CyberArk

MongoDB

Description

Manage MongoDB database privileged accounts.



Vendor

This platform is designed for remote account management for the following target:

VendorMongoDB
ProductMongoDB
Product Category

Database

Product Subcategory


Product Versions6.0, 7.0



CyberArk

This platform works with the following CyberArk versions:

CyberArk Solution

Privileged Credentials Management 

CyberArk Product

Central Policy Manager (CPM)

CyberArk Versions12.2 or higher
Artifact Version

13.2.0.259

Out of the Box

NO

Out of the Box in versions



Support & Certification

Support Level

STANDARD

Developed byCyberArk
Certification Level

CERTIFIED

Connection Methods



Actions

The following table lists the supported management actions for this platform:

ActionSupportedPermissions
Verify

YES

Users must have 'read' permissions on their authentication database.
Change

YES

For users to change their password, grant users 'changeOwnPassword' permissions on the users db.

Reconcile

YES

Assign users one of the following roles:

  • UserAdmin
  • dbOwner
Delete

NO




Linked Accounts

The following linked accounts are in use by the plugin.

Logon Account

Supported

NO

Required

NO

Platfroms


Permissions


Reconcile Account

Supported

YES

Required

YES

Platfroms

MongoDB

Permissions

Assign users one of the following roles:

  • UserAdmin
  • dbOwner



Installation

Import Platform

Do the following to import the platform:

StepHow To
Add missing file categories

Add the following file categories, if they do not already exist:

File Catagory NameTypeValid ValueRequierd
UseSSL Text
No
ReplicaSetText
No
Import the platform

See Add new platform topic in the Online Help Center or in the Privileged Account Security Implementation Guide.



Configuration

Platform Settings

Specify the following parameters at the platform level:

Parameter NameDescriptionAcceptable ValuesDefault Value
UseSSL

Whether or not an SSL connection is used to connect to the remote device.
This parameter is case sensitive.

Yes, NoYes
PasswordForbiddenChars

List of characters that cannot be used when generating a new password.

List of unique special characters\:@|



Account Settings

Account Mandatory Parameters

Specify the following parameters on the account:

Parameter NameDescriptionAcceptable Values
UsernameThe name of the user on the remote machine to whom this password belongs.

DatabaseUser's authentication database.
This parameter is case sensitive.

AddressesList of hostnames (IP or DNS and optional port).
At least one must be specified.
This parameter is case sensitive.

Account Optional Parameters

Specify the following parameters on the account:

Parameter NameDescriptionAcceptable ValuesDefault Value
UseSSL

Whether or not an SSL connection is used to connect to the remote device.

This parameter is case sensitive.

Yes, NoUseSSL defined in the platform
ReplicaSetName of the replica set