Transparent Login with SQL Server

Document ID : KB000010874
Last Modified Date : 06/06/2018
Show Technical Document Details
Introduction:

This technical document explains how we can setup Transparent Login capabilities to a SQL Server database application that you have configured within your CA PAM instance.

 

This document explains how to Troubleshoot RDP Application with Transparent Login:

https://support.ca.com/us/knowledge-base-articles.TEC1357953.html

Instructions:

First, make sure you have created the device under Devices -> Manage Devices -> Create Device.

Next, create your RDP Application under Services -> RDP Applications.  Make sure the Launch Path string matches exactly what the destination is on the targeted SQL Server.  Check Enable and Transparent Login on the Administration flag.  The Window Title should be the window in which you are authenticating against.  When you go to authenticate against SQL Server, you will see the 'Connect to Server' dialogue box spawn.  You will want to Save this.

The Application Fingerprint and Transparent Login Configs can be figured out later:

 RDP Applications.PNG

Once you have assigned your new Service to the device via Managed Devices and saved your work, you will want to click the Access page.  Hover your mouse over the RDP hyperlink under Access Methods and you will see a dialogue box where we can select 'Learn mode' and click the Launch button:

 Learn Mode.png

You will see a Learn Tool on your Windows session now that looks like this:

 Learn Tool.PNG

We want to click 'Add new configuration' and give it a name you will use within the Transparent Login Configs menu for later.  Next, you will want to launch SQL Server.  Your configuration should look like this after you are done creating a new configuration:

 Example.PNG

Click 'Run Control Viewer' and use the magnifying glass to drag it over to the 'Server name' textbox (note: do not hover the Browse Tool over the down arrow on the dropdown box, only on the inside of the box).  Your Control Viewer box should look identical to mine if it is SQL Server 2012.

 

Next, click 'Text input' and pick Text Field for Element Type, fill in Element ID with the Instance data you have in your Control tab of your Control Viewer, and for Value put in your SQL Server name you are connecting to:

 Add Edit Tag.PNG

Your Transparent Login Configuration should look like this:

 First line.PNG

Now, we want to put in a macro keyboard click that after we submit the Value string, we would then press Enter to log us into the database.  Again, click 'Text input' and click Keystrokes for the Element type dropdown box.  Grab the same Instance as before and insert that into the Element ID, and for Value put in '{ENTER}':

 Transparent Login Config.PNG

Next, get the 'Application Fingerprint', specify the App Path and you will see the tool generate an Application Fingerprint.  That Application Fingerprint, as aforementioned, needs to be populated on the RDP Application side again.

 Application Fingerprint.PNG