UiPath Documentation
orchestrator
latest
false
Orchestrator ユーザー ガイド
重要 :
このコンテンツの一部は機械翻訳によって処理されており、完全な翻訳を保証するものではありません。 新しいコンテンツの翻訳は、およそ 1 ~ 2 週間で公開されます。

Orchestrator Credentials Proxy

Orchestrator Credentials Proxy を設定して、カスタムの資格情報ストア プラグインを Orchestrator に接続します。

Orchestrator に独自の資格情報ストアを追加することで、接続データのセキュリティを独自に制御できます。

そのためには、必要な資格情報ストア プラグインを .dll ファイルの形式で、Orchestrator の Credentials Proxy Web サービスに読み込みます。インストール キットには UiPath がサポートするすべてのプラグインが含まれていますが、独自のプラグイン .dll ファイルを開発して読み込むこともできます。

次に、このサービスによって、プロキシ経由でプラグインを利用できるようになります。 プロキシは、プロキシによって生成されたパブリック URL とシークレット キーに基づいて Orchestrator で作成されます。

既知の問題

アップグレード後にカスタム ポートを 443 にリセット

この問題は、Orchestrator Credentials Proxy が既定の 443 以外のポートを使用するよう設定されている場合にのみ適用されます。

1.0.0 から 2.0.1 までの任意のバージョンからアップグレードするときに、カスタム ポートを使用していても、受信規則 UiPathOrchestratorCredentialsProxy のローカル ポートが自動的に 443 (既定値) に変更されます。これにより、プロキシへの接続が確立されなくなります。

この問題を回避するには、アップグレード時に受信規則のローカル ポートを手動で変更する必要があります。

インストール

Orchestrator Credentials Proxy は、UiPath が提供する .msi インストーラー、または Docker イメージを使用してインストールできます。

.msi インストーラーを使用する

前提条件

Orchestrator Credentials Proxy は IIS でホストされる ASP.NET Core Web アプリケーションであるため、IIS 8.0 以降をホストできる任意の Windows エディションにインストールできます。これには、Windows Server と Windows 10 および Windows 11 クライアントの両方が含まれます。Windows Server は必須ではありません。

ハードウェア要件

IIS を搭載した Windows マシンでプロキシを実行するための最小要件は以下のとおりです。実際に必要なリソースは、個々の使用状況によって異なります。

CPU コアRAM
24 GB
ソフトウェア要件

プロキシをホストするマシンは、次の要件を満たす必要があります。

  • オペレーティング システム - IIS 8.0 以降をサポートする任意の Windows エディション。Windows Server 2012 R2、2016、2019、2022、および 2025 はすべて、Windows 10 および Windows 11 と同様に、この要件を満たしています。
  • IIS - バージョン 8.0 以降
  • .NET ホスティング バンドル - バージョン 10.0 以降 (.NET 10 で動作する Orchestrator Credentials Proxy 2.2.2 以降の場合)。2.2.2 より前のバージョンのプロキシには、バージョン 3.1 以降が必要です。このバンドルでは、ASP.NET Core ランタイムと ASP.NET Core IIS モジュールの両方がインストールされます。これらはプロキシを IIS で実行するために必要なものです。
    重要:

    以前のバージョンから Orchestrator Credentials Proxy 2.2.2 以降にアップグレードする場合は、アップグレードしたプロキシを起動する前に、ホスト マシンに .NET 10 ホスティング バンドルをインストールし、IIS を再起動してください。タイムアウトが指定されていない場合、プロキシは IIS での起動に失敗します。

さらに、次の IIS 機能を有効化する必要があります。

  • IIS-DefaultDocument
  • IIS-HttpErrors
  • IIS-StaticContent
  • IIS-RequestFiltering
  • IIS-URLAuthorization
  • IIS-WindowsAuthentication
  • IIS-ASPNET45
  • IIS-ISAPIExtensions
  • IIS-ISAPIFilter
  • IIS-WebSockets
  • IIS-ApplicationInit
  • IIS-ManagementConsole

これらの機能を有効化する方法は、Windows のエディションによって異なります。

  • Windows Server - サーバー マネージャー を使用して> 役割や機能を追加します
  • Windows 10 および Windows 11 - [コントロール パネル] > [プログラム] にある [Windows の機能の有効化または無効化] ユーティリティを使用します。
注:

インストーラーは、何かをインストールする前に、IIS バージョン、コア IIS モジュールの ASP.NET、および上記の IIS 機能を検証します。いずれかのフィールドが見つからない場合、インストールが停止し、追加する必要がある内容が報告されます。

