UiPath Documentation
orchestrator
latest
false
Orchestrator ユーザー ガイド
重要 :
このコンテンツの一部は機械翻訳によって処理されており、完全な翻訳を保証するものではありません。 新しいコンテンツの翻訳は、およそ 1 ~ 2 週間で公開されます。

Orchestrator Credentials Proxy

Orchestrator Credentials Proxy を設定して、カスタムの資格情報ストア プラグインを Orchestrator に接続します。

Orchestrator に独自の資格情報ストアを追加することで、接続データのセキュリティを独自に制御できます。

そのためには、必要な資格情報ストア プラグインを .dll ファイルの形式で、Orchestrator の Credentials Proxy Web サービスに読み込みます。インストール キットには UiPath がサポートするすべてのプラグインが含まれていますが、独自のプラグイン .dll ファイルを開発して読み込むこともできます。

次に、このサービスによって、プロキシ経由でプラグインを利用できるようになります。 プロキシは、プロキシによって生成されたパブリック URL とシークレット キーに基づいて Orchestrator で作成されます。

既知の問題​

アップグレード後にカスタム ポートを 443 にリセット​

この問題は、Orchestrator Credentials Proxy が既定の 443 以外のポートを使用するよう設定されている場合にのみ適用されます。

1.0.0 から 2.0.1 までの任意のバージョンからアップグレードするときに、カスタム ポートを使用していても、受信規則 UiPathOrchestratorCredentialsProxy のローカル ポートが自動的に 443 (既定値) に変更されます。これにより、プロキシへの接続が確立されなくなります。

この問題を回避するには、アップグレード時に受信規則のローカル ポートを手動で変更する必要があります。

インストール​

Orchestrator Credentials Proxy は、UiPath が提供する .msi インストーラー、または Docker イメージを使用してインストールできます。

.msi インストーラーを使用する​

前提条件​

Orchestrator Credentials Proxy は IIS でホストされる ASP.NET Core Web アプリケーションであるため、IIS 8.0 以降をホストできる任意の Windows エディションにインストールできます。これには、Windows Server と Windows 10 および Windows 11 クライアントの両方が含まれます。Windows Server は必須ではありません。

ハードウェア要件​

IIS を搭載した Windows マシンでプロキシを実行するための最小要件は以下のとおりです。実際に必要なリソースは、個々の使用状況によって異なります。

CPU コアRAM
24 GB
ソフトウェア要件​

プロキシをホストするマシンは、次の要件を満たす必要があります。

  • オペレーティング システム - IIS 8.0 以降をサポートする任意の Windows エディション。Windows Server 2012 R2、2016、2019、2022、および 2025 はすべて、Windows 10 および Windows 11 と同様に、この要件を満たしています。
  • IIS - バージョン 8.0 以降
  • .NET ホスティング バンドル - バージョン 10.0 以降 (.NET 10 で動作する Orchestrator Credentials Proxy 2.2.2 以降の場合)。2.2.2 より前のバージョンのプロキシには、バージョン 3.1 以降が必要です。このバンドルでは、ASP.NET Core ランタイムと ASP.NET Core IIS モジュールの両方がインストールされます。これらはプロキシを IIS で実行するために必要なものです。
    重要:

    以前のバージョンから Orchestrator Credentials Proxy 2.2.2 以降にアップグレードする場合は、アップグレードしたプロキシを起動する前に、ホスト マシンに .NET 10 ホスティング バンドルをインストールし、IIS を再起動してください。タイムアウトが指定されていない場合、プロキシは IIS での起動に失敗します。

さらに、次の IIS 機能を有効化する必要があります。

  • IIS-DefaultDocument
  • IIS-HttpErrors
  • IIS-StaticContent
  • IIS-RequestFiltering
  • IIS-URLAuthorization
  • IIS-WindowsAuthentication
  • IIS-ASPNET45
  • IIS-ISAPIExtensions
  • IIS-ISAPIFilter
  • IIS-WebSockets
  • IIS-ApplicationInit
  • IIS-ManagementConsole

これらの機能を有効化する方法は、Windows のエディションによって異なります。

  • Windows Server - サーバー マネージャー を使用して> 役割や機能を追加します。
  • Windows 10 および Windows 11 - [コントロール パネル] > [プログラム] にある [Windows の機能の有効化または無効化] ユーティリティを使用します。
注:

インストーラーは、何かをインストールする前に、IIS バージョン、コア IIS モジュールの ASP.NET、および上記の IIS 機能を検証します。いずれかのフィールドが見つからない場合、インストールが停止し、追加する必要がある内容が報告されます。

インストールの手順​

インストールを実行するには、以下の手順に従います。

  1. Customer Portal から UiPath Orchestrator Credential Proxy インストーラーをダウンロードします。
  2. プロキシをインストールします。
接続状態のプロキシ​
  • パブリック URL - パブリックに公開されている Orchestrator Credentials Proxy の URL です。
  • SSL 証明書 - Orchestrator Credentials Proxy との接続をセキュリティで保護するために使用される SSL 証明書のサブジェクトまたは拇印です。これは、プロキシをホストするコンピューターまたは Web サーバーにインストールされた SSL 証明書です。 パブリックな証明書プロバイダーによって発行される必要があり、パブリック URL に対して有効である必要がありますのでご注意ください。
  • ポート - パブリック URL に対応するポートです。
  • シークレット キー - Orchestrator のインターフェイスでカスタム プロキシを構成するのに必要なキー (自動生成) です。後で使用できるよう、クリップボードにコピーしておいてください。

これは手動で変更できて、キー ローテーションにも適しています。

非接続のプロキシ​

この機能は、フレックス プライシング プランの Enterprise - Advanced ライセンス プラン、またはユニファイド プライシング プランの Enterprise または Application Test Enterprise の場合にのみ利用できます。

  • SSL 証明書 - Orchestrator Credentials Proxy との接続をセキュリティで保護するために使用される SSL 証明書のサブジェクトまたは拇印です。これは、プロキシをホストするコンピューターまたは Web サーバーにインストールされた SSL 証明書です。ロボットはユーザー自身のインフラストラクチャ内でプロキシに接続するため、ロボットを実行するマシンが信頼する限り、この証明書は自己署名または社内の証明機関によって発行できます。
  • ポート - URL に対応するポートです。
  • シークレット キー - Orchestrator のインターフェイスでカスタム プロキシを構成するのに必要なキー (自動生成) です。後で使用できるよう、クリップボードにコピーしておいてください。

これは手動で変更できて、キー ローテーションにも適しています。

注:

非接続のプロキシの場合、ロボットは Orchestrator を経由せずにプロキシに直接接続します。この接続は、プロキシの パブリック URL に設定されているポート (既定では 443) で HTTPS を使用します。接続状態のプロキシの種類と非接続のプロキシの種類について詳しくは、「 資格情報ストアのプロキシを管理する 」をご覧ください。

インストール時に、appsettings.Production.json ファイルの AppSettings.CredentialsProxyType パラメーターは Disconnected に設定されます。これによって、プロキシは起動時に接続/非接続を検出します。

注:

プロキシを動作させるには、IIS で [匿名認証 ] オプションを [有効 ] に設定する必要があります。

Jwt:Keysパラメーター​を暗号化する

さらにセキュリティのレイヤーを追加するには、appsettings.json ファイルの Jwt:Keys パラメーターと SecureStoreConfigurations:Context パラメーターを暗号化します。

