Cyber-Ark特权身份管理API
有谁知道是否有任何类型的 API 可用于 Cyber-Ark 特权身份管理将其与企业应用程序集成?
Do anybody know if there is any sort of API available for Cyber-Ark Privileged Identity Management to integrate it with an enterprise applications?
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。

绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论
评论(4)
我认为答案可能是 50% 是,50% 不是。当然,Cyber-Ark 为其 Vault 对象提供 Web 服务和 API,因此您应该能够通过受信任的应用程序从 Vault 检索密码。 赛博方舟网站:
但除了使用其 Vault 对象之外,我并不完全确定。我目前正在寻找有关其 Vault Web 服务的更多信息,并且我认为我需要注册成为合作伙伴才能获取该信息。如果我再学习的话,我会发布后续内容。
I think the answer might be 50% yes, 50% no. Definitely Cyber-Ark offers web services and an API for their Vault objects, so you should be able to retrieve passwords from the Vault from a trusted application. There is a paragraph of sales information on Cyber-Ark's website:
But beyond working with their Vault objects, I'm not entirely sure. I'm currently looking for more information on their Vault web services, and I think I need to register to be a Partner to get that information. I'll post a follow-up if I learn anymore.
您应该为每台服务器购买一个 API 许可证,以便对授权应用程序的保管库具有只读访问权限。
他们提供Java、C#等库,您将授权密钥材料放置在服务器上以使其能够访问。
You are suppose to purchase an API license per server to have read-only access to the vault for authorized applications.
They provide Java, C#, etc. libraries and you place authorization key material on the server to enable it access.
它被称为 CyberArk Application Identity Manager,是一个完整的子产品。
我能找到的唯一参考:
http://lp.cyberark.com/rs/cyberarksoftware/images/ds-application-identity-manager-10-20-2014-en.pdf
It is called CyberArk Application Identity Manager, an entire sub-product.
The only reference I could find:
http://lp.cyberark.com/rs/cyberarksoftware/images/ds-application-identity-manager-10-20-2014-en.pdf
CyberArk 创建了 Conjur。它是开源且免费的。它包含自己的保管库,旨在用于动态应用程序访问管理。特别是,Conjur 及其升级版 Conjur Enterprise 应确保完整的 DevOps 管道的安全。付费版本可以与Vault解决方案(CyberArk的PAS Core解决方案)集成。
对于静态应用程序,CyberArk有Credential Provider、Central Credential Provider和ASCP(我现在忘记了它的全名)。这些解决方案是基于代理的,而 Conjur 是无代理的。由于它们是基于代理的,因此它们仅适用于变化相对较慢的环境,因为需要在每台服务器上安装代理才能提供来自 Vault 的凭据。
这些解决方案具有 REST API、CLI 和 SDK 功能。
CyberArk created Conjur. It is open source and free. It contains its own Vault and is intended for dynamic Application Access Management. In particular, Conjur and its upgrade Conjur Enterprise should secure the complete DevOps pipeline. The paid version can be integrated with the Vault solution (the PAS Core solution of CyberArk).
For static applications, CyberArk has the Credential Provider, Central Credential Provider and ASCP (I forgot the full name of it now). These solutions are agent based while Conjur is agentless. Because they are agent based, they are only intended for environments with comparatively slow changes as an agent needs to be installed on every server in order to provide the credentials from the Vault.
These solutions have REST API, CLI and SDK capabilities.