statement template that will be used to change the password on the required database. | SQL Statement | ALTER ROLE "%USER%" PASSWORD '%NEWPASSWORD%'; |
| ReconcileCommand | The legal SQL statement template that will be used to reconcile the password on the required database. | SQL Statement | ALTER ROLE "%USER%" PASSWORD '%NEWPASSWORD%'; |
| Debug | To enable debug logs | Yes, No | No |
Account Settings
Account Mandatory Parameters
Specify the following parameters on the account:
| Parameter Name | Description |
|---|---|
| Username | Username of the target account |
| Address | Address of the AWS MSSQL instance |
| Database | A database name the target account has access to. Note that this is a required property, otherwise the ODBC connector attempts to connect to the base database, which no newly created role has access to by default. |