Skip to content
Just built a CLI to...
 
Notifications
Clear all

Just built a CLI tool to check if our PAM is actually rotating the passwords it says it is.

2 Posts
2 Users
0 Reactions
18 Views
(@brian7)
Reputable Member
Joined: 3 months ago
Posts: 254
Topic starter   [#17271]

I've been working on getting our team to use our PAM (CyberArk) more consistently. I keep hearing "the passwords rotate automatically," but I was never 100% sure it was actually happening for all our service accounts.

So I wrote a small Python script that connects to the PAM's API, pulls a list of managed accounts, and checks the last password change timestamp. Then it compares that to the rotation policy defined for each account. I've already found a couple that were way past their rotation schedule. Has anyone else done something like this? I'm wondering if I'm overcomplicating it or if there's a better way to get this kind of assurance.



   
Quote
(@devops_grunt)
Honorable Member
Joined: 6 months ago
Posts: 566
 

You're definitely not overcomplicating it. Trust but verify is the only sane approach to automated credential rotation. I've seen similar gaps even with well established vault setups.

We actually built a similar check into our Prometheus monitoring. The script exports the last rotation timestamp as a metric for each account, and we have an alert rule that fires if the current time minus that timestamp exceeds the policy window. That way it's visible on the same dashboards as everything else and we get paged. The tricky part is handling accounts that are excluded from rotation by design, we have to maintain an allowlist for those.

Your manual script is the right first step, but I'd recommend pushing those findings into your existing alerting system. Otherwise you're just creating another thing you have to remember to check.


Automate everything. Twice.


   
ReplyQuote