注:

これには、UiPath.ConfigProtector.exe v1.0.9 以上が必要です。

Docker イメージを使用する​

予備情報​

Orchestrator Credentials Proxy の編集可能な設定はすべて、appsettings.json ファイルで利用できます。初期の設定では以下のパラメーターが重要です。

  • Jwt:Keys - (最初は空) プロキシの認証を設定するために、この文字列の配列が使用されます。プロキシの作成プロセスで使用するシークレット キーはこの配列で構成され、Orchestrator がプロキシからデータを正常に取得できるようになります。無効な値は無視されます。有効な値が見つからなかった場合、プロキシは起動しません。

シークレット キーは Base64 形式である必要があり、以下の PowerShell スクリプトのいずれかを使用して生成できます。

$bytes = [System.Security.Cryptography.RandomNumberGenerator]::GetBytes(64)
$jwtSigningKey = [Convert]::ToBase64String($bytes);
Write-Host $jwtSigningKey
$bytes = [System.Security.Cryptography.RandomNumberGenerator]::GetBytes(64)
$jwtSigningKey = [Convert]::ToBase64String($bytes);
Write-Host $jwtSigningKey

上記のスクリプトはランダムな 64 バイトを SeccureRandomを使用して生成し、Base64 文字列に変換します。

[Byte[]] $bytes = 1..64
$rng = New-Object System.Security.Cryptography.RNGCryptoServiceProvider
$rng.GetBytes($bytes)
$jwtSigningKey = [Convert]::ToBase64String($bytes);
Write-Host $jwtSigningKey
[Byte[]] $bytes = 1..64
$rng = New-Object System.Security.Cryptography.RNGCryptoServiceProvider
$rng.GetBytes($bytes)
$jwtSigningKey = [Convert]::ToBase64String($bytes);
Write-Host $jwtSigningKey
  • appSettings:Plugins.SecureStores - (最初は Orchestrator で利用可能な既定の資格情報ストアに設定) これは、プロキシによる Secure Store の使用を有効化するために、ディスク (path/plugins) から読み込むべき .dll アセンブリを指定する目的で使用される CSV 文字列です。無効なアセンブリをリストに追加してもスタートアップは破損しませんが、デプロイしようとするとログのエラーが発生します。
  • appSettings:SigningCredentialSettings:FileLocation:SigningCredential:FilePath、appSettings:SigningCredentialSettings:FileLocation:SigningCredential:Password - (最初は非表示) Jwt:Keys および SecureStoreConfigurations:Context パラメーターを暗号化するために使用されます。これは、署名証明書へのファイル パスを表します。
  • appSettings:SigningCredentialSettings:StoreLocation:Name、appSettings:SigningCredentialSettings:StoreLocation:Location、appSettings:SigningCredentialSettings:StoreLocation:NameType - (最初は非表示) Jwt:Keys および SecureStoreConfigurations:Context パラメーターを暗号化するために使用されます。
Docker イメージをセットアップして実行する​

Docker を使用して Orchestrator Credentials Proxy を実行するには、以下の手順に従います。

  1. Docker イメージをダウンロードする

イメージは http://registry.uipath.com/ からダウンロードできます。

注:

この URL に Orchestrator Credentials Proxy の必要なバージョンを含めます。 たとえば、バージョン 2.1.4 のイメージをダウンロードするには、次の URL を使用します。

http://registry.uipath.com/orchestrator-credentialsproxy:2.1.4
http://registry.uipath.com/orchestrator-credentialsproxy:2.1.4

この URL は Docker イメージを指しており、Web ブラウザーではなく Docker CLI を使用してアクセスする必要があります。

バージョン 1.0.0 では接続状態のプロキシのみがサポートされますが、バージョン 2.0.0 以降では非接続のプロキシもサポートされます。

イメージを取得するには、次のコマンドを使用します。

$bytes = [System.Security.Cryptography.RandomNumberGenerator]::GetBytes(64);
$jwtSigningKey = [Convert]::ToBase64String($bytes);
docker run -e LICENSE_AGREEMENT=accept -e Jwt__Keys__0=$jwtSigningKey -p 8000:8080 registry.uipath.com/orchestrator-credentialsproxy:1.0.0
$bytes = [System.Security.Cryptography.RandomNumberGenerator]::GetBytes(64);
$jwtSigningKey = [Convert]::ToBase64String($bytes);
docker run -e LICENSE_AGREEMENT=accept -e Jwt__Keys__0=$jwtSigningKey -p 8000:8080 registry.uipath.com/orchestrator-credentialsproxy:1.0.0

これは既定の UiPath イメージであり、お使いのクラウド アカウントで既に利用可能な資格情報ストアが含まれています。イメージは、選択したクラウド環境にデプロイできます。

上記のコマンドではシークレット キーも生成されます。

  1. 独自のカスタム Docker イメージを作成する

手順 1 でダウンロードした、UiPath が提供するイメージに基づいて、追加のアセンブリを含む独自の Docker イメージを作成できます。このためには、以下の手順に従います。

  1. Dockerfile を新たに作成し (分かりやすいようここでは CustomDockerfile という名前を付けます)、以下を追加します。
    FROM {docker-image-path}
    RUN rm -rf ./plugins 
    COPY --chown=1001:0 {path of your custom assemblies} ./plugins 
    ENTRYPOINT ["dotnet", "UiPath.OrchestratorCredentialsProxy.dll"]
    FROM {docker-image-path}
    RUN rm -rf ./plugins 
    COPY --chown=1001:0 {path of your custom assemblies} ./plugins 
    ENTRYPOINT ["dotnet", "UiPath.OrchestratorCredentialsProxy.dll"]
    
    • {docker-image-path} を、UiPath が提供する初期状態の Docker イメージのパスに置き換えます。
    • {path of your custom assemblies} を独自の資格情報ストアへのパスに置き換えます.dllファイル。Visual Studio でこの Dockerfile を使用し、イメージを構築してデバッグを高速化する方法について詳しくは、こちらをご覧ください 。
  2. 次のコマンドを使用して Docker イメージを生成します。これには、新しく作成された Dockerfile の名前が含まれます。
    docker build -f CustomDockerfile . -t customproxy
    docker build -f CustomDockerfile . -t customproxy
    
  3. Docker イメージを実行する
    docker run --publish 8000:8080 -e LICENSE_AGREEMENT="accept" -e Jwt__Keys__0=$jwtSigningKey -e appSettings__Plugins.SecureStores="{your-list-of-assemblies}" customproxy
    docker run --publish 8000:8080 -e LICENSE_AGREEMENT="accept" -e Jwt__Keys__0=$jwtSigningKey -e appSettings__Plugins.SecureStores="{your-list-of-assemblies}" customproxy
    
    • {your-list-of-assemblies} を、Orchestrator に追加するカスタム資格情報ストアの .dll ファイルに置き換えます。

1 つの Jwt:Keys パラメーターでイメージを実行する場合:

  ```
  docker run --publish 8000:8080 -e LICENSE_AGREEMENT="accept" -e Jwt__Keys__0=$jwtSigningKey {docker-image-name}
  ```
  ```
  docker run --publish 8000:8080 -e LICENSE_AGREEMENT="accept" -e Jwt__Keys__0=$jwtSigningKey {docker-image-name}
  ```

