FortiPAM
FortiPAM allows you to protect, isolate and secure privileged account credentials, manage and control privileged user access, and monitor and record privileged account activity.
rbraha
Staff
Staff
Article Id 371021
Description

 

This article describes how to perform basic troubleshooting of secret launching in FortiPAM.

 

Scope

 

FortiPAM, FortiSRA.

 

Solution

 

In FortiPAM a Secret contains all the parameters required to connect to a target system. Parameters such as the IP address, protocol used, credentials used to connect to the system, and other advanced PAM features/settings. Some of these settings are inherited from the folder via a Secret Policy but inheritance can be disabled to configure these directly on a Secret.

 

The following example shows how secrets can be launched to access FortiAuthenticator using a Web launcher or Web SSH.

 

  1. Creating Target.

 

Select Secrets -> Targets -> Create.

 

Figure 1. Creating a TargetFigure 1. Creating a Target

 

  1. Creating  Secret.

     

    Select Secrets -> Create, Select Public or Personal Folder -> Create.

     

    Figure 2. Creating SecretFigure 2. Creating Secret

     

  2. Troubleshooting.

     

    When launching a secret fails for some reason, to troubleshoot it run debug commands in FortiPAM CLI.

    Different categories can be selected, based on which service debug logs collected are needed.

     

    Figure 3. Debug commandsFigure 3. Debug commands

     

    There are different level traces by default info, error, and warn displayed but level verbose is hidden.

     

    diagnose wad debug enable category secret

    diagnose wad debug enable category http

    diagnose wad debug enable level verbose

    diagnose  debug enable

     Figure 4. Debug outputFigure 4. Debug output