インストールの手順

インストールを実行するには、以下の手順に従います。

  1. Customer Portal から UiPath Orchestrator Credential Proxy インストーラーをダウンロードします。
  2. プロキシをインストールします。
接続状態のプロキシ
  • パブリック URL - パブリックに公開されている Orchestrator Credentials Proxy の URL です。
  • SSL 証明書 - Orchestrator Credentials Proxy との接続をセキュリティで保護するために使用される SSL 証明書のサブジェクトまたは拇印です。これは、プロキシをホストするコンピューターまたは Web サーバーにインストールされた SSL 証明書です。 パブリックな証明書プロバイダーによって発行される必要があり、パブリック URL に対して有効である必要がありますのでご注意ください。
  • ポート - パブリック URL に対応するポートです。
  • シークレット キー - Orchestrator のインターフェイスでカスタム プロキシを構成するのに必要なキー (自動生成) です。後で使用できるよう、クリップボードにコピーしておいてください。

これは手動で変更できて、キー ローテーションにも適しています。

非接続のプロキシ

この機能は、フレックス プライシング プランの Enterprise - Advanced ライセンス プラン、またはユニファイド プライシング プランの Enterprise または Application Test Enterprise の場合にのみ利用できます。

  • SSL Certificate - the Subject or Thumbprint of the SSL certificate used to secure connections with the Orchestrator Credentials Proxy. This is the SSL certificate installed on the computer or web server hosting the proxy. Since robots connect to the proxy inside your own infrastructure, this certificate can be self-signed or issued by your internal certificate authority, as long as the machines running your robots trust it.
  • ポート - URL に対応するポートです。
  • シークレット キー - Orchestrator のインターフェイスでカスタム プロキシを構成するのに必要なキー (自動生成) です。後で使用できるよう、クリップボードにコピーしておいてください。

これは手動で変更できて、キー ローテーションにも適しています。

注:

非接続のプロキシの場合、ロボットは Orchestrator を経由せずにプロキシに直接接続します。この接続は、プロキシの パブリック URL に設定されているポート (既定では 443) で HTTPS を使用します。接続状態のプロキシの種類と非接続のプロキシの種類について詳しくは、「 資格情報ストアのプロキシを管理する 」をご覧ください。

インストール時に、appsettings.Production.json ファイルの AppSettings.CredentialsProxyType パラメーターは Disconnected に設定されます。これによって、プロキシは起動時に接続/非接続を検出します。

注:

プロキシを動作させるには、IIS で [匿名認証 ] オプションを [有効 ] に設定する必要があります。

Jwt:Keysパラメーターを暗号化する

さらにセキュリティのレイヤーを追加するには、appsettings.json ファイルの Jwt:Keys パラメーターと SecureStoreConfigurations:Context パラメーターを暗号化します。

注:

これには、UiPath.ConfigProtector.exe v1.0.9 以上が必要です。

Docker イメージを使用する

予備情報

Orchestrator Credentials Proxy の編集可能な設定はすべて、appsettings.json ファイルで利用できます。初期の設定では以下のパラメーターが重要です。

  • Jwt:Keys - (最初は空) プロキシの認証を設定するために、この文字列の配列が使用されます。プロキシの作成プロセスで使用するシークレット キーはこの配列で構成され、Orchestrator がプロキシからデータを正常に取得できるようになります。無効な値は無視されます。有効な値が見つからなかった場合、プロキシは起動しません。

シークレット キーは Base64 形式である必要があり、以下の PowerShell スクリプトのいずれかを使用して生成できます。

$bytes = [System.Security.Cryptography.RandomNumberGenerator]::GetBytes(64)
$jwtSigningKey = [Convert]::ToBase64String($bytes);
Write-Host $jwtSigningKey
$bytes = [System.Security.Cryptography.RandomNumberGenerator]::GetBytes(64)
$jwtSigningKey = [Convert]::ToBase64String($bytes);
Write-Host $jwtSigningKey

上記のスクリプトはランダムな 64 バイトを SeccureRandomを使用して生成し、Base64 文字列に変換します。

[Byte[]] $bytes = 1..64
$rng = New-Object System.Security.Cryptography.RNGCryptoServiceProvider
$rng.GetBytes($bytes)
$jwtSigningKey = [Convert]::ToBase64String($bytes);
Write-Host $jwtSigningKey
[Byte[]] $bytes = 1..64
$rng = New-Object System.Security.Cryptography.RNGCryptoServiceProvider
$rng.GetBytes($bytes)
$jwtSigningKey = [Convert]::ToBase64String($bytes);
Write-Host $jwtSigningKey
  • appSettings:Plugins.SecureStores - (最初は Orchestrator で利用可能な既定の資格情報ストアに設定) これは、プロキシによる Secure Store の使用を有効化するために、ディスク (path/plugins) から読み込むべき .dll アセンブリを指定する目的で使用される CSV 文字列です。無効なアセンブリをリストに追加してもスタートアップは破損しませんが、デプロイしようとするとログのエラーが発生します。
  • appSettings:SigningCredentialSettings:FileLocation:SigningCredential:FilePathappSettings:SigningCredentialSettings:FileLocation:SigningCredential:Password - (最初は非表示) Jwt:Keys および SecureStoreConfigurations:Context パラメーターを暗号化するために使用されます。これは、署名証明書へのファイル パスを表します。
  • appSettings:SigningCredentialSettings:StoreLocation:NameappSettings:SigningCredentialSettings:StoreLocation:LocationappSettings:SigningCredentialSettings:StoreLocation:NameType - (最初は非表示) Jwt:Keys および SecureStoreConfigurations:Context パラメーターを暗号化するために使用されます。
Docker イメージをセットアップして実行する

