Skip to content

Commit faecbe9

Browse files
authored
Merge pull request #352 from netwrix/npws/release_9_3_0
Npws/release 9 3 0
2 parents 9face25 + 40efdab commit faecbe9

File tree

312 files changed

+14760
-2
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

312 files changed

+14760
-2
lines changed
Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,10 @@
1+
{
2+
"label": "Configuration",
3+
"position": 40,
4+
"collapsed": true,
5+
"collapsible": true,
6+
"link": {
7+
"type": "doc",
8+
"id": "configuration"
9+
}
10+
}
Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
{
2+
"label": "Advanced View",
3+
"position": 20,
4+
"collapsed": true,
5+
"collapsible": true
6+
}
Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,10 @@
1+
{
2+
"label": "Client Module",
3+
"position": 20,
4+
"collapsed": true,
5+
"collapsible": true,
6+
"link": {
7+
"type": "doc",
8+
"id": "client_module"
9+
}
10+
}
Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,10 @@
1+
{
2+
"label": "Applications",
3+
"position": 80,
4+
"collapsed": true,
5+
"collapsible": true,
6+
"link": {
7+
"type": "doc",
8+
"id": "applications"
9+
}
10+
}
Lines changed: 110 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,110 @@
1+
---
2+
title: "Applications"
3+
description: "Applications"
4+
sidebar_position: 80
5+
---
6+
7+
# Applications
8+
9+
## What are applications?
10+
11+
Applications can be used to configure automated logins to various systems. Especially when combined
12+
with various protective mechanisms, the company benefits in terms of security because complex
13+
passwords are automated and entered in the login masks in concealed form. Various types are
14+
available, such as Remote Desktop (**RDP**), Secure Shell (**SSH**), general applications (**SSO**)
15+
and web applications. The Single Sign On Engine offers countless configuration options to enable
16+
automatic logon to almost any kind of software.
17+
18+
![applications module](/images/passwordsecure/9.2/configuration/advanced_view/clientmodule/applications/applications_1-en.webp)
19+
20+
- Automatic logins to websites are covered by the
21+
[Autofill Add-on](/docs/passwordsecure/9.3/configuration/autofilladdon/autofill_add-on.md).
22+
23+
## The four types of applications
24+
25+
Netwrix Password Secure varies between four different types of applications: RDP, SSH, SSO and web
26+
applications.
27+
28+
![new application](/images/passwordsecure/9.2/configuration/advanced_view/clientmodule/applications/applications_2-en.webp)
29+
30+
In terms of how they are handled, **RDP and SSH** applications can be covered together. Both types
31+
of application can be (optionally) "embedded" in Netwrix Password Secure. The relevant session then
32+
opens in its own tab in the [Reading pane](/docs/passwordsecure/9.3/configuration/advancedview/operationandsetup/reading_pane.md).
33+
All other forms of automatic logins are summarized in the **SSO applications** and **web
34+
applications** categories. How exactly these logins are created and used is covered in the next
35+
section and in the web applications chapter. They include all forms of Windows login masks and also
36+
applications for websites. In contrast to RDP and SSH applications, they cannot be started embedded
37+
in Netwrix Password Secure but are instead opened as usual in their own window. These SSO
38+
applications need to be defined in advance. In Netwrix Password Secure, this is also described as
39+
[Learning the applications](/docs/passwordsecure/9.3/configuration/advancedview/clientmodule/applications/learningtheapplications/learning_the_applications.md). In contrast,
40+
RDP and SSH can be both completely defined and also started within Netwrix Password Secure.
41+
42+
## RDP and SSH
43+
44+
A new RDP/SSH application can be created via the ribbon or also the context menu that is accessed
45+
using the right mouse button. A corresponding form opens in each case where the variables for a
46+
connection can be defined.
47+
48+
![new application](/images/passwordsecure/9.2/configuration/advanced_view/clientmodule/applications/applications_3-en.webp)
49+
50+
These variables also correspond precisely to those (using the example of RDP here) that can be
51+
configured when creating an RDP connection via “mstsc”. Whether the connections should be started in
52+
a tab, full screen mode or in a window can be defined in the field **"window mode"**.
53+
54+
## Working with RDP and SSH applications
55+
56+
If you have created e.g. an RDP connection, this can now also be directly started via the ribbon.
57+
The connection to the desired session can be established via the icon **Establish RDP connection**.
58+
59+
![estabish RDP](/images/passwordsecure/9.2/configuration/advanced_view/clientmodule/applications/applications_4-en.webp)
60+
61+
Netwrix Password Secure now attempts to log in to the target system with the information available.
62+
Data that are not saved in the form will be directly requested when opening the session. It is thus
63+
also possible to only enter the IP address and/or the password after starting the Netwrix Password
64+
Secure application. If all data has been retrieved, the RDP session will open in a tab – if so
65+
defined (Window mode field in the application):
66+
67+
![RDP session](/images/passwordsecure/9.2/configuration/advanced_view/clientmodule/applications/applications_5-en.webp)
68+
69+
## Logging in via SSH certificates
70+
71+
