Symantec Privileged Access Management

  • 1.  CA PAM - Windows local account - Password roatation

    Posted Oct 05, 2016 01:56 PM

    Hello All,

     

    How windows password rotation works and ho to go about having password rotation achieve in that windows endpoint.

    What are the port requirement for this to work.

     

    Why we need an windows proxy for Windows endpoint only, whereas Linux password rotation works with out a need for proxy?

     

    Thanks



  • 2.  Re: CA PAM - Windows local account - Password roatation

    Broadcom Employee
    Posted Oct 05, 2016 06:39 PM

    Hello,

    The CA PAM appliance runs on a Linux OS. It has SSH, Telnet and some other clients to silently logon to a variety of target devices running corresponding servers, such as an SSH server. But for Windows there is no such client. So in order to manage local Windows accounts, we need a client/proxy service running on a Windows host. The appliance is able to connect to Active Directory, specifically a domain controller, to manage domain accounts. For these you can use the Windows Domain Services target application rather than a Windows Proxy.

    Port requirements for the Windows Proxy are:

    – PAM to Proxy – port 27077

    – Proxy to PAM – port 443

    – Proxy to end-point – port 445  (if the Proxy manages accounts on other Windows hosts than where the Proxy is installed)

     

    Regards,

    Ralf Prigl