SIA
[0.3.32]
Security
- Secret-bearing request bodies (
New-SIAStrongAccount,Set-SIAStrongAccount,New-SIADatabaseStrongAccount,Set-SIADatabaseStrongAccount) are now sent toInvoke-IDRestMethodas UTF8 bytes instead of a JSON string, so the plaintext password / secret cannot be captured by Windows PowerShell ParameterBinding / Module Logging. Mirrors pspete/psPAS#602 / pspete/psPAS#627. A static regression guard test was added toIdentityCommand.SIA.Tests.ps1.
Added
Get-SIASSHHostKeyFingerprint,Add-SIASSHHostKeyFingerprint,Set-SIASSHHostKeyFingerprint,Remove-SIASSHHostKeyFingerprint- Manage SSH host key fingerprints for targets.
Invoke-SIASSHPublicKeyRotation- Generate a new SSH CA public key version, or deactivate / reactivate the previous version.
Get-SIAMFAKey- Retrieve the SIA MFA key (openssh or ppk format) used for SSH authentication, returned as text.
Remove-SIAConnector,Test-SIAConnector,Update-SIAConnector,Set-SIAConnectorMaintenanceMode,Add-SIAConnectorPoolMember,Invoke-SIAConnectorCertificateRotation- Delete, test reachability of, upgrade, set maintenance mode on, assign to pools, and rotate the certificate of connectors.
Get-SIAHttpsRelay,Remove-SIAHttpsRelay,Update-SIAHttpsRelay,Get-SIAHttpsRelaySetupScript,Invoke-SIAHttpsRelayCertificateRotation- Manage SIA HTTPS relays, generate relay installation scripts, and rotate relay certificates.
Set-SIAStrongAccount- Update an existing virtual machine strong account.
Get-SIADatabaseStrongAccount,New-SIADatabaseStrongAccount,Set-SIADatabaseStrongAccount,Remove-SIADatabaseStrongAccount- Manage database strong accounts via the
/api/database-strong-accountsAPI (store_type/account_properties/password_secret_objectbody), supporting PAM accounts and managed accounts for PostgreSQL, MySQL, MariaDB, MSSql, Oracle, MongoDB, DB2UnixSSH, WinDomain and AWSAccessKeys platforms.
- Manage database strong accounts via the
Get-SIADatabaseTarget- Lists the database targets configured in SIA (
GET /api/database-targets).
- Lists the database targets configured in SIA (
Changed
- Module renamed from
IdentityCommand.DPAtoIdentityCommand.SIA, reflecting the rebrand of CyberArk Dynamic Privileged Access to CyberArk Secure Infrastructure Access.- All commands renamed to use the
SIAnoun prefix in place ofDPA(e.g.Get-DPAPolicyis nowGet-SIAPolicy). - Repository, folder structure, and help content updated to match.
- All commands renamed to use the
Get-SIAStrongAccount,New-SIAStrongAccount,Remove-SIAStrongAccount(breaking)- The
-database/-databasesswitches have been removed - database strong accounts are now managed with the dedicated*-SIADatabaseStrongAccountcommands. These commands now only manage virtual machine strong accounts (/api/secrets). New-SIAStrongAccountparameter sets renamedStoredInDPA-VM->StoredInSIAandVaultedInPrivilegeCloud-VM->VaultedInPrivilegeCloud.New-SIAStrongAccount/Set-SIAStrongAccountgained optional-enable_bulk_elevationand-ephemeral_domain_user_dataparameters.Get-SIAStrongAccountgained-countand-offsetlist parameters.
- The
Add-SIATargetSet/Get-SIATargetSet/Remove-SIATargetSet- Target set endpoints moved from
/api/discovery/targetsetsto/api/targetsets.
- Target set endpoints moved from
Get-SIAConnectorSetupScript(breaking)- Removed the
-connector_typeparameter - it is not part of thePOST /api/connectors/setup-scriptrequest body. - Added optional
-expiration_minutes(15 - 240),-proxy_host,-proxy_portand-windows_installation_pathparameters.
- Removed the
Get-SIASetting/Set-SIASetting-FeatureName(Get) and the feature switches (Set) now cover all settings features exposed by SIA, includingrdpTokenMfaCaching,rdpTranscription,sshRecording,logonSequence,selfHostedPam,connectViaBrowser,rdpFileSigning,rdpKerberosAuthMode,rdpChannels,validateFingerprintForSshZeroStanding,httpsRelay,rdpFileParameters,granularEnabled,oracleOudandoracleConnectionProtocol.Set-SIASettingnow performs a true partial update - only the supplied sub-settings are sent (PATCH /api/settings/), instead of reading and re-sending the full configuration.Set-SIASettingvalidates-keyExpirationTimeSec(300 - 43200 seconds),-sessionMaxDuration(60 - 1440 minutes),-sessionIdleTime(1 - 120 minutes),-logonSequenceValue(up to 30000 characters) and-shellPromptForAudit(up to 1024 characters).
Fixed
Get-SIACertificate- Updated to return correct property of output value.
Get-SIAResource- Updated to return correct property of output value.