Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
aliben
New Contributor II

Hiding sensitive credentials for Standard users on FortiPAM

  Hello FortiPAM admins, I'm looking for a way to hide secrets sensitive credentials ( Username and Password ) from users with View or Edit roles  

1 Solution
ozkanaltas
Valued Contributor III

Hello @aliben ,

 

If your user has edit permission you can't hide the password from them. But if your user just has view permission, FortiPAM doesn't show the password to them.

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW

View solution in original post

If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
4 REPLIES 4
ozkanaltas
Valued Contributor III

Hello @aliben ,

 

If your user has edit permission you can't hide the password from them. But if your user just has view permission, FortiPAM doesn't show the password to them.

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
Bjay_Prakash_Ghising
Contributor

Hi @ozkanaltas 

 

Can you confirm it once again. If view permission allow you to hide password of the secrets. 

 

Edit:

Users with the following permission can view secret passwords on the GUI:

  • Owner

  • Edit

  • View (Only for users with roles where View Encrypted Information is enabled)

 

So, role with "View Encrypted Information " disabled can't see the password of the secret.

Ghising
Ghising
ozkanaltas

Hi @Bjay_Prakash_Ghising ,

 

Yes,sure. 

 

For example, this user has just "view" permission for this secret. User can't edit or view passwords.

 

image.png

 

But if I give edit permission to this user. Users can view and edit passwords. 

 

image.png

 

There is one important point. Your user role should be Standart User should not Power User or Administrator. 

 

 

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
Bjay_Prakash_Ghising

Understood. Thanks @ozkanaltas for sharing. 

Ghising
Ghising
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors