Managing the credential vault
Credentials are not shared between vaults. That is:
- A discovery scan from an appliance can only use credentials from its own vault.
- A discovery scan from a BMC Discovery Outpost can only use credentials from its own vault.
The credential vault can be open or closed. If no passphrase is set or the passphrase is saved, the vault is opened automatically when BMC Discovery starts. If a passphrase has been set and not saved, you will be prompted to enter it before Discovery can begin. While the vault is open, BMC Discovery can use the credentials stored in it to access devices.
When BMC Discovery is stopped, the vault is automatically closed if a passphrase is set and has not been saved. You can close the vault while the discovery process is in progress. This will prevent access to further devices during the current discovery runs.
Whenever a credential is added, removed, or changed, the vault is backed up. No more than two copies of the vault are held as back ups. When the vault passphrase is added, changed, or removed, all backups are deleted, ensuring that no backups of potentially less secure vaults are retained on the system.
To manage the credential vault
- From the main menu, click the Administration icon.
The Administration page is displayed. - From the Discovery section, click Vault Management.
The Vault management page is displayed.
From the Vault management page you can open or close the credential vault and specify a passphrase to secure it. You can also change the passphrase or remove it.
Setting a passphrase
To set a passphrase:
- Enter the new passphrase in the New Passphrase field.
- Repeat it in the verify New Passphrase field.
- You can also choose to save the passphrase so that it is not required whenever scanning is enabled. You must still enter a passphrase to open a closed credential vault. To do so, select Save Passphrase.
- Click Set Passphrase.
The passphrase is now set.
Changing a passphrase
To change a passphrase:
- Enter the new passphrase in the New Passphrase field.
- Repeat it in the Verify New Passphrase field.
- Click Change Passphrase.
The passphrase is now changed.
Clearing a passphrase
To clear a passphrase:
- Enter the current passphrase in the Current Passphrase field.
- Click Clear Passphrase.
The passphrase is now cleared.
Opening the credential vault
To open a closed credential vault:
- Enter the passphrase and click Open the Vault.
You are requested to confirm the operation.
You can also open the credential vault from the Discovery Home page. When BMC Discovery is not running and the vault is closed, a Passphrase entry box is displayed above START LOCAL SCANS.
Closing the credential vault
To close the vault, it must be open and have the passphrase set:
- Click Close the Vault.
You are requested to confirm the operation.
You can also close the vault from the Discovery Home page. When BMC Discovery is running and a passphrase is set, stopping BMC Discovery also closes the vault.
See the following video (07:33), which explains how you can add, edit, test, and manage credentials. You can also explore the functioning of credential vaults and learn how to close, open, export, and import the vault.