Vaults
A vault is a connection to an Central Credential Provider (CCP) that stores the credentials used by your authentication records. When you link an authentication record to a vault, the scanner retrieves the credential from the vault at scan time instead of using a value stored in the authentication record. Only a reference to the credential is saved in TotalAppSec.
Vaults are useful when your organization manages production credentials centrally and does not allow them to be stored in other applications. Because the credential is read from the vault each time a scan runs, a password that is rotated in the vault is picked up automatically, and you do not need to edit the authentication record.
This release supports CyberArk Central Credential Provider (CCP) as the vault provider.
Vaults are available to TotalAppSec subscriptions.
Vaults Tab
Navigate to Configuration > Vault to view the vaults in your subscription. The tab displays the vault name, provider, validity, the date on which the vault was last validated, and the tags added to the vault.
From the Vault tab, you can:
- Create a vault. See Create a Vault.
- View, edit, tag, or delete a vault, and review the authentication records that use it. See Manage Vaults.
- Search for vaults using Qualys Query Language (QQL) tokens, and group the list by provider, validity, or reachability. See Search Tokens for Vault.
Validity of a Vault
The Validity column shows whether the scanner was able to retrieve a credential from the vault during the most recent scan that used it.
-
Valid: The credential was retrieved successfully.
-
Invalid: The credential could not be retrieved. Review the vault configuration and the connectivity between the scanner and the vault.
The Last Validated column shows when the validity was last updated. Validity and Last Validated are updated automatically after each scan that uses the vault, so you do not need to open the scan results to confirm that the integration is working.
Each scan that uses a vault-linked authentication record also reports QID 150615 (Scanner Vault Diagnostics). This QID lists the safe and account name for each credential, and whether the credential was retrieved successfully.
Activity Tracking
Vault create, edit, and delete actions are recorded in the action log, so you can review the changes made to a vault and the user who made them.
Permissions for Vaults
Managing vaults requires the VAULT.CREATE, VAULT.EDIT, and VAULT.DELETE permissions. These permissions are assigned to the WAS Manager role by default.