Description
Securely connect to PingOne for Enterprise Web Interface.
Vendor
This connection component is designed for secure connection to the following target:
| Vendor | Ping Identity |
|---|---|
| Product | PingOne for Enterprise |
| Product Category | Authentication |
| Product Versions |
CyberArk
This connection component works with the following CyberArk versions:
| CyberArk Solution | Privileged Session Management |
|---|---|
| CyberArk Product | Privileged Session Manager (PSM) |
| CyberArk Versions | 11.x |
| Artifact Version | |
| Out of the Box | NO |
| Out of the Box in versions |
Support & Certification
| Support Level | STANDARD |
|---|---|
| Developed by | CyberArk |
| Certification Level | CERTIFIED |
Linked Accounts
Logon Account
| Supported | NO |
|---|---|
| Required | NO |
| Platfroms | |
| Permissions |
Prerequisites
The following prerequisites are required on the machine running this connection component:
Google Chrome installed
Installation
Do the following to set up the connection component:
| Step | How To |
|---|---|
| Create the Connection Component |
|
| Add the connection component to a platform |
|
Configuration
AppLocker Settings
If your PSM server is hardened, you will need to make the following change in order for Google Chrome to be excluded from the Applocker rules:
1. On the PSM Server, open Powershell as Administrator from C:\Program Files (x86)\Cyberark\PSM\Hardening
2. Run notepad PSMConfigureAppLocker.xml
3. Towards the end of the PSMConfigureAppLocker.xml file, before the end tag, add the following line:
<Application Name="Google Chrome" Type="Exe" Path="C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" Method="Hash"/>
Note - if Google Chrome is not installed in the suggested path then the value of Path will be different.
4. In the same Powershell window run PSMConfigureAppLocker.ps1
Connection Component Settings
User Parameters section
Parameters that determine the information that users will be required to supply while initiating the PSM connection. These parameters can be overridden at platform or account level.
| Parameter Name | Description | Acceptable Values | Default Value | Visable | Requierd | Type | Enforce In Dual Control Request |
|---|---|---|---|---|---|---|---|
| AllowMappingLocalDrives | Whether or not the local drives will be mapped | Yes/No | No | No | Yes | CyberArk.TransparentConnection.BooleanUserParameter, CyberArk.PasswordVault.TransparentConnection |
Target Settings section
Parameters that define specific target machines settings. These parameters can be overridden at platform or account level.
| Parameter Name | Path | Description | Acceptable Values | Default Value |
|---|---|---|---|---|
| ActionTimeout | TargetSettings → ClientSpecific | int | 10 | |
| PageLoadTimeout | TargetSettings → ClientSpecific | int | 30 | |
| RunValidations | TargetSettings → ClientSpecific | Yes/No | Yes | |
| LogonURL | TargetSettings → Web Form Settings | URL | https://admin.pingone.com | |
| WebFormFields | TargetSettings → Web Form Settings | email > {Username} (SearchBy=ID) | ||
| EnforceCertificateValidation | TargetSettings → Web Form Settings | Yes/No | Yes |
Account Settings
Account Mandatory Parameters
Specify the following parameters on the account:
| Parameter Name | Description | Acceptable Values |
|---|---|---|
| Username | The username to authenticate with | String |