Other: Service Account Authentication Enablement in HVR Required
Hi HVR team,
We have noticed that there are no service account authentication in HVR. We have tried service accounts for passwordless authentication between HVR and remote SFTP server. This got failed. The same case we have noticed for HVR metadata database authentication as well. It was not accepting the Service account user but was accepting only local user accounts.
According to TJX organization policies, service accounts authentication only will be approved but usage of local user account in application considered as a non-compliant item. Also user passwords should have an option of frequent rotation and will be stored in cyber arc. This feature also not available at present. This is another non-compliance item in TJX security policy perspective.
Hence request you to consider these feature enhancements in the product.
Thanks & Regards
Manoj K C
-
Hi Manoj,
I am surprised you would not be able to perform password-less authentication through sftp certificates. Did your team follow the steps in the documentation?
Regarding password rotation: HVR 6.1.5 supports external password stores. This feature will be GA with version 6.2, planned for late September. With this feature you store tokens in HVR as a reference to secrets you would otherwise use. One of the benefits with this approach is that you can aggressively rotate passwords without having to update HVR (and re-activate channels or recreate jobs).
Hope this helps.
Mark. -
Hi Mark,
Thanks for the update.
We were able to establish password less connection through SSH. Our ask is why service account is not allowed in HVR for authentication? At present local user account authentication is enabled in HVR.
Regarding password store mechanism, as per TJX policies it is stored in cyber arc and hence inline with password rotation it should be required to update manually in HVR application. This may cause chances like delay/missing to update the password and hence adverse impact on business continuity as well. However feels that new feature enablement on 6.2.x will address these short comings.
Thanks & Regards
Manoj K C
-
Hi Team,
The below mentioned are the requirements in brief from our side as Feature Enablement in Fivetran HVR.
- Service Account authentication should be enabled.
- Rotating Passwords feature should be available and should be stored in Keystore/Cert Store
- LDAP/AD group integration as part of User Authorization /Authentication mechanism
- Unable to see "Log Out" Or "Sign Out" option in HVR GUI.
Thanks & Regards
Manoj K C
Please sign in to leave a comment.
Comments
3 comments