Use > Hardening > Data Flow Credentials Management > Data Flow Credentials Management Overview

Data Flow Credentials Management Overview

To perform discovery or run integration, you must set up the credentials to access the remote system. Credentials are configured in the Data Flow Probe Setup window and saved in the UCMDB Server. For details, see the section describing the Data Flow Probe setup in the Universal CMDB Data Flow Management Guide.

Credentials storage is managed by the Confidential Manager component. For details, see Confidential Manager.

The Data Flow Probe can access the credentials using the Confidential Manager client. The Confidential Manager client resides on the Data Flow Probe and communicates with the Confidential Manager server, which resides on the UCMDB Server. Communication between the Confidential Manager client and the Confidential Manager server is encrypted, and authentication is required by the Confidential Manager client when it connects to the Confidential Manager server.

The Confidential Manager client's authentication on the Confidential Manager server is based on a LW-SSO component. Before connecting to the Confidential Manager server, the Confidential Manager client first sends an LW-SSO cookie. The Confidential Manager server verifies the cookie and upon successful verification, communication with the Confidential Manager client begins. For details about LW-SSO, see Configure LW-SSO Settings.

The communication between the Confidential Manager client and the Confidential Manager server is encrypted. For details about updating the encryption configuration, see Configure Confidential Manager Communication Encryption .

Caution The Confidential Manager authentication uses the universal time defined on the computer (UTC). In order for the authentication to succeed, ensure that the universal time on the Data Flow probe and the UCMDB Server are the same. The server and probe may be located in different time zones, as UTC is independent of time zone or daylight savings time.

The Confidential Manager client maintains a local cache of the credentials. The Confidential Manager client is configured to download all credentials from the Confidential Manager server and store them in a cache. The credentials changes are automatically synchronized from Confidential Manager server on a continuous basis. The cache can be a file-system or in-memory cache, depending on the preconfigured settings. In addition, the cache is encrypted and cannot be accessed externally. For details about updating the cache settings, see Configure the Confidential Manager Client’s Cache Mode on the Probe. For details about updating the cache encryption, see Configure the Confidential Manager Client’s Cache Encryption Settings on the Probe.

For details on troubleshooting, see Change Confidential Manager Client Log File Message Level.

You can copy credentials information from one UCMDB server to another. For details, see Export and Import Credential and Range Information in Encrypted Format.

Note The DomainScopeDocument (DSD) that was used for credentials storage on the Probe (in UCMDB version 9.01 or earlier) no longer contains any credentials-sensitive information. The file now contains a list of Probes and network range information. It also contains a list of credential entries for each domain, where each entry includes the credential ID and a network range (defined for this credential entry) only.