Docker を使用して Orchestrator Credentials Proxy を実行するには、以下の手順に従います。

  1. Docker イメージをダウンロードする

イメージは http://registry.uipath.com/ からダウンロードできます。

注:

この URL に Orchestrator Credentials Proxy の必要なバージョンを含めます。 たとえば、バージョン 2.1.4 のイメージをダウンロードするには、次の URL を使用します。

http://registry.uipath.com/orchestrator-credentialsproxy:2.1.4
http://registry.uipath.com/orchestrator-credentialsproxy:2.1.4

この URL は Docker イメージを指しており、Web ブラウザーではなく Docker CLI を使用してアクセスする必要があります。

バージョン 1.0.0 では接続状態のプロキシのみがサポートされますが、バージョン 2.0.0 以降では非接続のプロキシもサポートされます。

イメージを取得するには、次のコマンドを使用します。

$bytes = [System.Security.Cryptography.RandomNumberGenerator]::GetBytes(64);
$jwtSigningKey = [Convert]::ToBase64String($bytes);
docker run -e LICENSE_AGREEMENT=accept -e Jwt__Keys__0=$jwtSigningKey -p 8000:8080 registry.uipath.com/orchestrator-credentialsproxy:1.0.0
$bytes = [System.Security.Cryptography.RandomNumberGenerator]::GetBytes(64);
$jwtSigningKey = [Convert]::ToBase64String($bytes);
docker run -e LICENSE_AGREEMENT=accept -e Jwt__Keys__0=$jwtSigningKey -p 8000:8080 registry.uipath.com/orchestrator-credentialsproxy:1.0.0

これは既定の UiPath イメージであり、お使いのクラウド アカウントで既に利用可能な資格情報ストアが含まれています。イメージは、選択したクラウド環境にデプロイできます。

上記のコマンドではシークレット キーも生成されます。

  1. 独自のカスタム Docker イメージを作成する

手順 1 でダウンロードした、UiPath が提供するイメージに基づいて、追加のアセンブリを含む独自の Docker イメージを作成できます。このためには、以下の手順に従います。

  1. Dockerfile を新たに作成し (分かりやすいようここでは CustomDockerfile という名前を付けます)、以下を追加します。
    FROM {docker-image-path}
    RUN rm -rf ./plugins 
    COPY --chown=1001:0 {path of your custom assemblies} ./plugins 
    ENTRYPOINT ["dotnet", "UiPath.OrchestratorCredentialsProxy.dll"]
    FROM {docker-image-path}
    RUN rm -rf ./plugins 
    COPY --chown=1001:0 {path of your custom assemblies} ./plugins 
    ENTRYPOINT ["dotnet", "UiPath.OrchestratorCredentialsProxy.dll"]
    
    • {docker-image-path} を、UiPath が提供する初期状態の Docker イメージのパスに置き換えます。
    • {path of your custom assemblies} を独自の資格情報ストアへのパスに置き換えます.dllファイル。Visual Studio でこの Dockerfile を使用し、イメージを構築してデバッグを高速化する方法について詳しくは、こちらをご覧ください
  2. 次のコマンドを使用して Docker イメージを生成します。これには、新しく作成された Dockerfile の名前が含まれます。
    docker build -f CustomDockerfile . -t customproxy
    docker build -f CustomDockerfile . -t customproxy
    
  3. Docker イメージを実行する
    docker run --publish 8000:8080 -e LICENSE_AGREEMENT="accept" -e Jwt__Keys__0=$jwtSigningKey -e appSettings__Plugins.SecureStores="{your-list-of-assemblies}" customproxy
    docker run --publish 8000:8080 -e LICENSE_AGREEMENT="accept" -e Jwt__Keys__0=$jwtSigningKey -e appSettings__Plugins.SecureStores="{your-list-of-assemblies}" customproxy
    
    • {your-list-of-assemblies} を、Orchestrator に追加するカスタム資格情報ストアの .dll ファイルに置き換えます。

1 つの Jwt:Keys パラメーターでイメージを実行する場合:

  ```
  docker run --publish 8000:8080 -e LICENSE_AGREEMENT="accept" -e Jwt__Keys__0=$jwtSigningKey {docker-image-name}
  ```
  ```
  docker run --publish 8000:8080 -e LICENSE_AGREEMENT="accept" -e Jwt__Keys__0=$jwtSigningKey {docker-image-name}
  ```

