Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
AEK
SuperUser
SuperUser

Hide passwords in FortiPAM

Hello FortiPAM admins

Is there a way to hide passwords of users' secrets from being seen by the admin?

AEK
AEK
4 REPLIES 4
Bjay_Prakash_Ghising
Contributor

Hi @AEK 

 

https://docs.fortinet.com/document/fortipam/1.3.0/administration-guide/203151/creating-a-folder#User...

 

Users with the following permission can view secret passwords on the GUI:

  • Owner
  • Edit
  • View (Only for users with roles where View Encrypted Information is enabled)

https://docs.fortinet.com/document/fortipam/1.3.0/administration-guide/488581/secrets

 

Admin cannot view the secrets (password) of the target with user permission:

  • List
  • None

But you can't launch the secret list with that permission.

1 (3).jpg

 2.jpg

 

Currently, FortiPAM don't offer to hide password for secret list with view permission.

 

Hope that helps, 

 

Kind Regards, 

Bijay Prakash Ghising

 

 

 

Ghising
Ghising
AEK

Hello Ghising

Thanks for your response and reference.

I think it would be much more secure to permanently hide the back-end server's passwords from any admin or user with any role/permissions.

I still don't understand why FortiPAM doesn't hide it. Maybe there is something conceptual that I don't understand yet about PAM.

AEK
AEK
Bjay_Prakash_Ghising

Ghising
AEK

Thanks Ghising

But the question still here: how can I convince my sysadmin to enter his password in my FortiPAM if he knows that I (as FortiPAM administrator) can see his password if I want?

AEK
AEK
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors