- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hide passwords in FortiPAM
Hello FortiPAM admins
Is there a way to hide passwords of users' secrets from being seen by the admin?
- Labels:
-
FortiPAM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @AEK
Users with the following permission can view secret passwords on the GUI:
- Owner
- Edit
- View (Only for users with roles where View Encrypted Information is enabled)
https://docs.fortinet.com/document/fortipam/1.3.0/administration-guide/488581/secrets
Admin cannot view the secrets (password) of the target with user permission:
- List
- None
But you can't launch the secret list with that permission.
Currently, FortiPAM don't offer to hide password for secret list with view permission.
Hope that helps,
Kind Regards,
Bijay Prakash Ghising
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Ghising
Thanks for your response and reference.
I think it would be much more secure to permanently hide the back-end server's passwords from any admin or user with any role/permissions.
I still don't understand why FortiPAM doesn't hide it. Maybe there is something conceptual that I don't understand yet about PAM.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @AEK
If you have role disabled for "View Encrypted Information " and "view" user permission then it won't display the password.
Just verified in this Q/A
https://docs.fortinet.com/document/fortipam/1.3.0/administration-guide/117972/role
https://docs.fortinet.com/document/fortipam/1.3.0/administration-guide/488581/secrets
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks Ghising
But the question still here: how can I convince my sysadmin to enter his password in my FortiPAM if he knows that I (as FortiPAM administrator) can see his password if I want?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello
I also searching for the same question, there is missing concept here, admin or SuperAdmin should not be able to see the password in secrete, it's supposed just in one case Glass breaking mode.
I did not find any related article talks about this issue