複数の Jwt:Keys パラメーターでイメージを実行する場合:

  ```
  docker run --publish 8000:8080 -e LICENSE_AGREEMENT="accept" -e Jwt__Keys__0==$jwtSigningKey" -e Jwt__Keys__1==$jwtSigningKey" -e Jwt__Keys__2==$jwtSigningKey ... {docker-image-name}
  ```
  * Replace `{docker-image-name}` with the name you set for your custom Docker image.
  ```
  docker run --publish 8000:8080 -e LICENSE_AGREEMENT="accept" -e Jwt__Keys__0==$jwtSigningKey" -e Jwt__Keys__1==$jwtSigningKey" -e Jwt__Keys__2==$jwtSigningKey ... {docker-image-name}
  ```
  * Replace `{docker-image-name}` with the name you set for your custom Docker image.

appSettings:Plugins.SecureStores パラメーターのカスタム値 (すなわち、目的の資格情報ストア) でイメージを実行するには、このパラメーターの内容を独自の資格情報ストアの .dll ファイルに置き換えます。次のようにします。

  ```
  docker run --publish 8000:8080 -e LICENSE_AGREEMENT="accept" -e Jwt__Keys__0=$jwtSigningKey -e appSettings__Plugins.SecureStores="UiPath.Orchestrator.CyberArk.dll;UiPath.Orchestrator.AzureKeyVault.SecureStore.dll" {docker-image-name}
  ```
  ```
  docker run --publish 8000:8080 -e LICENSE_AGREEMENT="accept" -e Jwt__Keys__0=$jwtSigningKey -e appSettings__Plugins.SecureStores="UiPath.Orchestrator.CyberArk.dll;UiPath.Orchestrator.AzureKeyVault.SecureStore.dll" {docker-image-name}
  ```

4. (任意) 新しい Docker イメージをテストする

イメージをテストするには、http://localhost:8000/swagger/index.html で Swagger インターフェイスにアクセスし、専用の非認証エンドポイント /Health が機能していることを確認します。リクエストが成功すると、HTTP ステータス コード 200 OK とともに空の応答が返されます。

構成

接続状態のプロキシと非接続のプロキシ

プロキシ設定の最初の手順は、使用するカスタム .dll プラグインを C:\Program Files\UiPath\CredentialsProxy\plugins フォルダーに追加することです。

一部の資格情報ストアでは、アプリケーション、ホスト、またはプロキシレベルで設定を構成する必要があります。これらの設定は、Orchestrator の対応する設定と同じです。これらの設定は、プロキシの appsettings.Production.json ファイルで指定する必要があります。

CyberArk

appsettings.Production.json ファイルの Appsettings パラメーターの下に、CLIPasswordSDKExePathUsePowerShellCLIAdditionalAllowedCharacters などのホスト レベルの設定を追加する必要があります。

{
// ...
  "AppSettings": {
    "Plugins.SecureStores.CyberArk.CLIPasswordSDKExePath": "D:\\PathName\\CLIPasswordSDK.exe",
    // ...
  }
  // ...
}
{
// ...
  "AppSettings": {
    "Plugins.SecureStores.CyberArk.CLIPasswordSDKExePath": "D:\\PathName\\CLIPasswordSDK.exe",
    // ...
  }
  // ...
}

CyberArk CCP

Credentials Proxy は、読み込まれたユーザー プロファイルを持たないサービス アカウントで実行されます。既定では、読み込まれたユーザー プロファイルを必要とするキー ストアを使用しますが、これはサービス アカウントでは使用できません。したがって、CyberArk CCP クライアント証明書の秘密キーの読み込みに失敗し、CyberArk CCP による資格情報の取得が失敗します。このコンテキストで証明書を正しく読み込むには、以下を追加する必要がありますappsettings.Production.json

{
// ...
  "AppSettings": {
    "Plugins.SecureStores.CyberArkCCP.KeyStorageFlags": "MachineKeySet",
    // ...
  }
  // ...
}
{
// ...
  "AppSettings": {
    "Plugins.SecureStores.CyberArkCCP.KeyStorageFlags": "MachineKeySet",
    // ...
  }
  // ...
}

HashiCorp Vault

Two kinds of settings control the HashiCorp Vault and HashiCorp Vault (read only) credential stores:

  • Host-level settings govern plugin behavior for the whole proxy. You add them under AppSettings in the appsettings.Production.json file, prefixed with the store name. They apply to both proxy types.
  • Context parameters describe one Vault connection. A disconnected proxy reads them from the SecureStoreConfigurations section of the same file, as shown in the Configuration samples section. A connected proxy receives them from Orchestrator instead.

For what each Context parameter means, and for how SecretsEngineMountPath and DataPath resolve to the path of an individual secret, see HashiCorp Vault in Managing credential stores. Each JSON key is the field label from that page without the spaces, except for LdapUseDynamicCredentials, which is (Ldap) Use Dynamic Credentials, and KerberosSPN, which is Kerberos fully qualified SPN.

