Set up CyberArk
Prerequisites
CyberArk CCP infrastructure
You need:
- CyberArk CCP installed
- Network connectivity between Itential Platform and CyberArk CCP
- Firewall rules that allow HTTP API communication
When using CyberArk on Windows Server 2022 or newer, you cannot configure Client Credential Authentication (mutual TLS) and TLS 1.3 simultaneously. This is a known compatibility issue between CyberArk and IIS. See CyberArk Support.
CyberArk CCP configuration
Configure these items in CyberArk CCP:
- A Safe containing your secrets
- An Application ID (AppID) for Itential Platform authentication
- Permissions that allow Itential Platform to retrieve secrets
Itential Platform requirements
You need:
- Administrative access to Itential Platform
- Write access to the Itential Platform server for configuration
Initial setup
Step 1: Install and verify CyberArk CCP
Install CyberArk CCP
Install CyberArk CCP following the CyberArk CCP installation guide or verify its installation.
Step 2: Configure the Itential Platform connection
Configure Itential Platform to connect to CyberArk CCP using one of three methods: Properties File, Environment Variable, or Server Profile (properties.json).
All three configuration methods are available in Platform 6, but 2023.2 only supports the Server Profile (properties.json) method.
Configuration parameters
Configuration examples
Step 3: Verify the connection
View configuration
View the CyberArk CCP configuration in Admin Essentials (read-only):
- Platform 6: Navigate to Admin Essentials > Configuration
- 2023.2: Navigate to Admin Essentials > Profiles