複数の Jwt:Keys パラメーターでイメージを実行する場合:

  ```
  docker run --publish 8000:8080 -e LICENSE_AGREEMENT="accept" -e Jwt__Keys__0==$jwtSigningKey" -e Jwt__Keys__1==$jwtSigningKey" -e Jwt__Keys__2==$jwtSigningKey ... {docker-image-name}
  ```
  * Replace `{docker-image-name}` with the name you set for your custom Docker image.
  ```
  docker run --publish 8000:8080 -e LICENSE_AGREEMENT="accept" -e Jwt__Keys__0==$jwtSigningKey" -e Jwt__Keys__1==$jwtSigningKey" -e Jwt__Keys__2==$jwtSigningKey ... {docker-image-name}
  ```
  * Replace `{docker-image-name}` with the name you set for your custom Docker image.

appSettings:Plugins.SecureStores パラメーターのカスタム値 (すなわち、目的の資格情報ストア) でイメージを実行するには、このパラメーターの内容を独自の資格情報ストアの .dll ファイルに置き換えます。次のようにします。

  ```
  docker run --publish 8000:8080 -e LICENSE_AGREEMENT="accept" -e Jwt__Keys__0=$jwtSigningKey -e appSettings__Plugins.SecureStores="UiPath.Orchestrator.CyberArk.dll;UiPath.Orchestrator.AzureKeyVault.SecureStore.dll" {docker-image-name}
  ```
  ```
  docker run --publish 8000:8080 -e LICENSE_AGREEMENT="accept" -e Jwt__Keys__0=$jwtSigningKey -e appSettings__Plugins.SecureStores="UiPath.Orchestrator.CyberArk.dll;UiPath.Orchestrator.AzureKeyVault.SecureStore.dll" {docker-image-name}
  ```

4. (任意) 新しい Docker イメージをテストする

イメージをテストするには、http://localhost:8000/swagger/index.html で Swagger インターフェイスにアクセスし、専用の非認証エンドポイント /Health が機能していることを確認します。リクエストが成功すると、HTTP ステータス コード 200 OK とともに空の応答が返されます。

構成​

接続状態のプロキシと非接続のプロキシ​

プロキシ設定の最初の手順は、使用するカスタム .dll プラグインを C:\Program Files\UiPath\CredentialsProxy\plugins フォルダーに追加することです。

一部の資格情報ストアでは、アプリケーション、ホスト、またはプロキシレベルで設定を構成する必要があります。これらの設定は、Orchestrator の対応する設定と同じです。これらの設定は、プロキシの appsettings.Production.json ファイルで指定する必要があります。

CyberArk​

appsettings.Production.json ファイルの Appsettings パラメーターの下に、CLIPasswordSDKExePath、UsePowerShellCLI、AdditionalAllowedCharacters などのホスト レベルの設定を追加する必要があります。

{
// ...
  "AppSettings": {
    "Plugins.SecureStores.CyberArk.CLIPasswordSDKExePath": "D:\\PathName\\CLIPasswordSDK.exe",
    // ...
  }
  // ...
}
{
// ...
  "AppSettings": {
    "Plugins.SecureStores.CyberArk.CLIPasswordSDKExePath": "D:\\PathName\\CLIPasswordSDK.exe",
    // ...
  }
  // ...
}

CyberArk CCP​

Credentials Proxy は、読み込まれたユーザー プロファイルを持たないサービス アカウントで実行されます。既定では、読み込まれたユーザー プロファイルを必要とするキー ストアを使用しますが、これはサービス アカウントでは使用できません。したがって、CyberArk CCP クライアント証明書の秘密キーの読み込みに失敗し、CyberArk CCP による資格情報の取得が失敗します。このコンテキストで証明書を正しく読み込むには、以下を追加する必要がありますappsettings.Production.json

{
// ...
  "AppSettings": {
    "Plugins.SecureStores.CyberArkCCP.KeyStorageFlags": "MachineKeySet",
    // ...
  }
  // ...
}
{
// ...
  "AppSettings": {
    "Plugins.SecureStores.CyberArkCCP.KeyStorageFlags": "MachineKeySet",
    // ...
  }
  // ...
}

HashiCorp Vault​

HashiCorp Vault と HashiCorp Vault (読み取り専用) の資格情報ストアは、次の 2 種類の設定で制御されます。

  • プロキシ全体のプラグインの動作は、ホスト レベルの設定によって制御されます。appsettings.Production.json ファイルの AppSettings で、プレフィックスとしてストア名を追加します。両方のプロキシの種類に適用されます。
  • コンテキスト パラメーターは、 1 つの Vault 接続を記述します。非接続のプロキシは、「設定のサンプル」セクションに示すように、同じファイルの [SecureStoreConfigurations] セクションからデータを読み取ります。接続状態のプロキシは、代わりに Orchestrator からそれらを受信します。

各コンテキスト パラメーターの意味、および と が個々のシークレットのパスに解決される方法については、「SecretsEngineMountPath DataPath資格情報ストアを管理する 」の「 HashiCorp Vault 」をご覧ください。各 JSON キーは、スペースなしの該当ページのフィールド ラベルです。ただし、 LdapUseDynamicCredentialsは (LDAP) 動的資格情報を使用) であり、 KerberosSPNは Kerberos の完全修飾 SPN です。

ホスト レベルの設定​

各ストアは独自のプレフィックス ( Plugins.SecureStores.HashiCorp Vault. または Plugins.SecureStores.HashiCorp Vault (read only). ) のみを読み取るため、両方のストアを構成するには、各設定を 2 回追加します。

設定既定 (Default)説明
KerberosEnabledfalseKerberosUserPassword認証の種類とKerberosDefaultCredentials認証の種類を利用できるようにします。プロキシを Docker イメージから実行する場合、この設定が何であれ、Kerberos は利用できません。
ForwardToActiveNodefalseX-Vault-Forward: active-node ヘッダーをすべての要求に追加し、パフォーマンス スタンバイ ノードがアクティブ ノードに転送するようにします。Vault Enterprise 専用です。
ClientCacheDurationSeconds600認証された Vault クライアントが操作間でキャッシュされたままになる時間。
MaxRetries5HTTP 403、412、429、500、または 503 を返す Vault 要求をプラグインがリトライする回数。
RetryDelayMilliseconds3000リトライ間の遅延。既定値では、権限エラーが表面化するまでに約 15 秒かかります。

Kerberos 認証プロトコルを有効化し、HashiCorp Vault のノード転送をアクティブ化するには、appsettings.Production.json ファイルに次のパラメーターを追加します。

{
// ...
  "AppSettings": {
    "Plugins.SecureStores.HashiCorp Vault.KerberosEnabled": "true", // Optional, for Kerberos enablement
    "Plugins.SecureStores.HashiCorp Vault.ForwardToActiveNode": "true", // Optional, for forwarding to active node
    // ...
  }
  // ...
}
{
// ...
  "AppSettings": {
    "Plugins.SecureStores.HashiCorp Vault.KerberosEnabled": "true", // Optional, for Kerberos enablement
    "Plugins.SecureStores.HashiCorp Vault.ForwardToActiveNode": "true", // Optional, for forwarding to active node
    // ...
  }
  // ...
}