Host-level settings

Each store reads only its own prefix — Plugins.SecureStores.HashiCorp Vault. or Plugins.SecureStores.HashiCorp Vault (read only). — so to configure both stores, add each setting twice.

設定既定 (Default)説明
KerberosEnabledfalseMakes the KerberosUserPassword and KerberosDefaultCredentials authentication types available. Kerberos is unavailable when the proxy runs from the Docker image, whatever this setting says.
ForwardToActiveNodefalseAdds the X-Vault-Forward: active-node header to every request, so that a performance standby node forwards it to the active node. Vault Enterprise only.
ClientCacheDurationSeconds600How long an authenticated Vault client stays cached between operations.
MaxRetries5How many times the plugin retries a Vault request that returns HTTP 403, 412, 429, 500, or 503.
RetryDelayMilliseconds3000Delay between retries. With the default values, a permission error takes about 15 seconds to surface.

Kerberos 認証プロトコルを有効化し、HashiCorp Vault のノード転送をアクティブ化するには、appsettings.Production.json ファイルに次のパラメーターを追加します。

{
// ...
  "AppSettings": {
    "Plugins.SecureStores.HashiCorp Vault.KerberosEnabled": "true", // Optional, for Kerberos enablement
    "Plugins.SecureStores.HashiCorp Vault.ForwardToActiveNode": "true", // Optional, for forwarding to active node
    // ...
  }
  // ...
}
{
// ...
  "AppSettings": {
    "Plugins.SecureStores.HashiCorp Vault.KerberosEnabled": "true", // Optional, for Kerberos enablement
    "Plugins.SecureStores.HashiCorp Vault.ForwardToActiveNode": "true", // Optional, for forwarding to active node
    // ...
  }
  // ...
}

If the proxy reaches Vault through a forward proxy, configure it with the following settings:

  • HttpProxy.Outbound.Enabled
  • HttpProxy.Outbound.Address
  • HttpProxy.Outbound.Username
  • HttpProxy.Outbound.Password

These are not prefixed with a store name, and they apply to every credential store plugin loaded by the proxy.

HashiCorp Vault (読み取り専用)

The read-only store takes the same Context parameters and the same host-level settings as the read-write store, with two differences:

Kerberos 認証プロトコルを有効化し、HashiCorp Vault (読み取り専用) のノード転送をアクティブ化するには、appsettings.Production.json ファイルに次のパラメーターを追加します。

{
// ...
  "AppSettings": {
    "Plugins.SecureStores.HashiCorp Vault (read only).KerberosEnabled": "true", // Optional, for Kerberos enablement
    "Plugins.SecureStores.HashiCorp Vault (read only).ForwardToActiveNode": "true", // Optional, for forwarding to active node
    // ...
  }
  // ...
}
{
// ...
  "AppSettings": {
    "Plugins.SecureStores.HashiCorp Vault (read only).KerberosEnabled": "true", // Optional, for Kerberos enablement
    "Plugins.SecureStores.HashiCorp Vault (read only).ForwardToActiveNode": "true", // Optional, for forwarding to active node
    // ...
  }
  // ...
}

非接続のプロキシのみ

この種類のプロキシは Orchestrator から完全に分離されているため、資格情報コンテナーに関する情報をローカルの設定ファイル appsettings.Production.json で指定する必要があります。ファイルは、 C:\Program Files\UiPath\OrchestratorCredentialsProxy\appsettings.Production.jsonにあります。

上記のファイルの [AppSettings - SecureStoreConfigurations] セクションで、以下のフィールドを編集する必要があります。

  • Key - 設定の識別子キーです。
  • Type - appsettings.jsonPlugins.SecureStores パラメーターを使用して設定された .dll ファイルで識別される資格情報コンテナーの種類です (以下のサンプルを参照)。
  • Context - Secure Store の実装に関連する接続情報です。
    重要:

    設定ファイルを編集したら、IIS からサービスを再起動する必要があります。

設定のサンプル

非接続のプロキシを起動するには、以下のサンプルを appsettings.Production.json 設定ファイルに追加する必要があります。そうしないとサービスは起動されません。

資格情報ストアの種類に基づいて適切なサンプルを選択するか、このページの最後のサンプルを使用して複数の資格情報ストアを追加します。

上記のファイルの [AppSettings - SecureStoreConfigurations] セクションで、以下のフィールドを編集する必要があります。

  • Key - 設定の識別子キーです。
  • Type - appsettings.jsonPlugins.SecureStores パラメーターを使用して設定された .dll ファイルで識別される資格情報コンテナーの種類です (以下のサンプルを参照)。
  • Context - Secure Store の実装に関連する接続情報です。
    重要:

    設定ファイルを編集したら、IIS からサービスを再起動する必要があります。

注:

appsettings.Production.json ファイルに変更を加える前に、必ず元のファイルのバックアップを作成してください。こうしておけば、設定中に問題が発生した場合に、簡単に初期設定を復元したり、変更箇所を比較したりできます。

