Description
Manage MongoDB database privileged accounts.
Vendor
This platform is designed for remote account management for the following target:
| Vendor | MongoDB |
|---|---|
| Product | MongoDB |
| Product Category | Database |
| Product Subcategory | |
| Product Versions | 6.0, 7.0 |
CyberArk
This platform works with the following CyberArk versions:
| CyberArk Solution | Privileged Credentials Management |
|---|---|
| CyberArk Product | Central Policy Manager (CPM) |
| CyberArk Versions | 12.2 or higher |
| Artifact Version | 13.2.0.259 |
| Out of the Box | NO |
| Out of the Box in versions |
Support & Certification
| Support Level | STANDARD |
|---|---|
| Developed by | CyberArk |
| Certification Level | CERTIFIED |
| Connection Methods |
Actions
The following table lists the supported management actions for this platform:
| Action | Supported | Permissions |
|---|---|---|
| Verify | YES | Users must have 'read' permissions on their authentication database. |
| Change | YES | For users to change their password, grant users 'changeOwnPassword' permissions on the users db. |
| Reconcile | YES | Assign users one of the following roles:
|
| Delete | NO |
Linked Accounts
The following linked accounts are in use by the plugin.
Logon Account
| Supported | NO |
|---|---|
| Required | NO |
| Platfroms | |
| Permissions |
Reconcile Account
| Supported | YES |
|---|---|
| Required | YES |
| Platfroms | MongoDB |
| Permissions | Assign users one of the following roles:
|
Installation
Import Platform
Do the following to import the platform:
| Step | How To | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Add missing file categories | Add the following file categories, if they do not already exist:
| ||||||||||||
| Import the platform | See Add new platform topic in the Online Help Center or in the Privileged Account Security Implementation Guide. |
Configuration
Platform Settings
Specify the following parameters at the platform level:
| Parameter Name | Description | Acceptable Values | Default Value |
|---|---|---|---|
| UseSSL | Whether or not an SSL connection is used to connect to the remote device. | Yes, No | Yes |
| PasswordForbiddenChars | List of characters that cannot be used when generating a new password. | List of unique special characters | \:@| |
Account Settings
Account Mandatory Parameters
Specify the following parameters on the account:
| Parameter Name | Description | Acceptable Values |
|---|---|---|
| Username | The name of the user on the remote machine to whom this password belongs. | |
| Database | User's authentication database. This parameter is case sensitive. | |
| Addresses | List of hostnames (IP or DNS and optional port). At least one must be specified. This parameter is case sensitive. |
Account Optional Parameters
Specify the following parameters on the account:
| Parameter Name | Description | Acceptable Values | Default Value |
|---|---|---|---|
| UseSSL | Whether or not an SSL connection is used to connect to the remote device. This parameter is case sensitive. | Yes, No | UseSSL defined in the platform |
| ReplicaSet | Name of the replica set |