プロキシがフォワード プロキシ経由で Vault に接続する場合は、次の設定で構成します。

  • HttpProxy.Outbound.Enabled
  • HttpProxy.Outbound.Address
  • HttpProxy.Outbound.Username
  • HttpProxy.Outbound.Password

これらにはストア名のプレフィックスが付いておらず、プロキシによって読み込まれるすべての資格情報ストア プラグインに適用されます。

HashiCorp Vault (読み取り専用)​

読み取り専用ストアは、読み取り/書き込みストアと同じコンテキスト パラメーターとホスト レベルの設定を使用しますが、次の 2 つの違いがあります。

Kerberos 認証プロトコルを有効化し、HashiCorp Vault (読み取り専用) のノード転送をアクティブ化するには、appsettings.Production.json ファイルに次のパラメーターを追加します。

{
// ...
  "AppSettings": {
    "Plugins.SecureStores.HashiCorp Vault (read only).KerberosEnabled": "true", // Optional, for Kerberos enablement
    "Plugins.SecureStores.HashiCorp Vault (read only).ForwardToActiveNode": "true", // Optional, for forwarding to active node
    // ...
  }
  // ...
}
{
// ...
  "AppSettings": {
    "Plugins.SecureStores.HashiCorp Vault (read only).KerberosEnabled": "true", // Optional, for Kerberos enablement
    "Plugins.SecureStores.HashiCorp Vault (read only).ForwardToActiveNode": "true", // Optional, for forwarding to active node
    // ...
  }
  // ...
}

非接続のプロキシのみ​

この種類のプロキシは Orchestrator から完全に分離されているため、資格情報コンテナーに関する情報をローカルの設定ファイル appsettings.Production.json で指定する必要があります。ファイルは、 C:\Program Files\UiPath\OrchestratorCredentialsProxy\appsettings.Production.jsonにあります。

上記のファイルの [AppSettings - SecureStoreConfigurations] セクションで、以下のフィールドを編集する必要があります。

  • Key - 設定の識別子キーです。
  • Type - appsettings.json で Plugins.SecureStores パラメーターを使用して設定された .dll ファイルで識別される資格情報コンテナーの種類です (以下のサンプルを参照)。
  • Context - Secure Store の実装に関連する接続情報です。
    重要:

    設定ファイルを編集したら、IIS からサービスを再起動する必要があります。

設定のサンプル​

非接続のプロキシを起動するには、以下のサンプルを appsettings.Production.json 設定ファイルに追加する必要があります。そうしないとサービスは起動されません。

資格情報ストアの種類に基づいて適切なサンプルを選択するか、このページの最後のサンプルを使用して複数の資格情報ストアを追加します。

上記のファイルの [AppSettings - SecureStoreConfigurations] セクションで、以下のフィールドを編集する必要があります。

  • Key - 設定の識別子キーです。
  • Type - appsettings.json で Plugins.SecureStores パラメーターを使用して設定された .dll ファイルで識別される資格情報コンテナーの種類です (以下のサンプルを参照)。
  • Context - Secure Store の実装に関連する接続情報です。
    重要:

    設定ファイルを編集したら、IIS からサービスを再起動する必要があります。

注:

appsettings.Production.json ファイルに変更を加える前に、必ず元のファイルのバックアップを作成してください。こうしておけば、設定中に問題が発生した場合に、簡単に初期設定を復元したり、変更箇所を比較したりできます。

AWS Secrets Manager/AWS Secrets Manager (読み取り専用)​
...
"SecureStoreConfigurations": [
      {
        "Key": "<MyAwsStore>",
        "Type": "AWS Secrets Manager" / "AWS Secrets Manager (read only)",
        "Context": {
          "UseDefaultCredentials": "true",
          "AccessKey": "<AccessKey>",
          "SecretKey": "<SecretKey>",
          "Region": "<SelectedRegion>"
        }
      },
    ]
...
...
"SecureStoreConfigurations": [
      {
        "Key": "<MyAwsStore>",
        "Type": "AWS Secrets Manager" / "AWS Secrets Manager (read only)",
        "Context": {
          "UseDefaultCredentials": "true",
          "AccessKey": "<AccessKey>",
          "SecretKey": "<SecretKey>",
          "Region": "<SelectedRegion>"
        }
      },
    ]
...
Azure Key Vault (読み取り専用)​
...
"SecureStoreConfigurations": [
      {
        "Key": "<MyAzureStore>",
        "Type": "AzureKeyVault (read only)",
        "Context": {
          "KeyVaultUri": "<KeyVaultUri>",
          "DirectoryId": "<DirectoryId>",
          "ClientId": "<ClientId>",
          "ClientSecret": "<ClientSecret>"
        }
      },
    ]
...
...
"SecureStoreConfigurations": [
      {
        "Key": "<MyAzureStore>",
        "Type": "AzureKeyVault (read only)",
        "Context": {
          "KeyVaultUri": "<KeyVaultUri>",
          "DirectoryId": "<DirectoryId>",
          "ClientId": "<ClientId>",
          "ClientSecret": "<ClientSecret>"
        }
      },
    ]
...
重要:

Azure Key Vault (読み取り/書き込み) はサポートされていません。

BeyondTrust Password Safe - Managed Accounts​
...
"SecureStoreConfigurations": [
      {
        "Key": "<MyBeyondTrustManagedAccountsSafe>",
        "Type": "BeyondTrust Password Safe - Managed Accounts",
        "Context": {
          "Hostname": "<HostName>",
          "APIRegistrationKey": "<ApiRegistrationKey>",
          "APIRunAsUsername": "<Username>",
          "DefaultManagedSystemName": "", // can be empty or a string
          "SystemAccountDelimiter": "/", // default account delimiter is "/", but it can be changed
          "ManagedAccountType": "<ManagedAccountType>" // expected value is one of "system", "domainlinked", "database", "cloud", "application"
        }
      },
    ]
...
...
"SecureStoreConfigurations": [
      {
        "Key": "<MyBeyondTrustManagedAccountsSafe>",
        "Type": "BeyondTrust Password Safe - Managed Accounts",
        "Context": {
          "Hostname": "<HostName>",
          "APIRegistrationKey": "<ApiRegistrationKey>",
          "APIRunAsUsername": "<Username>",
          "DefaultManagedSystemName": "", // can be empty or a string
          "SystemAccountDelimiter": "/", // default account delimiter is "/", but it can be changed
          "ManagedAccountType": "<ManagedAccountType>" // expected value is one of "system", "domainlinked", "database", "cloud", "application"
        }
      },
    ]
...
BeyondTrust Password Safe - Team Passwords​
...
"SecureStoreConfigurations": [
      {
        "Key": "<MyBeyondTrustTeamPasswordSafe>",
        "Type": "BeyondTrust Password Safe - Team Passwords",
        "Context": {
          "Hostname": "<HostName>",
          "APIRegistrationKey": "<ApiRegistrationKey>",
          "APIRunAsUsername": "<Username>",
          "FolderPathPrefix" : "/", // default delimiter is "/", but it can be changed
          "FolderPasswordDelimiter" : "/" // default delimiter is "/", but it can be changed
        }
      },
    ]
...
...
"SecureStoreConfigurations": [
      {
        "Key": "<MyBeyondTrustTeamPasswordSafe>",
        "Type": "BeyondTrust Password Safe - Team Passwords",
        "Context": {
          "Hostname": "<HostName>",
          "APIRegistrationKey": "<ApiRegistrationKey>",
          "APIRunAsUsername": "<Username>",
          "FolderPathPrefix" : "/", // default delimiter is "/", but it can be changed
          "FolderPasswordDelimiter" : "/" // default delimiter is "/", but it can be changed
        }
      },
    ]
...
CyberArk - AIM​
...
"SecureStoreConfigurations": [
      {
        "Key": "<MyCyberArk>",
        "Type": "CyberArk",
        "Context": {
          "ApplicationId": "<App_MyCyberArk>",
          "Safe": "<Passwords>",
          "Folder": "<MyFolder>"
        }
      },
    ]
...
...
"SecureStoreConfigurations": [
      {
        "Key": "<MyCyberArk>",
        "Type": "CyberArk",
        "Context": {
          "ApplicationId": "<App_MyCyberArk>",
          "Safe": "<Passwords>",
          "Folder": "<MyFolder>"
        }
      },
    ]
...

