cyberark-aws-auto-onboarding icon indicating copy to clipboard operation
cyberark-aws-auto-onboarding copied to clipboard

Windows supported ?

Open edhedh opened this issue 4 years ago • 1 comments

When reading the documentation it states: "CyberArk provides a solution that detects unmanaged privileged SSH Keys in new created Unix/Linux EC2 instances in Amazon Web Services (AWS) environments ..." and "CyberArk currently supports onboarding SSH keys for the following AWS accounts: AWS Linux, RHL AMIs: ec2-user Ubuntu: ubuntu user Centos: centos user openSuse: root user Debian: admin user Fedora: fedora user"

However further down it states things related to Windows EC2 instances. E.g. "Target safe for Windows accounts, The name of the Safe to which the windows accounts will be onboarded (Note: The deployment will fail if the safe already exist)" and e.g. "List of Windows instances that require this command to be run manually: Microsoft Windows Server 2016 Base Microsoft Windows Server 2016 Base with Containers ..."

I don't understand why Windows is mentioned ? Does it mean that cyberark-aws-auto-onboarding support both Linux and windows EC2 instances or is the doco wrong ?

edhedh avatar Apr 13 '20 10:04 edhedh

Thanks for reaching out,

Regarding your question: Yes. The solution supports discovering and auto on boarding of Linux AND Windows instances. The instances can be new instances or old instances that changed their status from any status to 'Running' (we are listening to the change of instances status). In order for the solution to on board and manage these instances - it is crucial that the Instance's Key Pair will be On Boarded first to the Key Pair safe (which is being set during the Auto On Boarding Deployment).

yogevh avatar Apr 22 '20 05:04 yogevh