A general place for Password Safe conversations.
Recently active
Hi ! Just wanted to understand how you are handling the initial API keys /OAuth secret required to authenticate to BI PS itself.e.g. we have BI-managed service account used by few Linux endpoints . This service account is used to map a network drive. We want to fetch the latest credentials via a script from BI PS at user log on and map the network drive. To secure the api key , we are planning to put it on a network share where a Group of users will have access. But this means if the machine is compromised or the internal user wants to get the access , they can fetch the key and service account credentials. We are thinking of rotating this key in BI PS config + network share from a secure server , but this introduces another high privileged account with config access to API + possibly one more account with network share access (Though in a more secured environment). This increases complexity but the key/password is still has same level of security (when compared to keeping the key stat
How do you manage Microsoft Edge browser updates on RDS servers used for web applications?Do we need to allow continuous internet access for Edge updates and WebDriver checks, or do you manage updates in a controlled/whitelisted manner? What are the best practices to follow ?
I’d like to understand the recommended approach for onboarding local Linux dedicated accounts. Additionally, from a Linux server perspective, is there a recommended method to configure these accounts so that sudo does not prompt for a password? Thank you.
What is the recommended approach for securely managing and remotely accessing macOS systems using a password safe? Specifically, does a managed application for a VNC client support this use case, and is there an implementation guide? Thank you.
The following articles were published last week. New Knowledge Base Articles: KB0021853 - Deploying a SQL free or SQL-less U-Series appliance shows duplicate names for Session Agent and password changes not occurring KB0022527 - AWS marketplace U-Series appliance configuration wizard failing with error "Page Cannot be Displayed" KB0022767 - "Error 1722 there is a problem with this Windows installer package" when upgrading BeyondInsight Password Safe KB0022877 - Unable to view or create new installer activation key "No such host is known." http 500 errors KB0023137 - Secrets Cache Port listening error Rest Server Failed to listen on KB0023162 - Non-admin AD users cannot access PMR and EPM Policy Editor in the BI web console KB0023190 - RemoteApp sessions in Password Safe are not fully terminating which creates RDP session overlap risk KB0023198 - Web console administrator user not seeing
Hello everyone,I am currently encountering an issue when performing a managed account password change on F5 BIG-IP. I would like to describe the issue as follows:On the F5 BIG-IP device, I created a user named "btfunctional" and configured this user in PAM as a Functional Account (FA). I performed a Test Functional Account, and it completed successfully. However, when I attempt to change the password of another managed account, I encounter the following error:[btfunctional@ltm01:Active:Disconnected] ~ # Thread was interrupted from a waiting state. Password change failed.I would greatly appreciate your support and assistance with this issue.Thank you very much.
Hello everyone,We have encountered a challenging requirement during our discovery scans for a range of IP addresses. In the scan results, some assets appear with their asset names as IP addresses instead of hostnames.We need to filter out these assets and prevent them from being added to Password Safe. Does anyone know how we can filter out assets without hostnames that are still being added to Password Safe? Thank you,Prasad
Hello Team, We have one requirement for deletion of 1000+ managed systems without any Managed account.Is there any easy way to delete them in bulk? Can someone help with API script or DB Query to do so. Thanks,Prasad
Hello! Is there any news or a roadmap regarding the implementation of Direct Connect within the Pathfinder portal? This feature would significantly reduce connection time and greatly improve productivity.Unfortunately, I don’t have access to the Ideas Portal to open a request about this, but if anyone knows anything, I would be very grateful.Thanks!
Hi Team, is there any way to clean/flush the password stored in clipboard “when you do a copy of credentials from password safe , it does not get cleared automatically from your clipboard. The clipboard storers the credentials rather than clearing the clipboard after a short period of time”
The following articles were published last week. New Knowledge Base Articles: KB0021206 - Appliance self-signed certificate does not have Subject Alternate Name KB0021697 - Registering FIDO2 authenticator fails - Could not create credentials KB0021739 - Resource Broker SAML error - GetGroupForADUser for domain cred failed KB0021827 - Users are not able to ssh from Password Safe with AD account when using Centrify SSHD service KB0021846 - Onboarding Managed Accounts or Assets via a Smart Rule issue - Disassociation from DC when directory query is used KB0021872 - Secrets Cache pspca logs error "A timeout occurred" KB0021909 - What AD permissions should a bind account or directory credential have? KB0021972 - After upgrading, no accounts are showing in the Password Safe tile. KB0022073 - Pathfinder and Password Safe Cloud 24.3.1 - SAML user is removed from the local group in P
Hi,Anyone else have a need to keep password history for more than one year? A problem we face is if we need to restore a windows server from more than a year ago, we won’t be able to log in via the local administrator password as it will be unknown. I know there are some workarounds where you can reset if it is an AzureVM, but having history more than a year is needed.Anyone have any smart ways to work around this limitation?Someone has already logged an idea for this if you want to vote.Allow Password History For More Than 360 | All Product Ideas - PublicThanks
Hi Team,I am looking for creating the script to automate Application onboarding in Beyondtrust Password Safe. We are using Cloud version of Password Safe. I am exploring BT API However I dont see any API to create application in BT. I only see API to get application or to remove application or assign application to Manage account . From this List , I dont see any api to create application into BT. Requesting help here to guide how application can be created in BT using API.Regards,Imran Aliyani
hi guys, is there a way to get a list of AD managed systems without linked accounts? thank you
The following articles were published last week. New Knowledge Base Articles: KB0022504 - Clicking update connector or create connector with the type SNMP results in an error: "Form is stale" KB0022561 - Service Account Usage Report showing duplicate service accounts - Service Account Usage Report missing managed service accounts KB0022739 - Functional Account test fails - Error 26: Error locating server/instance specified KB0022969 - BeyondInsight Configuration (rememconfig.exe) tool Start Service not working - Services not starting KB0023034 - TLS 1.3 support and future removal of TLS Client Renegotiation in Password Safe KB0023119 - Asset Smart Rule address group removed after upgrading to 24.3 KB0023135 - BI Password Safe configured with RAIDUS fails to login - AuthServiceResponse rejected logon KB0023157 - WPE freezes or shows a spinning loading circle when trying to edit a polic
Hi All,I'm new to PS but have been running RS for over a year now, we export syslog via webhooks on RS and PRA to our Rapid7 SIEM and it is working well, but I cannot seem to get it to work with PS. Any ideas?