CLIPasswordSDKExePath、UsePowerShellCLI、AdditionalAllowedCharacters などのホスト レベルの設定は、Orchestrator の場合と同様に Appsettings パラメーターの下に配置する必要があります。

{
// ...
  "AppSettings": {
    "Plugins.SecureStores.CyberArk.CLIPasswordSDKExePath": "D:\\<MyPath>\\CLIPasswordSDK.exe",
    "Plugins.SecureStores": "UiPath.Orchestrator.CyberArk.dll;UiPath.Orchestrator.AzureKeyVault.SecureStore.dll;UiPath.Orchestrator.SecureStore.CyberArkCCP.dll;UiPath.Orchestrator.SecureStore.CyberArkConjur.dll;UiPath.Orchestrator.SecureStore.HashiCorpVault.dll;UiPath.Orchestrator.SecureStore.ThycoticSecretServer.dll;UiPath.Orchestrator.SecureStore.BeyondTrust.dll;UiPath.Orchestrator.SecureStore.AWSSecretsManager.dll;UiPath.Orchestrator.SecureStore.GoogleSecretManager.dll;UiPath.Orchestrator.SecureStore.DelineaSecretServer.dll",
    "CredentialsProxyType": "Disconnected"
    // ...
  }
  // ...
{
// ...
  "AppSettings": {
    "Plugins.SecureStores.CyberArk.CLIPasswordSDKExePath": "D:\\<MyPath>\\CLIPasswordSDK.exe",
    "Plugins.SecureStores": "UiPath.Orchestrator.CyberArk.dll;UiPath.Orchestrator.AzureKeyVault.SecureStore.dll;UiPath.Orchestrator.SecureStore.CyberArkCCP.dll;UiPath.Orchestrator.SecureStore.CyberArkConjur.dll;UiPath.Orchestrator.SecureStore.HashiCorpVault.dll;UiPath.Orchestrator.SecureStore.ThycoticSecretServer.dll;UiPath.Orchestrator.SecureStore.BeyondTrust.dll;UiPath.Orchestrator.SecureStore.AWSSecretsManager.dll;UiPath.Orchestrator.SecureStore.GoogleSecretManager.dll;UiPath.Orchestrator.SecureStore.DelineaSecretServer.dll",
    "CredentialsProxyType": "Disconnected"
    // ...
  }
  // ...
CyberArk - CCP​
...
"SecureStoreConfigurations": [
      {
        "Key": "<MyCyberArkCCPStore>",
        "Type": "CyberArkCCP",
        "Context": {
          "ApplicationId": "<ApplicationId>",
          "Safe": "<CyberArkSafe>",
          "Folder": "<CyberArkFolder>",
          "WebServiceUrl": "<CentralCredentialProviderUrl>",
          "WebServiceName": "<WebServiceName>",
          "SerializedClientCertificate": "<ClientCertificate>", // must be the ".pfx" file's content as base64 string
          "ClientCertificatePassword": "<ClientCertificatePassword>",
          "SerializedRootCA": "<someServerRootCA>" // must be the ".crt" or ".cer" file's content as base64 string
        }
      },
    ]
...
...
"SecureStoreConfigurations": [
      {
        "Key": "<MyCyberArkCCPStore>",
        "Type": "CyberArkCCP",
        "Context": {
          "ApplicationId": "<ApplicationId>",
          "Safe": "<CyberArkSafe>",
          "Folder": "<CyberArkFolder>",
          "WebServiceUrl": "<CentralCredentialProviderUrl>",
          "WebServiceName": "<WebServiceName>",
          "SerializedClientCertificate": "<ClientCertificate>", // must be the ".pfx" file's content as base64 string
          "ClientCertificatePassword": "<ClientCertificatePassword>",
          "SerializedRootCA": "<someServerRootCA>" // must be the ".crt" or ".cer" file's content as base64 string
        }
      },
    ]
...

IIS の設定によっては、以下のように追加の KeyStorageFlags を設定する必要がある場合があります。

"AppSettings": {
...
"Plugins.SecureStores.CyberArkCCP.KeyStorageFlags": "MachineKeySet",
...
}
"AppSettings": {
...
"Plugins.SecureStores.CyberArkCCP.KeyStorageFlags": "MachineKeySet",
...
}

PFX、CRT、または CER のファイルは、次の方法で base64 文字列に変換できます。

$fileContentBytes = get-content 'C:\path\to\the.pfx' -Encoding Byte
[System.Convert]::ToBase64String($fileContentBytes) | Out-File 'C:\path\to\the.txt'
$fileContentBytes = get-content 'C:\path\to\the.pfx' -Encoding Byte
[System.Convert]::ToBase64String($fileContentBytes) | Out-File 'C:\path\to\the.txt'
CyberArk® Conjur Cloud (読み取り専用)​
...
"SecureStoreConfigurations": [
      {
        "Key": "MyCyberArkConjur",
        "Type": "CyberArk Conjur Cloud (read only)",
        "Context": {
          "ServiceUrl": "https://{myCyberArkConjurUrl}/",
          "LoginName": "{myLoginName}",
          "ApiKey": "{myApiKey}",
          "VariableIdPrefix": "{myPrefix}"
        }
      },
    ]
...
...
"SecureStoreConfigurations": [
      {
        "Key": "MyCyberArkConjur",
        "Type": "CyberArk Conjur Cloud (read only)",
        "Context": {
          "ServiceUrl": "https://{myCyberArkConjurUrl}/",
          "LoginName": "{myLoginName}",
          "ApiKey": "{myApiKey}",
          "VariableIdPrefix": "{myPrefix}"
        }
      },
    ]
...
CyberArk® Conjur (読み取り専用)​
...
"SecureStoreConfigurations": [
  {
    "Key": "MyCyberArkConjur",
    "Type": "CyberArk Conjur (read only)",
    "Context": {
      "ApplianceUrl": "https://{company}.secretsmgr.cyberark.cloud/api",
      "Account": "{myAccount}",
      "AuthenticationType": "{Jwt|ApiKey}",
      "JWT":  {
          "JwtServiceId": "{myJwtServiceId}",
          "IdentityProviderUrl": "{myIdentityProviderUrl}",
          "ClientId": "{myClientId}",
          "ClientSecret": "{myClientSecret}",
          "Scope": "{myScope}"
      },
      "ApiKey": {
          "LoginName": "{myLoginName}",
          "Key": "{myApiKey}"
      },
      "HostId": "{myHostId}",
      "VariableIdPrefix": "{myPrefix}"
    }
  },
]
...
...
"SecureStoreConfigurations": [
  {
    "Key": "MyCyberArkConjur",
    "Type": "CyberArk Conjur (read only)",
    "Context": {
      "ApplianceUrl": "https://{company}.secretsmgr.cyberark.cloud/api",
      "Account": "{myAccount}",
      "AuthenticationType": "{Jwt|ApiKey}",
      "JWT":  {
          "JwtServiceId": "{myJwtServiceId}",
          "IdentityProviderUrl": "{myIdentityProviderUrl}",
          "ClientId": "{myClientId}",
          "ClientSecret": "{myClientSecret}",
          "Scope": "{myScope}"
      },
      "ApiKey": {
          "LoginName": "{myLoginName}",
          "Key": "{myApiKey}"
      },
      "HostId": "{myHostId}",
      "VariableIdPrefix": "{myPrefix}"
    }
  },
]
...
Delinea Secret Server (読み取り専用)​
注:

Delinea Secret Server (読み取り専用) には、Orchestrator Credentials Proxy 2.2.2 以降が必要です。プラグイン UiPath.Orchestrator.SecureStore.DelineaSecretServer.dllはインストール キットに同梱されており、既定で Plugins.SecureStores に表示されているため、手動で追加する必要はありません。

これは読み取り専用の資格情報ストアです。プロキシはそこからアセット値とロボットの資格情報を取得できますが、シークレットを作成、更新、削除することはできません。

...
"SecureStoreConfigurations": [
      {
        "Key": "<MyDelineaServer>",
        "Type": "Delinea Secret Server (read only)",
        "Context": {
          "PlatformServerUrl": "<PlatformServerUrl>",
          "SecretServerUrl": "<SecretServerUrl>",
          "RuleName": "<Rule>",
          "RuleKey": "<Key>",
          "UsernameField": "<Username>",
          "PasswordField": "<Password>"
        }
      },
    ]
...
...
"SecureStoreConfigurations": [
      {
        "Key": "<MyDelineaServer>",
        "Type": "Delinea Secret Server (read only)",
        "Context": {
          "PlatformServerUrl": "<PlatformServerUrl>",
          "SecretServerUrl": "<SecretServerUrl>",
          "RuleName": "<Rule>",
          "RuleKey": "<Key>",
          "UsernameField": "<Username>",
          "PasswordField": "<Password>"
        }
      },
    ]
...

Contextフィールドは次のとおりです。

  • PlatformServerUrl - (必須) Delinea プラットフォームの URL です (例: https://<tenant>.delinea.app)。
  • SecretServerUrl - (必須) シークレット サーバーの URL です (例: https://<tenant>.secretservercloud.eu)。これを取得するには、Delinea テナントの [Secret Server connection ] ページに移動します。
  • RuleName - (必須) Delinea で作成した SDK クライアントのオンボーディング ルールの名前です。
  • RuleKey - (任意) ルールのオンボーディング キーです。Delinea で [オンボーディング キーが必要] が有効化されていない場合は、空のままにします。このフィールドは任意ですが、セキュリティを向上させるために設定することをお勧めします。
  • UsernameField - (必須) ユーザー名の読み込み元のシー クレット テンプレート フィールドのスラグ名です (例: username)。
  • PasswordField - (必須) パスワードの読み込み元のシー クレット テンプレート フィールドのスラグ名です (例: password)。
注:

Delineaの継続的なプラットフォーム移行中は、 PlatformServerUrl と SecretServerUrl の両方が必要です。プロキシは PlatformServerUrl を使用して Delinea プラットフォームがアクセス可能であることを確認し、シークレット自体を取得する SecretServerUrl します。

シークレット テンプレート フィールドのスラッグ名は、[管理] > [シークレット テンプレート] > [テンプレート> フィールド] で確認できます。UsernameField と PasswordField の値は大文字と小文字を区別しません。

このストアにリンクされているアセットとロボットの資格情報では、Delinea Secret Server の数値 のシークレット ID を 外部名として使用する必要があります。文字列名はサポートされていません。

前提条件と Delinea 側の設定 ( SDK クライアント管理 の有効化、オンボーディング ルールの作成など) については、「 資格情報ストアを連携する 」ページの「 Delinea Secret Server との連携 」のセクションをご覧ください。

HashiCorp Vault/HashiCorp Vault (読み取り専用)​

次のサンプルでは、KeyValueV2 シークレット エンジンに対して AppRole 認証を使用します。各パラメーターの意味、認証方法とシークレット エンジンに必要なパラメーター、個々のシークレットのパスへの とSecretsEngineMountPath DataPath解決方法については、「 資格情報ストアを管理する 」の「 HashiCorp Vault 」をご覧ください。

...
"SecureStoreConfigurations": [
      {
        "Key": "<MyHashiCorp>",
        "Type": "HashiCorp Vault", // or "HashiCorp Vault (read only)"
        "Context": {
          "VaultUri": "https://vault.example.com:8200",
          "AuthenticationType": "AppRole", // or "UsernamePassword", "Ldap", "Token"
          "AuthenticationMountPath": "", // optional, defaults to the name of the authentication method
          "RoleId": "<RoleId>",
          "SecretId": "<SecretId>",
          "Username": "", // with "UsernamePassword" or "Ldap"
          "Password": "", // with "UsernamePassword" or "Ldap"
          "Token": "", // with "Token"
          "SecretsEngine": "KeyValueV2", // or "KeyValueV1"; read-only also accepts "ActiveDirectory", "OpenLDAP", "LDAP"
          "SecretsEngineMountPath": "uipath/kv", // the mount only - no "data" segment, no secret path
          "DataPath": "orchestrator/assets", // the prefix inside the mount - no mount, no "data" segment
          "Namespace": "", // Vault Enterprise only
          "LdapUseDynamicCredentials": "false", // with the "LDAP" secrets engine
          "KerberosSPN": "" // with Kerberos authentication
        }
      }
    ]
...
...
"SecureStoreConfigurations": [
      {
        "Key": "<MyHashiCorp>",
        "Type": "HashiCorp Vault", // or "HashiCorp Vault (read only)"
        "Context": {
          "VaultUri": "https://vault.example.com:8200",
          "AuthenticationType": "AppRole", // or "UsernamePassword", "Ldap", "Token"
          "AuthenticationMountPath": "", // optional, defaults to the name of the authentication method
          "RoleId": "<RoleId>",
          "SecretId": "<SecretId>",
          "Username": "", // with "UsernamePassword" or "Ldap"
          "Password": "", // with "UsernamePassword" or "Ldap"
          "Token": "", // with "Token"
          "SecretsEngine": "KeyValueV2", // or "KeyValueV1"; read-only also accepts "ActiveDirectory", "OpenLDAP", "LDAP"
          "SecretsEngineMountPath": "uipath/kv", // the mount only - no "data" segment, no secret path
          "DataPath": "orchestrator/assets", // the prefix inside the mount - no mount, no "data" segment
          "Namespace": "", // Vault Enterprise only
          "LdapUseDynamicCredentials": "false", // with the "LDAP" secrets engine
          "KerberosSPN": "" // with Kerberos authentication
        }
      }
    ]
...

