Efficient centralized credential storage for remotely managed networks
Abstract
An example embodiment may involve receiving, by a server device that stores a plurality of access credentials for computing devices that are disposed within a managed network, a request containing a label and an indication of an application service. The server device may be disposed within a remote network management platform that remotely manages the managed network. The example embodiment may further involve mapping, by the server device, the label and the application service to an endpoint identifier of a target computing device that is disposed within the managed network. The endpoint identifier may be associated with particular access credentials that are usable to access the application service executing on the target computing device. The example embodiment may further involve transmitting, by the server device, the endpoint identifier and the particular access credentials.
Claims
exact text as granted — not AI-modified1 - 20 . (canceled)
21 . A system comprising:
a processor; a memory storing instructions that, when executed by the processor, cause the processor to perform operations comprising:
receiving, from a server, a request containing a label and an indication of an application service, wherein the label is a character string that identifies an association between the application service and an endpoint identifier, wherein the endpoint identifier identifies a computing device disposed within a managed network;
storing, in a configuration management database (CMDB), the association between the application service and the endpoint identifier;
determining that an access credential is required to access the application service executing on the computing device;
retrieving the access credential from the CMDB based on the endpoint identifier; and
transmitting the endpoint identifier and the access credential to the server, wherein the endpoint identifier is associated with the access credential used to access the application service executing on the computing device, and wherein reception of the endpoint identifier causes the server to remotely access the application service executing on the computing device.
22 . The system of claim 21 , wherein the endpoint identifier is an IP address or uniform resource locator.
23 . The system of claim 21 , wherein the CMDB is a single database table that stores the association between the endpoint identifier, the label, and the application service.
24 . The system of claim 23 , wherein the CMDB stores all access credentials that are managed by a remote network management platform on behalf of the managed network.
25 . The system of claim 21 , wherein the application service is a remote login service.
26 . The system of claim 21 , wherein the access credential is obtained via an orchestration script executed on a proxy server.
27 . The system of claim 26 , wherein the orchestration script is configured to automatically run on a predetermined time schedule.
28 . A method comprising:
receiving, via a processor, a request from a server containing a label and an indication of an application service, wherein the label is a character string that identifies an association between the application service and an endpoint identifier, wherein the endpoint identifier identifies a computing device disposed within a managed network; storing, via a processor, the association between the application service and the endpoint identifier in a configuration management database (CMDB); determining, via the processor, that an access credential is required to access the application service executing on the computing device; retrieving, via the processor, the access credential from the CMDB based on the endpoint identifier; and transmitting, via the processor, the endpoint identifier and the access credential to the server, wherein the endpoint identifier is associated with the access credential used to access the application service executing on the computing device, and wherein reception of the endpoint identifier causes the server to remotely access the application service executing on the computing device.
29 . The method of claim 28 , wherein the endpoint identifier is an IP address or uniform resource locator.
30 . The method of claim 28 , wherein the CMDB is a single database table that stores the association between the endpoint identifier, the label, and the application service.
31 . The method of claim 30 , wherein the CMDB stores all access credentials that are managed by a remote network management platform on behalf of the managed network.
32 . The method of claim 28 , wherein the application service is a remote login service.
33 . The method of claim 28 , wherein the access credential is obtained via an orchestration script executed on a proxy server.
34 . The method of claim 33 , orchestration script is configured to automatically run on a predetermined time schedule.
35 . A non-transitory computer-readable medium, having stored thereon program instructions that, upon execution by a server that is disposed within a remote network management platform that remotely manages a managed network, cause the server to perform operations comprising:
receiving, from the server, a request containing a label and an indication of an application service, wherein the label is a character string that identifies an association between the application service and an endpoint identifier, wherein the endpoint identifier identifies a computing device disposed within the managed network; storing, in a configuration management database (CMDB), the association between the application service and the endpoint identifier; determining that an access credential is required to access the application service executing on the computing device; retrieving the access credential from the CMDB based on the endpoint identifier; and transmitting the endpoint identifier and access credential to the server, wherein the endpoint identifier is associated with the access credential used to access the application service executing on the computing device, and wherein reception of the endpoint identifier causes the server to remotely access the application service executing on the computing device.
36 . The non-transitory computer-readable medium of claim 35 , wherein the endpoint identifier is an IP address or uniform resource locator.
37 . The non-transitory computer-readable medium of claim 35 , wherein the CMDB is a single database table that stores the association between the endpoint identifier, the label, and the application service.
38 . The non-transitory computer-readable medium of claim 37 , wherein the CMDB stores all access credentials that are managed by a remote network management platform on behalf of the managed network.
39 . The non-transitory computer-readable medium of claim 35 , wherein the application service is a remote login service.
30 . The non-transitory computer-readable medium of claim 35 , wherein the access credential is obtained via an orchestration script executed on a proxy server.Join the waitlist — get patent alerts
Track US2020259809A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.