AWS Secrets Manager/AWS Secrets Manager (読み取り専用)
...
"SecureStoreConfigurations": [
      {
        "Key": "<MyAwsStore>",
        "Type": "AWS Secrets Manager" / "AWS Secrets Manager (read only)",
        "Context": {
          "UseDefaultCredentials": "true",
          "AccessKey": "<AccessKey>",
          "SecretKey": "<SecretKey>",
          "Region": "<SelectedRegion>"
        }
      },
    ]
...
...
"SecureStoreConfigurations": [
      {
        "Key": "<MyAwsStore>",
        "Type": "AWS Secrets Manager" / "AWS Secrets Manager (read only)",
        "Context": {
          "UseDefaultCredentials": "true",
          "AccessKey": "<AccessKey>",
          "SecretKey": "<SecretKey>",
          "Region": "<SelectedRegion>"
        }
      },
    ]
...
Azure Key Vault (読み取り専用)
...
"SecureStoreConfigurations": [
      {
        "Key": "<MyAzureStore>",
        "Type": "AzureKeyVault (read only)",
        "Context": {
          "KeyVaultUri": "<KeyVaultUri>",
          "DirectoryId": "<DirectoryId>",
          "ClientId": "<ClientId>",
          "ClientSecret": "<ClientSecret>"
        }
      },
    ]
...
...
"SecureStoreConfigurations": [
      {
        "Key": "<MyAzureStore>",
        "Type": "AzureKeyVault (read only)",
        "Context": {
          "KeyVaultUri": "<KeyVaultUri>",
          "DirectoryId": "<DirectoryId>",
          "ClientId": "<ClientId>",
          "ClientSecret": "<ClientSecret>"
        }
      },
    ]
...
重要:

Azure Key Vault (読み取り/書き込み) はサポートされていません。

BeyondTrust Password Safe - Managed Accounts
...
"SecureStoreConfigurations": [
      {
        "Key": "<MyBeyondTrustManagedAccountsSafe>",
        "Type": "BeyondTrust Password Safe - Managed Accounts",
        "Context": {
          "Hostname": "<HostName>",
          "APIRegistrationKey": "<ApiRegistrationKey>",
          "APIRunAsUsername": "<Username>",
          "DefaultManagedSystemName": "", // can be empty or a string
          "SystemAccountDelimiter": "/", // default account delimiter is "/", but it can be changed
          "ManagedAccountType": "<ManagedAccountType>" // expected value is one of "system", "domainlinked", "database", "cloud", "application"
        }
      },
    ]
...
...
"SecureStoreConfigurations": [
      {
        "Key": "<MyBeyondTrustManagedAccountsSafe>",
        "Type": "BeyondTrust Password Safe - Managed Accounts",
        "Context": {
          "Hostname": "<HostName>",
          "APIRegistrationKey": "<ApiRegistrationKey>",
          "APIRunAsUsername": "<Username>",
          "DefaultManagedSystemName": "", // can be empty or a string
          "SystemAccountDelimiter": "/", // default account delimiter is "/", but it can be changed
          "ManagedAccountType": "<ManagedAccountType>" // expected value is one of "system", "domainlinked", "database", "cloud", "application"
        }
      },
    ]
...
BeyondTrust Password Safe - Team Passwords
...
"SecureStoreConfigurations": [
      {
        "Key": "<MyBeyondTrustTeamPasswordSafe>",
        "Type": "BeyondTrust Password Safe - Team Passwords",
        "Context": {
          "Hostname": "<HostName>",
          "APIRegistrationKey": "<ApiRegistrationKey>",
          "APIRunAsUsername": "<Username>",
          "FolderPathPrefix" : "/", // default delimiter is "/", but it can be changed
          "FolderPasswordDelimiter" : "/" // default delimiter is "/", but it can be changed
        }
      },
    ]
...
...
"SecureStoreConfigurations": [
      {
        "Key": "<MyBeyondTrustTeamPasswordSafe>",
        "Type": "BeyondTrust Password Safe - Team Passwords",
        "Context": {
          "Hostname": "<HostName>",
          "APIRegistrationKey": "<ApiRegistrationKey>",
          "APIRunAsUsername": "<Username>",
          "FolderPathPrefix" : "/", // default delimiter is "/", but it can be changed
          "FolderPasswordDelimiter" : "/" // default delimiter is "/", but it can be changed
        }
      },
    ]
...
CyberArk - AIM
...
"SecureStoreConfigurations": [
      {
        "Key": "<MyCyberArk>",
        "Type": "CyberArk",
        "Context": {
          "ApplicationId": "<App_MyCyberArk>",
          "Safe": "<Passwords>",
          "Folder": "<MyFolder>"
        }
      },
    ]
...
...
"SecureStoreConfigurations": [
      {
        "Key": "<MyCyberArk>",
        "Type": "CyberArk",
        "Context": {
          "ApplicationId": "<App_MyCyberArk>",
          "Safe": "<Passwords>",
          "Folder": "<MyFolder>"
        }
      },
    ]
...

