This document provides step-by-step information on how to register a credential profile.
Requirements
- Must have a system administrator role.
The credential and device profiles serve as a template for new credentials on devices that fit one of these types of profile. But once you have registered the Credential, you have complete freedom to change the settings for executing the credential. Changing profiles also doesn't change the credential settings already registered.
Registering a Credential Profile
- In Segura, on the navigation bar, hover the mouse over the Product Menu and select Executions.
- In the side menu, select Management > Credential profiles.
- In the Credential profiles report, click the Add button.
- In the Credential execution profiles form, fill in the fields:
- On the Information tab, fill in:
- Name*: name of the created profile.
- Priority*: priority level.
- Enabled*: activates the registration.
- Immediate password change?*: enables the immediate password change at the time of registration.
- Interval for first change (in minutes): time interval for the first change.
- On the Execution tab, in the Credential password change settings section, fill in:
- Enable automatic change: enables the activation of automatic change.
- Plugin: choose from the options in the list.
- Template: choose from the options in the list.
- In the Credential status settings section, fill in:
- Manage account status: enables the management of the account state.
- Plugin: choose from the options in the list.
- Activation template: choose from the options in the list.
- Plugin: choose from the options in the list.
- Disabling template: choose from the options in the list.
- In the Authentication settings section, fill in:
- Use own password to connect: enables using the own password to connect.
- Authentication credential: choose from the options in the list, to use the same credential.
- Credential username: enter the username of the credential to use a device-based credential.Info
For example in the Credential username field, imagine that all Linux servers contain a local user with username linuxuser whose responsibility is to change the other passwords hosted on the same server. And that this user has different passwords from server to server.
However, as this credential is managed by Segura , you can fill in the Credential username with username linuxuser so that Segura uses the correct device-to-device credential.
- On the Criteria tab, in the Apply profile to the passwords section, fill in:
- Product: enable the use of the product.
- Product (comma-separated): enter the product.
- Vendor*: select the desired vendor.
- Device type*: select the desired device.
- Credential type*: select the desired credential type.
- On the Review tab, check the registered data.
- On the Information tab, fill in:
- Click Save.
After registration, the credential execution profile will be created. The created profiles are valid for new credentials and existing ones, as long as they fit the registered profile.
Do you still have questions? Reach out to the Segura Community.