Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
StefanSchmidt
Explorer
Jump to solution

Checkpoint Identity awareness: idc_servacc.db Meaning of "exceptions"

Hello,

I need to exclude certain service accounts from being monitored by CP Identity Awareness.

I have found an article  https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_IdentityAwareness_AdminGuide...

(and similar information in the CP Identity Awareness documentation) that there is a file 

$FWDIR/conf/idc_servacc.db

"Identity Awareness Gateway saves the session identifier and username c associated with an identified Service Account in the $FWDIR/conf/idc_servacc.db "

There are two sections in this file:

:serviceAccounts (
:exceptions (

Where should I insert the service accounts that I do not want be monitored? Under serviceAccounts or under exceptions?

Thank you

regards

Stefan

0 Kudos
1 Solution

Accepted Solutions
PhoneBoy
Admin
Admin

I assume this is what the command will do.
Rather than manipulate this file directly, you should use the relevant pdp idc service_accounts commands per the documentation.
That documentation suggests that "exceptions" in this case are to override the detection of service accounts for specific users (e.g. always enforce identity for these users).

View solution in original post

0 Kudos
4 Replies
PhoneBoy
Admin
Admin

Rather than modify that file directly, you should use pdp idc service_accounts mark username

0 Kudos
StefanSchmidt
Explorer

So the command  pdp idc service_accounts mark username will create an entry in the file $FWDIR/conf/idc_servacc.db ?

Or what does the command do?

What do the sections

:serviceAccounts (
:exceptions (

in the file $FWDIR/conf/idc_servacc.db mean?

Does the ":exceptions ( " line define which accounts should never be detected as service accounts or does it define that those accounts acutally ARE service accounts? If both is incorrect: what does the ":exceptions ( " line do for accounts that are dinfend under this line?

Thank you

regards

Stefan

0 Kudos
PhoneBoy
Admin
Admin

I assume this is what the command will do.
Rather than manipulate this file directly, you should use the relevant pdp idc service_accounts commands per the documentation.
That documentation suggests that "exceptions" in this case are to override the detection of service accounts for specific users (e.g. always enforce identity for these users).

0 Kudos
StefanSchmidt
Explorer

Thanks a lot for the clarification

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events