CLIPasswordSDKExePathUsePowerShellCLIAdditionalAllowedCharacters などのホスト レベルの設定は、Orchestrator の場合と同様に Appsettings パラメーターの下に配置する必要があります。

{
// ...
  "AppSettings": {
    "Plugins.SecureStores.CyberArk.CLIPasswordSDKExePath": "D:\\<MyPath>\\CLIPasswordSDK.exe",
    "Plugins.SecureStores": "UiPath.Orchestrator.CyberArk.dll;UiPath.Orchestrator.AzureKeyVault.SecureStore.dll;UiPath.Orchestrator.SecureStore.CyberArkCCP.dll;UiPath.Orchestrator.SecureStore.CyberArkConjur.dll;UiPath.Orchestrator.SecureStore.HashiCorpVault.dll;UiPath.Orchestrator.SecureStore.ThycoticSecretServer.dll;UiPath.Orchestrator.SecureStore.BeyondTrust.dll;UiPath.Orchestrator.SecureStore.AWSSecretsManager.dll;UiPath.Orchestrator.SecureStore.GoogleSecretManager.dll;UiPath.Orchestrator.SecureStore.DelineaSecretServer.dll",
    "CredentialsProxyType": "Disconnected"
    // ...
  }
  // ...
{
// ...
  "AppSettings": {
    "Plugins.SecureStores.CyberArk.CLIPasswordSDKExePath": "D:\\<MyPath>\\CLIPasswordSDK.exe",
    "Plugins.SecureStores": "UiPath.Orchestrator.CyberArk.dll;UiPath.Orchestrator.AzureKeyVault.SecureStore.dll;UiPath.Orchestrator.SecureStore.CyberArkCCP.dll;UiPath.Orchestrator.SecureStore.CyberArkConjur.dll;UiPath.Orchestrator.SecureStore.HashiCorpVault.dll;UiPath.Orchestrator.SecureStore.ThycoticSecretServer.dll;UiPath.Orchestrator.SecureStore.BeyondTrust.dll;UiPath.Orchestrator.SecureStore.AWSSecretsManager.dll;UiPath.Orchestrator.SecureStore.GoogleSecretManager.dll;UiPath.Orchestrator.SecureStore.DelineaSecretServer.dll",
    "CredentialsProxyType": "Disconnected"
    // ...
  }
  // ...
CyberArk - CCP
...
"SecureStoreConfigurations": [
      {
        "Key": "<MyCyberArkCCPStore>",
        "Type": "CyberArkCCP",
        "Context": {
          "ApplicationId": "<ApplicationId>",
          "Safe": "<CyberArkSafe>",
          "Folder": "<CyberArkFolder>",
          "WebServiceUrl": "<CentralCredentialProviderUrl>",
          "WebServiceName": "<WebServiceName>",
          "SerializedClientCertificate": "<ClientCertificate>", // must be the ".pfx" file's content as base64 string
          "ClientCertificatePassword": "<ClientCertificatePassword>",
          "SerializedRootCA": "<someServerRootCA>" // must be the ".crt" or ".cer" file's content as base64 string
        }
      },
    ]
...
...
"SecureStoreConfigurations": [
      {
        "Key": "<MyCyberArkCCPStore>",
        "Type": "CyberArkCCP",
        "Context": {
          "ApplicationId": "<ApplicationId>",
          "Safe": "<CyberArkSafe>",
          "Folder": "<CyberArkFolder>",
          "WebServiceUrl": "<CentralCredentialProviderUrl>",
          "WebServiceName": "<WebServiceName>",
          "SerializedClientCertificate": "<ClientCertificate>", // must be the ".pfx" file's content as base64 string
          "ClientCertificatePassword": "<ClientCertificatePassword>",
          "SerializedRootCA": "<someServerRootCA>" // must be the ".crt" or ".cer" file's content as base64 string
        }
      },
    ]
...

IIS の設定によっては、以下のように追加の KeyStorageFlags を設定する必要がある場合があります。

"AppSettings": {
...
"Plugins.SecureStores.CyberArkCCP.KeyStorageFlags": "MachineKeySet",
...
}
"AppSettings": {
...
"Plugins.SecureStores.CyberArkCCP.KeyStorageFlags": "MachineKeySet",
...
}