It is also possible to complete the authentication process using SSH certificates. For this purpose,
72+
the certificate is saved as a document in .ppk format. (It may be necessary to firstly approve this
73+
file ending in the settings). The document is then linked to the record via the footer. The record
74+
does not need to have a password. However, it is necessary for the record to be linked to a SSH
75+
application.
76+
77+
## Linking records and applications
78+
79+
The application defines the requirements for the desired connection and also optionally for the
80+
target system. By linking records with applications, the complete login process can be automated. If
81+
the record now also supplies the user name and password, all of the information required for the
82+
login is available. Applications and records are linked via the "Start" tab in the ribbon. If this
83+
link to a record is established, a 1-click login to the target system is possible.
84+
85+
![linking RDP](/images/passwordsecure/9.2/configuration/advanced_view/clientmodule/applications/applications_6-en.webp)
86+
87+
The following example illustrates this process using an RDP connection:
88+
89+
![RDP Connection](/images/passwordsecure/9.2/configuration/advanced_view/clientmodule/applications/applications_7-en.webp)
90+
91+
A record can also be linked to multiple target systems in this manner. The user name and record are
92+
supplied by the record, while all other information necessary for the login is supplied by the
93+
different applications. In the following example, a record (user name and password) is linked to
94+
multiple access points.
95+
96+
![multiple access points](/images/passwordsecure/9.2/configuration/advanced_view/clientmodule/applications/applications_8-en.webp)
97+
98+
This is generally a very common scenario. Nevertheless, it should be noted that accessing multiple
99+
servers with one single password is questionable from a security standpoint. It is generally
100+
recommended that a unique password is issued for every server/access point.
101+
102+
NOTE: It is possible to leave the **IP address** field empty in the application. If an **IP
103+
address** field exists in the linked record then this address will be used. If there is also no IP
104+
address in the record, a popup window will appear in which the desired IP address can be entered
105+
manually.
106+
107+
Alternatively, it is possible to connect several records with one RDP connection. In this way, you
108+
can combine different users with an RDP connection and register them straightforward.
109+
110+
![connect RDP sessions](/images/passwordsecure/9.2/configuration/advanced_view/clientmodule/applications/applications_9-en.webp)
Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,10 @@
1+
{
2+
"label": "Example Applications",
3+
"position": 40,
4+
"collapsed": true,
5+
"collapsible": true,
6+
"link": {
7+
"type": "doc",
8+
"id": "example_applications"
9+
}
10+
}
Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,11 @@
1+
---
2+
title: "Example Applications"
3+
description: "Example Applications"
4+
sidebar_position: 40
5+
---
6+
7+
# Example Applications
8+
9+
In this section you'll find examples for applications.
10+
11+
- [SAP GUI logon - SSO Application](/docs/passwordsecure/9.3/configuration/advancedview/clientmodule/applications/exampleapplications/sap_gui_logon_-_sso_application.md)
Lines changed: 42 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,42 @@
1+
---
2+
title: "SAP GUI logon - SSO Application"
3+
description: "SAP GUI logon - SSO Application"
4+
sidebar_position: 10
5+
---
6+
7+
# SAP GUI logon - SSO Application
8+
9+
## Fundamental information
10+
11+
Logging into SAP can be achieved via the usage of
12+
[Start Parameter](/docs/passwordsecure/9.3/configuration/advancedview/clientmodule/applications/learningtheapplications/start_parameter.md). The
13+
prerequisite here is for the login process to be carried out via the "SAPshortcut". All available
14+
parameters are listed in the [SAP-Wiki](https://wiki.scn.sap.com/wiki/display/NWTech/SAPshortcut).
15+
16+
Form Firstly, a [Forms](/docs/passwordsecure/9.3/configuration/advancedview/clientmodule/forms/forms.md) should be created with the required fields. This
17+
could look like this:
18+
19+
![SAP form](/images/passwordsecure/9.2/configuration/advanced_view/clientmodule/applications/examples/sap/sap_gui_logon_1-en.webp)
20+
21+
## Record
22+
23+
A corresponding record is then created via the form:
24+
25+
![SAP record](/images/passwordsecure/9.2/configuration/advanced_view/clientmodule/applications/examples/sap/sap_gui_logon_2-en.webp)
26+
27+
## Application
28+
29+
A corresponding SSO application now needs to be created.
30+
31+
![SAP Application](/images/passwordsecure/9.2/configuration/advanced_view/clientmodule/applications/examples/sap/sap_gui_logon_3-en.webp)
32+
33+
## Link
34+
35+
The record now needs to be linked with the application. To do this, open the context menu by right
36+
clicking on the record. The previously created application can then be selected here via
37+
**Applications** and **Connect application**.
38+
39+
![link record/application](/images/passwordsecure/9.2/configuration/advanced_view/clientmodule/applications/examples/sap/sap_gui_logon_4-en.webp)
40+
41+
The link is then displayed in the ribbon. Clicking on the link will now open SAP, whereby the
42+
parameters for logging in to the application are directly transferred.
Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,10 @@
