<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: CyberArk Blue Prism Integration - Certificates in Digital Exchange</title>
    <link>https://community.blueprism.com/t5/Digital-Exchange/CyberArk-Blue-Prism-Integration-Certificates/m-p/58296#M1618</link>
    <description>Hi Jiri,&lt;BR /&gt;&lt;BR /&gt;In my experience with CyberArk, each Digital Worker would have its own unique client certificate (stored in the User Certificate store). In that way, it is clear to CyberArk which Digital Worker it is communicating with.&lt;BR /&gt;&lt;BR /&gt;------------------------------&lt;BR /&gt;Charles Kovacs&lt;BR /&gt;Developer Consultant&lt;BR /&gt;Blue Prism&lt;BR /&gt;America/Chicago&lt;BR /&gt;------------------------------&lt;BR /&gt;</description>
    <pubDate>Tue, 22 Jun 2021 15:37:00 GMT</pubDate>
    <dc:creator>charliekovacs</dc:creator>
    <dc:date>2021-06-22T15:37:00Z</dc:date>
    <item>
      <title>CyberArk Blue Prism Integration - Certificates</title>
      <link>https://community.blueprism.com/t5/Digital-Exchange/CyberArk-Blue-Prism-Integration-Certificates/m-p/58295#M1617</link>
      <description>Dear community,&lt;BR /&gt;&lt;BR /&gt;my query relates to the CyberArk Blue Prism Integration solution that is published on the BP Digital Exchange website:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://digitalexchange.blueprism.com/dx/entry/10326/solution/blue-prism-cyberark-integration" target="test_blank"&gt;https://digitalexchange.blueprism.com/dx/entry/10326/solution/blue-prism-cyberark-integration&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;The integration&amp;nbsp; is primarily designed to authenticate BP client using a client certificate. A Client Certificate will need to be distributed to each Blue Prism Runtime Resource machine.&lt;BR /&gt;&lt;BR /&gt;Is it to be a single certificate, a certificate with the same serial number, that will be distributed in this way? Is it better to store it in the current users' certificate store or the local machine certificate store?&lt;BR /&gt;&lt;BR /&gt;Does anyone have any practical experience with this?&lt;BR /&gt;Thank you&lt;BR /&gt;&lt;BR /&gt;Jiri&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;------------------------------&lt;BR /&gt;Jiri Hlucil&lt;BR /&gt;Blue Prism Developer&lt;BR /&gt;Sberbank CZ, a. s.&lt;BR /&gt;Europe/Prague&lt;BR /&gt;------------------------------&lt;BR /&gt;</description>
      <pubDate>Tue, 22 Jun 2021 05:16:00 GMT</pubDate>
      <guid>https://community.blueprism.com/t5/Digital-Exchange/CyberArk-Blue-Prism-Integration-Certificates/m-p/58295#M1617</guid>
      <dc:creator>hlucil.jiri</dc:creator>
      <dc:date>2021-06-22T05:16:00Z</dc:date>
    </item>
    <item>
      <title>RE: CyberArk Blue Prism Integration - Certificates</title>
      <link>https://community.blueprism.com/t5/Digital-Exchange/CyberArk-Blue-Prism-Integration-Certificates/m-p/58296#M1618</link>
      <description>Hi Jiri,&lt;BR /&gt;&lt;BR /&gt;In my experience with CyberArk, each Digital Worker would have its own unique client certificate (stored in the User Certificate store). In that way, it is clear to CyberArk which Digital Worker it is communicating with.&lt;BR /&gt;&lt;BR /&gt;------------------------------&lt;BR /&gt;Charles Kovacs&lt;BR /&gt;Developer Consultant&lt;BR /&gt;Blue Prism&lt;BR /&gt;America/Chicago&lt;BR /&gt;------------------------------&lt;BR /&gt;</description>
      <pubDate>Tue, 22 Jun 2021 15:37:00 GMT</pubDate>
      <guid>https://community.blueprism.com/t5/Digital-Exchange/CyberArk-Blue-Prism-Integration-Certificates/m-p/58296#M1618</guid>
      <dc:creator>charliekovacs</dc:creator>