ホスト レベルの設定は、Orchestrator の場合と同じように [ AppSettings ] パラメーターの下に配置されます。各ストアは独自のプレフィックスのみを読み取るため、両方のストアを構成するには、各設定を 2 回追加します。すべての設定リストとその既定値については、「 ホスト レベルの設定」をご覧ください。

{
// ...
  "AppSettings": {
    // Optional, for Kerberos enablement
    "Plugins.SecureStores.HashiCorp Vault.KerberosEnabled": "true",
    "Plugins.SecureStores.HashiCorp Vault (read only).KerberosEnabled": "true",
    // Optional, for forwarding to the active node
    "Plugins.SecureStores.HashiCorp Vault.ForwardToActiveNode": "true",
    "Plugins.SecureStores.HashiCorp Vault (read only).ForwardToActiveNode": "true"
    // ...
  }
  // ...
}
{
// ...
  "AppSettings": {
    // Optional, for Kerberos enablement
    "Plugins.SecureStores.HashiCorp Vault.KerberosEnabled": "true",
    "Plugins.SecureStores.HashiCorp Vault (read only).KerberosEnabled": "true",
    // Optional, for forwarding to the active node
    "Plugins.SecureStores.HashiCorp Vault.ForwardToActiveNode": "true",
    "Plugins.SecureStores.HashiCorp Vault (read only).ForwardToActiveNode": "true"
    // ...
  }
  // ...
}
Thycotic Secret Server​
重要:

Thycotic Secret Server ストアは、上記のセクションで説明されている Delinea Secret Server (読み取り専用) ストアによって引き継がれます。両方のストアは、同じ基盤となる SDK と同じルールベースのオンボーディング メカニズムを共有しているため、 Context フィールドはほぼ同じです。既存の Thycotic 資格情報ストアを新しい Delinea ストアに移行することを強くお勧めします。

...
"SecureStoreConfigurations": [
      {
        "Key": "<MyThicoticServer>",
        "Type": "Thycotic Secret Server",
        "Context": {
          "SecretServerUrl": "<ServerUrl>",
          "RuleName": "<Rule>",
          "RuleKey": "<Key>",
          "UsernameField": "<Username>",
          "PasswordField": "<Password>"
        }
      },
    ]
...
...
"SecureStoreConfigurations": [
      {
        "Key": "<MyThicoticServer>",
        "Type": "Thycotic Secret Server",
        "Context": {
          "SecretServerUrl": "<ServerUrl>",
          "RuleName": "<Rule>",
          "RuleKey": "<Key>",
          "UsernameField": "<Username>",
          "PasswordField": "<Password>"
        }
      },
    ]
...
Google Secret Manager​
...
"SecureStoreConfigurations": [
      {
        "Key": "<GoogleSecretManager>",
        "Type": "Google Secret Manager",
        "Context": {
          "ProjectId": "<ProjectId>",
          "ServiceAccountKeyJson": "<ServiceAccountKeyJson>",
        }
      },
    ]
...
...
"SecureStoreConfigurations": [
      {
        "Key": "<GoogleSecretManager>",
        "Type": "Google Secret Manager",
        "Context": {
          "ProjectId": "<ProjectId>",
          "ServiceAccountKeyJson": "<ServiceAccountKeyJson>",
        }
      },
    ]
...
Google Secret Manager (読み取り専用)​
...
"SecureStoreConfigurations": [
      {
        "Key": "<GoogleSecretManager>",
        "Type": "Google Secret Manager (read only)",
        "Context": {
          "ProjectId": "<ProjectId>",
          "ServiceAccountKeyJson": "<ServiceAccountKeyJson>",
        }
      },
    ]
...
...
"SecureStoreConfigurations": [
      {
        "Key": "<GoogleSecretManager>",
        "Type": "Google Secret Manager (read only)",
        "Context": {
          "ProjectId": "<ProjectId>",
          "ServiceAccountKeyJson": "<ServiceAccountKeyJson>",
        }
      },
    ]
...
複数の資格情報ストア​

複数の資格情報ストアを使用する場合は、以下のように並べて追加できます。

{
...
  "AppSettings": {
  ...
    "SecureStoreConfigurations": [
      {
        "Key": "<SecureStoreKey1>",
        "Type": "AzureKeyVault (read only)",
        "Context": {
          "KeyVaultUri": "<Uri>",
          "DirectoryId": "<DirectoryId>",
          "ClientId": "<ClientId>",
          "ClientSecret": "<ClientSecret>"
        }
      },
      {
        "Key": "<SecureStoreKey2>",
        "Type": "BeyondTrust Password Safe - Managed Accounts",
        "Context": {
          "Hostname": "<Host>",
          "APIRegistrationKey": "<ApiKey>",
          "APIRunAsUsername": "<ApiUsername>",
          "DefaultManagedSystemName": "",
          "SystemAccountDelimiter": "/",
          "ManagedAccountType": "system"
        }
      }
    ]
  ...
  }
}
{
...
  "AppSettings": {
  ...
    "SecureStoreConfigurations": [
      {
        "Key": "<SecureStoreKey1>",
        "Type": "AzureKeyVault (read only)",
        "Context": {
          "KeyVaultUri": "<Uri>",
          "DirectoryId": "<DirectoryId>",
          "ClientId": "<ClientId>",
          "ClientSecret": "<ClientSecret>"
        }
      },
      {
        "Key": "<SecureStoreKey2>",
        "Type": "BeyondTrust Password Safe - Managed Accounts",
        "Context": {
          "Hostname": "<Host>",
          "APIRegistrationKey": "<ApiKey>",
          "APIRunAsUsername": "<ApiUsername>",
          "DefaultManagedSystemName": "",
          "SystemAccountDelimiter": "/",
          "ManagedAccountType": "system"
        }
      }
    ]
  ...
  }
}

検証​

重要:

これは、非接続の資格情報プロキシにのみ適用されます。

プロキシは、検出した種類が Disconnected の場合、起動時に設定を検証します。

プロキシが実行する検証手順の一部を以下に示します。

  • プロキシにより、上記の「設定」セクションで詳しく説明されている設定が、appsettings.Production.json に想定どおりに含まれていることが確認されます。
  • プロキシにより、SecureStoreConfigurations に重複する Key パラメーターが含まれないように、つまり、appsettings.Production.json ファイルで設定された資格情報ストアが一意であることが確認されます。
  • SecureStoreConfigurations パラメーターは、複数の値を列挙して設定できます。資格情報ストアを、同じ種類のものであっても、必要な数だけ追加できます。たとえば、Key フィールドが一意である限り、複数の Azure Key Vault (読み取り専用) インスタンスを設定できます。
  • プロキシによって、すべての Type 値が有効であることが確認されます。
  • 各 Secure Store の実装に基づいて、コンテナーに正常に到達できることがプロキシによって確認されます。

ログ​

Orchestrator Credentials Proxy のログはローカルの C:\Program Files\UiPath\OrchestratorCredentialsProxy フォルダーに保存されます (プロキシのアプリケーション プールにそのパスへの書き込み権限がある場合)。これらは IIS で設定されます。

そのフォルダーへの書き込みアクセス許可を与えない場合は、appsettings.Production.json の NLog.targets.logfile.fileName パラメーターを使用して、任意の相対パスまたは絶対パスを指定します。

