Integrate with Thycotic Secret Server

FlexDeploy provides out of box integration with Thycotic Secret Server to retrieve secrets. 

Thycotic Secret Server Setup

  • Make sure Thycotic has web services enabled

FlexDeploy Setup

You must first create a Credential Store in FlexDeploy by clicking the + Create button on Configuration - Integration - Credential Store page. The credential store represents an instance of a specific type of credential store provider. If you have more than one Thycotic Secret Server, you will create an equal number of Credential Stores in FlexDeploy.

Here are the configurations necessary for this store.

Property Name

Notes

Example

Thycotic Server Hostname

Thycotic will be accessed using URL https://<Thycotic Server Hostname>/SecretServer

thycotic.mycompany.com

Thycotic Username

Username of the service account to access Thycotic Secret Server

as per your server configurations

Thycotic Password

Password of the service account to access Thycotic Secret Server

as per your server configurations

Thycotic Domain

Domain of the service account to access Thycotic Secret Server

as per your server configurations

Ignore SSL Errors

Use default SSL configuration and ignore any SSL errors

true or false. Defaults to true



You may have to add certificate to Java keystore, see Adding certificate to Java Keystore

Now you are ready to create an individual credential to be retrieved from the Secret Server

You can 1:create or 2:edit credentials from the Credentials page or from where the specific credential is used.

Thycotic Secret Server requires input as described below.

Input Name

Notes

Input Name

Notes

Secret ID

The ID of the secret.  On Thycotic Secret server, this is the unique value for a secret.

It is in the URL when you browse to that secret on the Thycotic web application

Here is what the create and edit credential popup looks like. Credential Scope cannot be changed after creation.

You can change credential inputs (Secret ID) at any point. FlexDeploy will use these inputs with credential store properties to retrieve individual credentials for use during Workflow Execution.



The following macros are not currently supported in the footer:
  • style