      <dc:date>2021-06-22T15:37:00Z</dc:date>
    </item>
    <item>
      <title>RE: CyberArk Blue Prism Integration - Certificates</title>
      <link>https://community.blueprism.com/t5/Digital-Exchange/CyberArk-Blue-Prism-Integration-Certificates/m-p/58297#M1619</link>
      <description>Hi Charles,&lt;BR /&gt;&lt;BR /&gt;thank you for your reply.&lt;BR /&gt;What you write sounds logical. It will be a suitable solution for our environment where we have a Digital Worker fixed to each BP runtime resource.&lt;BR /&gt;&lt;BR /&gt;However, the CyberArk Blue Prism Integration solution that is published on the BP Digital Exchange website assumes a single certificate definition in the process layer based on the thumbprint. Can multiple personal certificates have the same thumbprint? I confess that I don't know much about digital certificates.&lt;BR /&gt;&lt;BR /&gt;Jiri &lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;JH&lt;BR /&gt;&lt;BR /&gt;------------------------------&lt;BR /&gt;Jiri Hlucil&lt;BR /&gt;Blue Prism Developer&lt;BR /&gt;Sberbank CZ, a. s.&lt;BR /&gt;Europe/Prague&lt;BR /&gt;------------------------------&lt;BR /&gt;</description>
      <pubDate>Wed, 23 Jun 2021 06:35:00 GMT</pubDate>
      <guid>https://community.blueprism.com/t5/Digital-Exchange/CyberArk-Blue-Prism-Integration-Certificates/m-p/58297#M1619</guid>
      <dc:creator>hlucil.jiri</dc:creator>
      <dc:date>2021-06-23T06:35:00Z</dc:date>
    </item>
    <item>
      <title>RE: CyberArk Blue Prism Integration - Certificates</title>
      <link>https://community.blueprism.com/t5/Digital-Exchange/CyberArk-Blue-Prism-Integration-Certificates/m-p/58298#M1620</link>
      <description>The thumbprint will be unique to each certificate, so no two certificates should have the same thumbprint.&lt;BR /&gt;&lt;BR /&gt;That process in the CyberArk integration is more of an example rather than a production-ready process. With multiple Digital Workers at play, each with their own unique certificate, you can use that example process as a springboard, but you will want to re-work it so that it can dynamically select the right thumbprint for the Digital Worker who runs the process. Off the top of my head, this might be some sort of lookup table that matches the Digital Worker's computer name to the right certificate thumbprint.&lt;BR /&gt;&lt;BR /&gt;Have you worked with the Login Agent before? I ask because the Login Agent VBO has a clever way of using BP's Credential manager and an environment variable to dynamically retrieve a password for a Digital Worker. You could apply this same logic to the CyberArk certificate thumbprint retrieval. Just food for thought, but this would be my approach for a CyberArk production environment.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://bpdocs.blueprism.com/bp-7-0/en-us/Guides/login-agent/advanced-installation-configuration.htm#Setting" target="test_blank"&gt;https://bpdocs.blueprism.com/bp-7-0/en-us/Guides/login-agent/advanced-installation-configuration.htm#Setting&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Cheers&lt;BR /&gt;&lt;BR /&gt;------------------------------&lt;BR /&gt;Charles Kovacs&lt;BR /&gt;Developer Consultant&lt;BR /&gt;Blue Prism&lt;BR /&gt;America/Chicago&lt;BR /&gt;------------------------------&lt;BR /&gt;</description>
      <pubDate>Wed, 23 Jun 2021 15:48:00 GMT</pubDate>
      <guid>https://community.blueprism.com/t5/Digital-Exchange/CyberArk-Blue-Prism-Integration-Certificates/m-p/58298#M1620</guid>
      <dc:creator>charliekovacs</dc:creator>
      <dc:date>2021-06-23T15:48:00Z</dc:date>
    </item>
  </channel>
</rss>