I can see several old sessions still appearing in the Active Sessions list in Password Safe, even though only today’s sessions should be showing.
Hi everyone, have any of you implemented High Availability using a proxy server, or worked with customers who have deployed this setup? If so, I’d appreciate hearing about your experience, challenges, and overall results.Please share any relatable articles, would appreciate it. Thanks!
The following articles were published last week. New Knowledge Base Articles: KB0021856 - After upgrading to 24.3 or higher, Create New Safe button is missing KB0023132 - Resource Broker fails to update with error - [Providers.IdentityServerSettingsProvider.RegenerateToken] Failed to regenerate token. KB0023134 - Where are the files for the Workforce Password Group Policy administrative template (ADMX) found?
Hi,I’m trying to find a good way to secure these generic accounts and still to be able to use them as bt- and buadmin are used on a regular basis for updates and support cases. As I have 4 appliances to manage and have high security requirements I’d need to have individual passwords, with regular changes and changes after access for each of them. It would be a challenge to manage the regular changes and make performing regular tasks challenging.I had posted an idea to use the Enterprise Updater as SPOC (Single Point of Control) which would have it’s own credentials and would have an encrypted key based connection to all appliances. From the Updater one could create individual schedules for the updates and unlock/lock them centrally. This would make tracking, planning and handling of updates a lot easier and only one generic user (buadmin) would need to be secured. I’d prefer a personal account though and leaving the generic account as a breaking glas solution. This would only cover the
Hi All, I wanted to check if there is any API available that I can use to retrieve the password of account ? We are using cloud version of Password safe. With my initial analysis , I found there is any API available that can be used to Set password for account But want to understand if there is any API available to retrieve the password as well?Awaiting response .thanks in advance.
Hi everyone,The end users are experiencing delay and slowness when taking RDP sessions through Password Safe on-prem. Usually they have to read logs and commands and the slow and delayed screen output is becoming a hassle for them, resulting in a very poor user experience.After some researching, I found a commonality in the solution that it an issue with the client’s network, however, they are not ready to accept it.According to them, when they take RDP directly from the U-series appliance, the session is much better but from the Web UI, it’s very delayed and slow.Has anyone here encountered an issue like this, if yes, how did you solve it.Thanks in advance.
Hello All, We have created the custom Mainframe platform to onboard the Mainframe account under Password safe. This functionality is working fine . We have a requirement to onboard the shared Ids on the custom Platform wherein one Id will be accessed by 8 users. Here we are facing issue that when one user checks out the Id other user gets the error saying “The account is not available during requested time”. I have seen the below KB article which says concurrent session is not available on Custom/Generic platforms and it asks to change the platform type of system to Windows/Linux which is not possible for us .https://beyondtrustcorp.service-now.com/csm?sys_kb_id=cf6c24fc47a2669015c43e7d826d4394&id=kb_article_view&sysparm_rank=2&sysparm_tsqueryId=6c5caa3f47d436501bf1db37536d43b3 My requirement here is , is there any workaround available which we can use from which users can at least view the password from Password safe for these shared ids ?. If users can view the passwo
Hi Elevate registry and allow changes only to particular section in registry HKEY_LOCAL_MACHINE\SOFTWARE\xxx and nothing else. So we know we can elevate any .reg files but we need to control because anyone can add anything into the reg file and do changes in registry. So is there any way to do this?
The following articles were published last week. New Knowledge Base Articles: KB0021770 - EPM Policy removed from Smart Rule causing error - Failed to load smart rule element KB0022852 - Internal error 500 when logging into Password Safe after configuring EPM-W as the as the password rotation agent KB0022970 - Password Safe integrated WPE fails to create policy from template nothing happens when clicking use template KB0023107 - Unable to run through the A&R configuration. Error "There was an error connecting to the server" KB0023119 - Asset Smart Rule address group removed after upgrading to 24.3 KB0023120 - Login to U-Series Appliance from Asset Page in Web console not working - Unable to connect to this Appliance KB0023129 - AD Managed Account password change failed. Error: The server could not be contacted. The LDAP server is unavailable.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.