AutoSys Integration with CyberArk and Database Password Rotation Impact
search cancel

AutoSys Integration with CyberArk and Database Password Rotation Impact

book

Article ID: 443359

calendar_today

Updated On:

Products

Autosys Workload Automation

Issue/Introduction

This article provides guidance on integrating AutoSys with CyberArk for job owner credentials and explains the impact of rotating the AutoSys database password on the OS-level account.

  • Is there a direct integration available between AutoSys and CyberArk?
  • Does rotating the AutoSys database user password impact the OS-level 'autosys' account?

 

Environment

  • AutoSys Workload Automation 12.1 and higher
  • CyberArk Credential Provider (CP) or Central Credential Provider (CCP)
  • Linux/Unix or Windows operating systems

Resolution

CyberArk Integration AutoSys 12.1 and higher officially supports native integration with CyberArk for managing Job Owner credentials.

  • Credential Provider (CP): Installed directly on the AutoSys server for business-critical performance.
  • Central Credential Provider (CCP): Utilizes a REST API to fetch credentials without a local agent installation.
  • Note: The AutoSys database connection password itself is managed via the DBAccess parameter in the configuration file using AES encryption and is not natively rotated by CyberArk CPM without custom scripting.

Password Rotation Impact Rotating the AutoSys database user password has no impact on the AutoSys OS account.

  • OS Account: Used for software installation and process execution.
  • Database Account: Used strictly by the Scheduler and Application Server to access the event server (AEDB).

How to Update the AutoSys Database Password:

  1. Stop the AutoSys Scheduler and Application Server services.
  2. Run the autosys_secure utility as the AutoSys OS user.
  3. Select Option 3 (Change database password) to update it interactively, or Option 6 (Get encrypted password) to generate a new AES string.
  4. If generating a string, update the DBAccess parameter in the $AUTOUSER/config.$AUTOSERV file: DBAccess=autosys/####
  5. Restart the AutoSys services.

Additional Information

 For more details, see the AutoSys Documentation on System Level Security.

To speak with a customer representative or a Support Engineer, see Contact Support.

Scroll to the bottom of the page and click on your respective region.