Info Security Memo
  • Blog
  • Sitemap
    • Categories
  • Contact
  • About
  • Resources
  • Tools
  • 51sec.org

Build Confidence

Focusing on Information Security 

Info Security Notes

Thycotic Secret Sever Cloud - Distributed Engine

7/4/2021

0 Comments

 
Thycotic Secret Sever Cloud - Distributed Engine

All interaction between the SSC tenant and your on premises network uses our distributed engine service to communicate. The work tasks that distributed engine completes includes Active Directory authentication, password changing, and heartbeat. The machine where the engine is installed must be able to communicate outbound on ports 443 and 9354.




SS Cloud Architecture:

https://ift.tt/3wfW4hP


Install the Distributed Engine

  1. Navigate to Admin > Distributed Engine

  2. Click the Download Engine Installer button for either 64-bit or 32-bit.

    Note: You can install distributed engine on your workstation or laptop for testing purposes, but for production installs, the distributed engine server should be installed on a server. SS uses the distributed engine to communicate with your domain, so if your machine is turned off, users cannot log on with their domain accounts, and heartbeat and remote password changing will fail.

  3. Run setup.exe as an administrator to install the engine service. This will install into Thycotic Software Ltd\Distributed Engine.

  4. Go to Admin > Distributed Engine.

  5. Click Manage Sites.

  6. Click Manage New Engines. There should be a new engine available.

  7. Click the Assigned Site dropdown list and select Default.

  8. Approve it by clicking the check box to the right.

  9. Validate the engine’s connectivity:

    1. Go to Admin > Distributed Engine > Manage Sites.

    2. Click the Default site.

    3. Click the Validate Connectivity button to test the communication between the engine and SS. It may take several minutes for the engine to register. If it does not immediately validate wait a few minutes and try again.







Configure Active Directory Integration

Active Directory integration allows users to log in with their domain credentials. Connections to your domain are routed through the distributed engine service running in your network.

  1. On the dashboard, create a new Active Directory secret from the create secret widget in the upper right hand corner.

    Note: The domain account should be able to read users and groups from the domain you want to sync. For detailed information on the rights required, please see Active Directory Rights for Synchronization Account (KB).

  2. Type the domain, username, and password in the Create Secret form.

  3. Save the secret.

  4. Navigate to Admin > Active Directory.

  5. Click Edit and check the boxes for Enable Active Directory Integration and Enable Synchronization of Active Directory.

  6. Click the Save button.

  7. Click the Edit Domains button.

  8. Click the Create New button.

  9. Type your FQDN and a friendly domain name that users will see on the login page.

  10. Click Sync Secret to select the secret you just created.

    Note: The domain site is set to default. This means that the Active Directory authentication and synchronization will run through the distributed engine service installed on your network.

    Note: Do not select “Enable Login from AD.” If you do, you cannot set the domain groups later in this instruction.

  11. Click the Save and Validate button.

  12. Click the Back button.


  13. Click the Edit Synchronization button. The Synchronization Edit page appears.

  14. In the Available Groups list, click each domain group that you want to log on in the SSC instance and click the the < button to move the group to the Synchronized Groups list.

  15. Click the Save button.

  16. Click the Synchronize Now button to start the user and group synchronization immediately. The synchronization process runs automatically, but to get immediate results, you can start it manually.









Test Heartbeat and Remote Password Changing

Heartbeat ensures the secrets you have stored have the correct password, and Remote Password Changing (RPC ) changes passwords on demand or a schedule.

  1. Navigate to Admin > Remote Password Changing.

  2. Click the Edit button.

  3. Click to select the Enable Remote Password Changing and Enable Heartbeat check boxes.

  4. Click the Save button.


  5. Click the Run Now button in the Remote Password Changing and Heartbeat Log sections. This runs the heartbeat and RPC processes immediately.

  6. Go to the secret you created for domain synchronization in the previous section or create a new test secret to use.

  7. A brand new secret’s Last Heartbeat status should be pending or processing. Once heartbeat completes you should one of these statuses:

    • Unable to Connect: SS could not reach the target machine. This could be a firewall issue or the machine name or IP address is wrong.
    • Failed: SS could connect but could not authenticate. This likely means the password on the secret is incorrect.
    • Success: SS successfully connected with the username and password.
  8. You can test password changing by viewing a secret and clicking the Change Password Remotely button.

    Note: This will change the password on the target system.

  9. You can view the status of password changes and heartbeats in the log at Admin > Remote Password Changing.









References

  • Secret Server Cloud Quick Start














via Blogger https://ift.tt/3xnqlNa
July 04, 2021 at 07:39AM Thycotic
0 Comments



Leave a Reply.

    Categories

    All
    Architecture
    Blog
    Checkpoint
    Cisco
    Cloud
    CyberArk
    F5
    Fortigate
    Guardium
    Juniper
    Linux
    Network
    Others
    Palo Alto
    Qualys
    Raspberry Pi
    Security
    SIEM
    Software
    Vmware
    VPN
    Wireless

    Archives

    March 2024
    February 2024
    January 2024
    December 2023
    November 2023
    October 2023
    September 2023
    August 2023
    July 2023
    June 2023
    May 2023
    April 2023
    March 2023
    February 2023
    January 2023
    December 2022
    November 2022
    October 2022
    September 2022
    August 2022
    July 2022
    June 2022
    May 2022
    April 2022
    March 2022
    February 2022
    January 2022
    December 2021
    November 2021
    October 2021
    September 2021
    August 2021
    July 2021
    June 2021
    May 2021
    April 2021
    March 2021
    February 2021
    January 2021
    December 2020
    November 2020
    October 2020
    September 2020
    August 2020
    July 2020
    October 2019
    September 2019
    June 2019
    July 2018
    May 2018
    December 2017
    August 2017
    April 2017
    March 2017
    January 2017
    December 2016
    November 2016
    October 2016
    September 2016
    August 2016
    July 2016
    June 2016
    May 2016
    April 2016
    March 2016
    February 2016
    January 2016
    December 2015
    November 2015
    October 2015
    September 2015
    August 2015
    July 2015
    June 2015
    May 2015
    April 2015
    March 2015

    Print Page:

    RSS Feed

    Email Subscribe
Powered by Create your own unique website with customizable templates.
  • Blog
  • Sitemap
    • Categories
  • Contact
  • About
  • Resources
  • Tools
  • 51sec.org