Secrets¶
IMan stores the passwords, keys and tokens it needs to reach other systems. IMan 6.1 calls these secrets. It encrypts every one of them before it writes it to the database or to an integration file, and only an IMan server that holds the right key can read them.
This section covers how that protection works and how you look after it:
- Managing Secrets: the Secrets window in the Admin Console, the recovery code, and what Create and Update do for secrets.
- Moving & Recovering: moving IMan to another server, restoring a backup, and what to do when IMan is locked.
What IMan protects¶
In the database:
- System connector passwords, keys and tokens.
- Database connections, and the connection strings of database lookups.
- FTP servers, including SSH private keys.
- The mail servers IMan sends and receives email with.
- OAuth tokens and client secrets.
- Web service credentials: Basic Authentication, and the secret values in HTTP headers, Webservice Behaviour and Webservice Lookups.
- Cloud file system settings.
- WebAPI users' credentials.
- The Windows passwords that schedules and File Events run as.
- IMan's own internal keys and certificates.
In the integration files:
- The connection string of a Database reader or writer.
- The password of a Process task.
- The zip password of a File task.
How IMan protects them¶
Three layers protect each secret:
- Data keys. IMan encrypts each secret with AES-256 under a data key. Each kind of secret has its own data key: one for system connector passwords, another for FTP passwords, and so on. The encrypted value is also bound to its place. A value copied into another column, or into another integration, does not open.
- The key certificate. IMan stores the data keys in its database, and every data key is itself encrypted with a certificate on the IMan server. The certificate is called IMan KEK <database>, and it is in the server's Local Machine Personal store. Only LocalSystem, the Administrators group and the accounts the IMan services and the WebAPI application pool run as can use its private key.
- The recovery code. IMan also keeps a copy of the certificate's private key in its database, sealed with a recovery code. The Admin Console shows you the code once, when it creates it. The code rebuilds the certificate on another server, and nothing else can.
A copy of the database on its own does not reveal the secrets. Anyone reading it also needs the key certificate from the IMan server, or the recovery code.
Record the recovery code
Keep the recovery code somewhere safe, away from the IMan server. Without the certificate or the code, IMan cannot read its stored secrets, and you must enter every one of them again.
The database connection¶
IMan keeps its own connection to the database in Config\appconfig.xml under
the IMan folder. That connection string is encrypted for the server with
Windows' own data protection. Only that server can read it. When you move IMan
or restore it onto another server, you enter the database settings again in the
Admin Console.
Secrets in the browser¶
IMan never sends a stored secret to the browser unless you ask to see it. A
field that holds a secret shows ********. When the secret is at least eight
characters long, IMan adds its last three characters, for example
********x7Q, to help you tell values apart. A connection string shows in full
except for its password.
- To change a secret, select the field and type the new value. The field shows Type a new value, or leave empty to keep the stored one. If you leave it empty, IMan keeps the stored value.
- To see a stored secret, press the eye button, Show the stored value. Press it again, Hide, to mask it.
Seeing a stored secret needs the permission Can reveal a stored secret in full, in the Secrets group. The Admin role has it. Give it only to the people who need it. See User Setup. IMan records each reveal, with the user and the item, in the service log.
Scripts¶
The VBScript function EncryptString and the RealisableData.EncDencUtils
object use an older fixed key built into IMan. Both are deprecated. See
EncryptString.