Skip to main content
Version: Axidian Privilege 3.0

Configuration

Licenses

The section contains Axidian Privilege licensing information.

The section displays the following data:

  • Installation ID — a unique installation code is required to generate a license.
  • User licenses available — total number of user licenses.
  • User licenses used — total number of licenses used.
  • Resource licenses available — total number of resource licenses.
  • Resource licenses used — number of licenses used.

The following data is displayed for each license:

  • Start date — license start date.
  • End date — license expiration date.
  • User licenses — total number of user licenses.
  • Resource licenses — total number of licenses used.
  • Issue date — license release date.

Add License

Click Add and select a license file.

Removing Licenses

Mark the required license and click Delete.

System Settings

OptionDescription
Number of failed OTP access attempts allowedAfter exceeding this value the user will be temporarily blocked, i.e. will not be able to enter OTP.

Min value: 0
Default value: 10
Max Value: 99

0 means that no blocking is applied, i.e. the number of input attempts is not limited.
Lockout durationDefines the period of time after which the user will be unblocked and will be able to enter OTP again.

Min value: 1
Default value: 10
Max Value: 9999

User Connection

caution

Manage User Connections privileges are required to work with user connections. The following privileges are required:

  • UserConnectionType.Create
  • UserConnectionType.Read
  • UserConnectionType.Update
  • UserConnectionType.Delete

Axidian Privilege has the following built-in user connection types:

  • RDP
  • SSH
  • Telnet
  • PostgreSQL

Built-in types cannot be changed or deleted.

It is also possible to add custom user connection types.

Adding Custom User Connection Types

To add a new connection type, you need to research the client application and develop a template for Axidian Privilege ESSO Agent. The new connection type is unique for each application, for development please contact Technical Support.

Service Connection

caution

Manage Service Connection Types privileges are required to work with service connections. The following privileges are required:

  • ServiceConnectionType.Create
  • ServiceConnectionType.Read
  • ServiceConnectionType.Update
  • ServiceConnectionType.Delete

Axidian Privilege has the following built-in service connection types:

  • Windows
  • SSH
  • Microsoft SQL Server
  • MySQL
  • PostgreSQL
  • Oracle Database
  • Cisco IOS
  • Inspur BMC

Built-in types cannot be changed or deleted.

It is also possible to add custom service connection types.

Adding Custom Service Connection Types

caution

If your PAM installation's management server is installed on a Windows host, you can only add connectors with a powershell template.

If your PAM installation's management server is installed on a Linux host, you can only add connectors with a bash template.

  1. Open the ConfigurationService Connection section.
  2. Click Add Service Connection Type.
  3. In the window that opens, upload the ZIP archive with the connector file.
  4. Specify the Name of the service connection or use the value loaded from the metadata.
  5. Enter the Description of the service connection. Optional.
  6. Finish operation by clicking Add.

Connectors preparation

To prepare a ZIP archive with the connector file, use the Connector Creation Tool.

Editing Custom Service Connection Types

  1. Open the ConfigurationService Connection section.
  2. Click Edit next to the desired service connection type.
  3. Click Download archive and select a folder on your computer to save the current ZIP archive with the connector file. This archive will be needed to restore the previous state of the service connection if an error occurs when loading a new archive.
  4. Upload a new ZIP archive with connector file.
  5. If necessary, edit Name and/or Description.
  6. Finish editing by clicking Save.

Connector Script Code Viewing

  1. Open the ConfigurationService Connection section.
  2. Click Show script code next to the desired service connection type.

Custom Connection Types Deleting

  1. Open the ConfigurationService Connection section.
  2. Click Delete next to the desired service connection type.
info

A service connection type cannot be deleted if a resource with that type exists.

Uploading the SSH Connector Template

The service operations template is unique for each *nix distribution. The PAM distribution includes templates for the following *nix distributions:

  • Alt
  • Astra
  • CentOS
  • Debian
  • FreeBSD
  • Gentoo
  • Oracle
  • RedOS
  • RHEL
  • Rocky
  • SLES
  • Ubuntu

Path to the templates in the PAM distribution: AxidianPAM_3.0_RU\indeed-pam-tools\ssh-templates\.

To add a template to Axidian Privilege:

  1. Open the ConfigurationService Connection section.
  2. Inside the SSH block, click Add.
  3. Select the file with the SSH connector template you need from the distribution by path AxidianPAM_3.0_RU\indeed-pam-tools\ssh-templates\.

If you need help with development of the new template, please contact Technical Support.

Network Location

The section contains information about adding network locations to limit the use of resources issued by addresses.

Adding the Network Location

Click Add.

Enter a Name and add the Network addresses of the resources to which you want to issue a limited connection.