Generally yes, the password does get sent to the application, so it's going to be best to try and rotate these credentials for custom launchers after each use. The alternate way to handle this would be to leverage "Session Connector" to do terminal based launchers. These generate a one time use password to connect to an RDS server hosting a terminal application.
------------------------------
Andrew Crandall
------------------------------
Original Message:
Sent: Mon September 18, 2023 12:44 PM
From: Martin Hansgut
Subject: PAM launcher and encrypted password parameter
I would like to add that this is a question from a customer and I could not find the required information anywhere.
Alternatively, is there any possibility for the application to ask for the password via the API to the secret in PAM?
------------------------------
Martin Hansgut
Original Message:
Sent: Mon July 24, 2023 08:57 AM
From: Martin Hansgut
Subject: PAM launcher and encrypted password parameter
If I sell the password from the secret to the launcher as a parameter, is this password somehow secured?
------------------------------
Martin Hansgut
------------------------------