1+
{
2+
"label": "Learning the applications",
3+
"position": 10,
4+
"collapsed": true,
5+
"collapsible": true,
6+
"link": {
7+
"type": "doc",
8+
"id": "learning_the_applications"
9+
}
10+
}
Lines changed: 89 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,89 @@
1+
---
2+
title: "Learning the applications"
3+
description: "Learning the applications"
4+
sidebar_position: 10
5+
---
6+
7+
# Learning the applications
8+
9+
## Which applications need to be learned?
10+
11+
As already indicated in the previous section, RDP and SSH applications are completely embedded in
12+
Netwrix Password Secure. These applications thus do not need to be specially learned. All other
13+
applications in Windows need to be learned once.
14+
15+
## What does learning mean?
16+
17+
The record contains the user name and password. Learning involves defining the steps required. The
18+
result is equivalent to a script that defines where precisely the login data should be entered. In
19+
Netwrix Password Secure, the completed instructions themselves are also known as an "application".
20+
21+
## Relevant rights
22+
23+
The following options are required.
24+
25+
### User right
26+
27+
- Can add new RDP applications
28+
- Can add new SSH applications
29+
- Can add new SSO applications
30+
- Can add new web applications
31+
32+
## Configuration
33+
34+
First, a new SSO application is created via the ribbon.
35+
36+
![new sso application](/images/passwordsecure/9.2/configuration/advanced_view/clientmodule/applications/learning_the_applications/learning_the_applications_1-en.webp)
37+
38+
Various properties for the application can now be defined in the tab that opens. The fields **Window
39+
title**, **Application** and **Application path** are not manually filled. This is done via the
40+
**Create application** button in the ribbon:
41+
42+
![new sso application](/images/passwordsecure/9.2/configuration/advanced_view/clientmodule/applications/learning_the_applications/learning_the_applications_2-en.webp)
43+
44+
A crosshair cursor now appears. It enables the actual "mapping" or assignment of the target fields.
45+
You can see the field assignment for the user name below using a login to an SQL server as an
46+
example. All of the other fields that should be automatically entered are assigned in the same way.
47+
The process is always the same. You select the field that needs to be automatically filled and then
48+
decide which information should be used to fill it.
49+
50+
![mapping fields](/images/passwordsecure/9.2/configuration/advanced_view/clientmodule/applications/learning_the_applications/learning_the_applications_3-en.webp)
51+
52+
In parallel to the previous step, all of the already assigned fields will be displayed on the right
53+
edge of the screen. In this example, the VMware vSphere Client has a total of 4 assigned fields: IP,
54+
user name, password and clicking the button to subsequently confirm the login.
55+
56+
![connected fields](/images/passwordsecure/9.2/configuration/advanced_view/clientmodule/applications/learning_the_applications/learning_the_applications_4-en.webp)
57+
58+
NOTE: "Graphical recognition:" The graphical recognition function provides additional protection. It
59+
can be used to define other factors for the SSO. An area is defined that then serves as the output
60+
for the comparison (e.g. for login masks with an image). In order to activate the graphical
61+
recognition function, click on the eye at the top right after assigning the fields! The area that
62+
will serve as the output point is then marked.
63+
64+
Once you have assigned all of the fields, you can exit the application process using the enter
65+
button. The fields "Window title", "Application" and "Application path" mentioned at the beginning
66+
are now automatically filled.
67+
68+
![filled fields](/images/passwordsecure/9.2/configuration/advanced_view/clientmodule/applications/learning_the_applications/learning_the_applications_5-en.webp)
69+
70+
As you can see, the .exe file is directly referenced. If the application is saved to the same
71+
storage location for all users, it can then also be accessed by all other users.
72+
73+
## Linking records with applications
74+
75+
In the [Passwords](/docs/passwordsecure/9.3/configuration/advancedview/clientmodule/passwords/passwords.md), the newly created application can now be directly
76+
linked. To do this, mark the record to be linked and open the "Connect application" menu in the
77+
"Start" tab via the ribbon. This will open a list of all the available applications. It is now
78+
possible here to link to the previously created application "VMware".
79+
80+
![connect application with record](/images/passwordsecure/9.2/configuration/advanced_view/clientmodule/applications/learning_the_applications/learning_the_applications_6-en.webp)
81+
82+
When the link has been established, this application can then be directly started via the ribbon in
83+
future. Pressing the button directly opens the linked application.
84+
85+
![start application](/images/passwordsecure/9.2/configuration/advanced_view/clientmodule/applications/learning_the_applications/learning_the_applications_7-en.webp)
86+
87+
**CAUTION:** With respect to permissions, applications are subject to the same rules as for
88+
passwords, roles or documents. It is possible to separately define which group of users is permitted
89+
to use each application.

0 commit comments

Comments
 (0)