Windows マシンでは、プロキシは Windows イベント ビューアーにもログを保存します。

セキュリティに関する考慮事項​

  • Orchestrator では、プロキシに対してセキュリティで保護された (HTTPS) URL のみが許可されます。証明書の要件はプロキシの種類によって異なります。
    • 接続状態のプロキシ - HTTPS 証明書は パブリック URL に対して有効で、Orchestrator が検証できる認証局 (広く認知されているパブリック証明書プロバイダー) によって署名されている必要があります。自己署名証明書はサポートされていません。
    • 非接続のプロキシ - 通信はユーザー独自のインフラストラクチャ内に留まるため、ロボットを実行するマシンが信頼する限り、内部の証明機関によって署名された証明書と自己署名証明書がサポートされます。
  • Orchestrator は、Orchestrator Credentials Proxy によって生成されたクライアント シークレットで検証されます。このクライアント シークレットは、Orchestrator Credentials Proxy がインストールされているマシンの構成ファイルに保存され、Orchestrator によって暗号化され、データベースに保存されます。
  • Orchestrator で資格情報ストア プロキシを編集してその URL を変更する場合、クライアント シークレットも入力する必要があります。
  • Orchestrator Credentials Proxy 2.0.0 以降のアクションは、Windows イベント ビューアーに記録されます。
  • バイナリは Windows マシンで署名される必要があります。
  • Docker イメージは署名されている必要があります。

ロード バランサーで Orchestrator Credentials Proxy を使用する​

プロキシをロード バランサーと組み合わせて使用する場合は、すべてのノードで同じ構成を維持するようにしてください。

ノード間で同一である必要がある要素​

  • プロキシ インストーラーのバージョン。たとえば、バージョン 1.0.0 を使用する場合は、すべてのロード バランサー ノードでも 1.0.0 を使用する必要があります。
  • アプリケーション構成ファイルの設定。ほとんどの場合、appsettings.json と appsettings.Production.json です。appsettings.Production.json はインストールごとに一意であるため、一貫性を確保するには、手動で各ノードに追加する必要があります。
  • path/plugins に追加された資格情報ストア プラグイン。UiPath がサポートするプラグインはすべてすでにこのフォルダーにあるため、注意が必要なのは追加するカスタム プラグインのみです。

考慮すべき重要事項​

  • プロキシのインストール用に提供されている Docker イメージの構成に変更を加える場合は、代わりにカスタム Docker イメージを作成することを強くお勧めします。次に、このカスタム イメージを使用して、すべてのノードにプロキシをデプロイする必要があります。
  • 一部の環境変数は、ランタイムに影響を与える可能性があります。たとえば、appsettings.json 構成値をオーバーライドする環境変数や、.NET 環境に影響を与える環境変数などです。
  • 専用の非認証エンドポイント https://{YourOrchestratorCredentialsProxyURL}/api/v1/Health を使用して、Orchestrator Credentials Proxy がまだ実行中かどうかを確認できます。

Orchestrator Credentials Proxy の証明書を更新する​

シングルノードのインストールの場合は、次の手順で SSL 証明書を更新します。

  1. 新しい証明書を、ローカル マシンの証明書コンソール (certlm.msc) の [証明書] の下にある [個人] フォルダーにインポートします。
  2. IIS 管理コンソールで、[サイト] を展開して [UiPath Orchestrator Credential Proxy] を選択します。
  3. 右側のパネルから [バインド...] を選択します。
  4. [バインド...] ビューから既定のhttps レコードを選択し、[選択...] ボタンを使用して証明書を選択します。
  5. [証明書の選択] ポップアップ ウィンドウで、新しく追加した証明書を選択します。
  6. セットアップが完了するまで [OK] を選択します。
    注:

    マルチノードのインストールの場合は、必ずすべてのマシンで証明書を更新してください。

ロード バランサーを使用しているインストールの証明書を更新するには、上記と同じ手順を使用します。Orchestrator Credentials Proxy はステートレスであるため、証明書を更新する際はロード バランサーからノードを削除してください。

キーのローテーション​

ダウンタイムを伴うキーのローテーション​

注:

この操作では、実行中の Orchestrator Credentials Proxy を停止して再起動する必要があります。これは、Orchestrator によって実行されるライブ要求に影響を与える可能性があります。

  1. Orchestrator Credentials Proxy の標準に従って新しいシークレット キーを生成します。
  2. Orchestrator Credentials Proxy を停止します。
  3. appsettings.Production.json ファイルを編集し、既存のキーを新しいキーで上書きします。
  4. Orchestrator Credentials Proxy を起動します。
  5. Orchestrator で Orchestrator Credentials Proxy に移動し、[Secret] フィールドを編集して新しいシークレットを指定します。

ダウンタイムを伴わないキーのローテーション​

注:

この操作には、ロード バランサーを備えた Orchestrator Credentials Proxy と、2 つ以上の Orchestrator Credentials Proxy インスタンスが必要です。詳しくは、「 インストール 」をご覧ください。

  1. Orchestrator Credentials Proxy の標準に従って新しいシークレット キーを生成します。
  2. 新しく生成されたキーを Credentials Proxy インスタンスに追加します。各インスタンスで以下の手順を実行します。
    1. Orchestrator Credentials Proxy インスタンスをロード バランサーから除外します。
    2. Orchestrator Credentials Proxy インスタンスを停止します。
    3. appsettings.Production.json ファイルを開きます。このファイルには次のようなコードが含まれています。
      {
          "Jwt": {
              "Keys": [
                  "{{OldKey}}"
              ],
      {
          "Jwt": {
              "Keys": [
                  "{{OldKey}}"
              ],
      
    4. 既存のキーを保持したまま、新しく生成されたキーを追加します。Keys パラメーターには、複数の値をコンマで区切って指定できます。
      {
          "Jwt": {
              "Keys": [
                  "{{OldKey}}",
                  "{{NewKey}}"
              ],
      {
          "Jwt": {
              "Keys": [
                  "{{OldKey}}",
                  "{{NewKey}}"
              ],
      
    5. Orchestrator Credentials Proxy を起動します。
    6. Orchestrator Credentials Proxy インスタンスをロード バランサーに戻します。
  3. Orchestrator で Orchestrator Credentials Proxy に移動し、[Secret] フィールドを編集して新しいシークレットを指定します。
  4. しばらくしてから、Credentials Proxy インスタンスから古いキーを取得します。各インスタンスで以下の手順を実行します。
    1. Orchestrator Credentials Proxy インスタンスをロード バランサーから除外します。
    2. Orchestrator Credentials Proxy インスタンスを停止します。
    3. appsettings.Production.json ファイルを開きます。このファイルには、前の手順で説明した次の 2 つのキーが含まれています。
      {
          "Jwt": {
              "Keys": [
                  "{{OldKey}}",
                  "{{NewKey}}"
              ],
      {
          "Jwt": {
              "Keys": [
                  "{{OldKey}}",
                  "{{NewKey}}"
              ],
      
    4. ファイルから古いキーを削除して次のようにします: { "Jwt": { "Keys": [ "{{NewKey}}" ],
    5. Orchestrator Credentials Proxy を起動します。
    6. Orchestrator Credentials Proxy インスタンスをロード バランサーに戻します。

このページは役に立ちましたか?

接続

ヘルプ リソース サポート

学習する UiPath アカデミー

質問する UiPath フォーラム

最新情報を取得