Create a Vault
Create a vault to connect TotalAppSec to your Central Credential Provider (CCP). After the vault is created, you can link it to an authentication record and reference the credentials stored in the vault instead of typing them into the record.
Navigate to Configuration > Vault and click New Vault. Provide the following information.
Basic Details
Enter a name and an optional description for the vault, and select how the vault is reached.
-
Internal: The vault is reachable on your internal network only. An internal scanner appliance is used to connect to it.
-
External: The vault is reachable over the internet.
You can also add tags to the vault. Tags help you organize vaults and control which users can access them.
Provider
Select CyberArk CCP as the provider and provide the connection details for your CyberArk Central Credential Provider.
-
Base URL: The URL of the Central Credential Provider web service.
-
Web Service Path: The path to the credential retrieval web service.
-
AppID: The application identifier that CyberArk uses to authorize the request.
Select how the scanner authenticates to the vault.
-
Client Certificate (mTLS): Upload the client certificate and private key in PEM format, and enter the private key passphrase. You can also upload a CA bundle in PEM format and select Verify TLS to validate the vault certificate. After the vault is saved, you can view or download the certificate you uploaded.
-
Allowed Machines: Identify the scanner to CyberArk by IP address, DNS name, host name, or CIDR range. Use this option when your CyberArk configuration authorizes requests by machine rather than by certificate.
Other Configurations
Enter the connection timeout, in seconds, that the scanner waits for a response from the vault.
Variables
Define the credentials that this vault provides. For each credential, enter the CyberArk Account Name and Safe that identify where the credential is stored. Each entry creates two variables, one for the user name and one for the password, which become available when you link the vault to an authentication record.
Review and Confirm
Review the vault configuration and click Save to create the vault.