Skip to main content

Adding target systems

The following procedure demonstrates the minimum requirements for manually adding a target system that will be a source of profiles in Bravura Security Fabric :

  1. Click Manage the System > Resources > Target systems > Manually defined.

    For target systems on which you can manage inventory items, you can also click Manage the system > Inventory > Target systems.

  2. Click Add new…

  3. Define the target system ID, type and description; for example:

    ID

    CODIR

    Type

    Active Directory DN

    Description

    Organization Directory

  4. Click Change to the right of the Address field and enter the required information; for example, for Active Directory DN if this is the domain or domain controller.

    Click Continue to return to the Target system information page.

    Ensure that you do not double target .

  5. Modify general options as needed.

    To create Bravura Security Fabric profiles from accounts on this system, select Source of profile IDs.

    Note that List accounts , List attributes, and List groups are selected by default.

  6. Click Add.

    Bravura Security Fabric displays the Administrator credentials page.

  7. Enter credentials for a designated account to perform Bravura Security Fabric operations on the target system; for example on Active Directory DN this would be member of the Domain Admins group with read and write permissions for passwords and accounts.

    Click Update.

  8. To add user and other information to the Bravura Security Fabric database, click the General tab, then click Run discovery at the bottom of the form.

  9. Click the Authorization tab to select one or more users who can authorize access change requests on this target system.

See also

Example: Adding an Active Directory target system as a source of profiles

Click below to view a demonstration of defining an Active Directory target system as the source of profiles (users) for Bravura Security Fabric including the following steps:

  • Creating a list file with the OUs to list users from

  • Specifying the target system as a source of profiles

  • Adding target system administrator credentials

  • Testing the connectionRunning auto discovery

This section shows you the typical procedure for adding an Active Directory target. For this demonstration, this target will be set up so that it becomes the source of Bravura Security Fabric profiles. This means that users with accounts in Active Directory will have profiles, including full user name, created for them in Bravura Security Fabric .

  1. Click Manage the System > Resources > Target systems > Manually defined.

  2. Click Add new... to add a new target system.

  3. Enter a unique identifier for the new target system. The target ID can contain only letters (A-Za-z), digits (0-9), and underscores (_).

  4. Select the target system’s Type; for example, Active Directory DN.

  5. Type a Description for the target system.

  6. Click Change next to the Address field to enter values for the target system address. For Active Directory, there are three primary methods for specifying the Active Directory target address:

    • globaldomain.example.com

    • \\mydomaincontroller.example.com

    • \\mydomaincontroller

    You can restrict user listing by container or group membership.

  7. Enable Automatically create a Bravura Privilege managed system if you want to manage privileged access to this system.

  8. Select the Source of profile IDs checkbox.

  9. If you want Bravura Security Fabric to generate a list of attributes for each account during auto discovery, select List attributes. You must select this checkbox if you want Bravura Security Fabric to import OrgChart data from the target system.

  10. Select the Allowed in the certification process checkbox.

  11. For this demonstration installation, leave other parameters with default values.

  12. Click Add.

    The Administrator credentials page displays so you can add a target system administrator for the target.

  13. Type the target system administrator’s login ID in the Administrator ID field.

  14. Type the account password in the Password and Confirm password fields.

    For this demonstration, the Workstation ID and Account ID do not apply.

  15. Click Update.

Test the connection

To test that your target system is configured correctly:

Run auto discovery

Once a target system has been added and is flagged as a source of profile IDs, you need to run psupdate to list accounts and create user profiles:

Example: Adding a Linux target system

This section shows you the typical procedure for adding a Linux target system, using the Linux SSH connector to list accounts and synchronize passwords. This example assumes that you have added another target as source of profiles, as in the Active Directory example.

To add the Linux target system:

  1. Log in to the Bravura Security Fabric Front-end (PSF) as superuser.

  2. Click Manage the system > Resources > Target systems > Manually defined.

  3. Click Add new…

  4. Enter the following information:

    • ID LINUX

    • Type Generic Linux Server (SSH)

    • Description Linux Lab Server

  5. Click Change to the right of the Address field.

  6. Enter your Linux server IP address in the Server field.

    lab-targeting-linux-address

    Leave other fields set to their default.

  7. Click Continue to return to the Target system information page.

    Note

    Do not select the Source of profile IDs option for this target.

  8. Scroll to the bottom of the page and click Add.

    The Administrator credentials page will be displayed.

    lab-targeting-linux-added
  9. Enter and confirm the Administrator ID and Password.

    Deselect Updated by Bravura Privilege?

  10. Click OK to confirm the action.

  11. Click Update.

    lab-targeting-linux-creds-added
  12. Click the Test connection tab.

  13. Click Test credentials and test that the credentials work.

    The Results column should show "Success".

  14. Click Test list, click Refresh then click Show users to see the list of users.

  15. Run auto-discovery for the LINUX target, similar to Targeting Active Directory, to load accounts and information.

  16. Verify auto-discovery of accounts by running a user accounts report for the LINUX target.

    Tip

    When you run the accounts report, set the Target system ID to LINUX in Search criteria before clicking Run.

    In this case, because you did not select Source of Profile IDs on the Target system information page, the accounts have been loaded, but only accounts with short IDs that match existing Profile IDs show up as "Auto-associated". The rest of the Account status' appear "Unclaimed" because they do not match any existing Bravura Security Fabric user profiles.

    lab-targeting-linux-report-user-accounts