PFX、CRT、または CER のファイルは、次の方法で base64 文字列に変換できます。

$fileContentBytes = get-content 'C:\path\to\the.pfx' -Encoding Byte
[System.Convert]::ToBase64String($fileContentBytes) | Out-File 'C:\path\to\the.txt'
$fileContentBytes = get-content 'C:\path\to\the.pfx' -Encoding Byte
[System.Convert]::ToBase64String($fileContentBytes) | Out-File 'C:\path\to\the.txt'
CyberArk® Conjur Cloud (読み取り専用)
...
"SecureStoreConfigurations": [
      {
        "Key": "MyCyberArkConjur",
        "Type": "CyberArk Conjur Cloud (read only)",
        "Context": {
          "ServiceUrl": "https://{myCyberArkConjurUrl}/",
          "LoginName": "{myLoginName}",
          "ApiKey": "{myApiKey}",
          "VariableIdPrefix": "{myPrefix}"
        }
      },
    ]
...
...
"SecureStoreConfigurations": [
      {
        "Key": "MyCyberArkConjur",
        "Type": "CyberArk Conjur Cloud (read only)",
        "Context": {
          "ServiceUrl": "https://{myCyberArkConjurUrl}/",
          "LoginName": "{myLoginName}",
          "ApiKey": "{myApiKey}",
          "VariableIdPrefix": "{myPrefix}"
        }
      },
    ]
...
CyberArk® Conjur (読み取り専用)
...
"SecureStoreConfigurations": [
  {
    "Key": "MyCyberArkConjur",
    "Type": "CyberArk Conjur (read only)",
    "Context": {
      "ApplianceUrl": "https://{company}.secretsmgr.cyberark.cloud/api",
      "Account": "{myAccount}",
      "AuthenticationType": "{Jwt|ApiKey}",
      "JWT":  {
          "JwtServiceId": "{myJwtServiceId}",
          "IdentityProviderUrl": "{myIdentityProviderUrl}",
          "ClientId": "{myClientId}",
          "ClientSecret": "{myClientSecret}",
          "Scope": "{myScope}"
      },
      "ApiKey": {
          "LoginName": "{myLoginName}",
          "Key": "{myApiKey}"
      },
      "HostId": "{myHostId}",
      "VariableIdPrefix": "{myPrefix}"
    }
  },
]
...
...
"SecureStoreConfigurations": [
  {
    "Key": "MyCyberArkConjur",
    "Type": "CyberArk Conjur (read only)",
    "Context": {
      "ApplianceUrl": "https://{company}.secretsmgr.cyberark.cloud/api",
      "Account": "{myAccount}",
      "AuthenticationType": "{Jwt|ApiKey}",
      "JWT":  {
          "JwtServiceId": "{myJwtServiceId}",
          "IdentityProviderUrl": "{myIdentityProviderUrl}",
          "ClientId": "{myClientId}",
          "ClientSecret": "{myClientSecret}",
          "Scope": "{myScope}"
      },
      "ApiKey": {
          "LoginName": "{myLoginName}",
          "Key": "{myApiKey}"
      },
      "HostId": "{myHostId}",
      "VariableIdPrefix": "{myPrefix}"
    }
  },
]
...
Delinea Secret Server (読み取り専用)
注:

Delinea Secret Server (読み取り専用) には、Orchestrator Credentials Proxy 2.2.2 以降が必要です。プラグイン UiPath.Orchestrator.SecureStore.DelineaSecretServer.dllはインストール キットに同梱されており、既定で Plugins.SecureStores に表示されているため、手動で追加する必要はありません。

これは読み取り専用の資格情報ストアです。プロキシはそこからアセット値とロボットの資格情報を取得できますが、シークレットを作成、更新、削除することはできません。

...
"SecureStoreConfigurations": [
      {
        "Key": "<MyDelineaServer>",
        "Type": "Delinea Secret Server (read only)",
        "Context": {
          "PlatformServerUrl": "<PlatformServerUrl>",
          "SecretServerUrl": "<SecretServerUrl>",
          "RuleName": "<Rule>",
          "RuleKey": "<Key>",
          "UsernameField": "<Username>",
          "PasswordField": "<Password>"
        }
      },
    ]
...
...
"SecureStoreConfigurations": [
      {
        "Key": "<MyDelineaServer>",
        "Type": "Delinea Secret Server (read only)",
        "Context": {
          "PlatformServerUrl": "<PlatformServerUrl>",
          "SecretServerUrl": "<SecretServerUrl>",
          "RuleName": "<Rule>",
          "RuleKey": "<Key>",
          "UsernameField": "<Username>",
          "PasswordField": "<Password>"
        }
      },
    ]
...

Contextフィールドは次のとおりです。

  • PlatformServerUrl - (必須) Delinea プラットフォームの URL です (例: https://<tenant>.delinea.app)。
  • SecretServerUrl - (必須) シークレット サーバーの URL です (例: https://<tenant>.secretservercloud.eu)。これを取得するには、Delinea テナントの [Secret Server connection ] ページに移動します。
  • RuleName - (必須) Delinea で作成した SDK クライアントのオンボーディング ルールの名前です。
  • RuleKey - (任意) ルールのオンボーディング キーです。Delinea で [オンボーディング キーが必要] が有効化されていない場合は、空のままにします。このフィールドは任意ですが、セキュリティを向上させるために設定することをお勧めします。
  • UsernameField - (必須) ユーザー名の読み込み元のシー クレット テンプレート フィールドのスラグ名です (例: username)。
  • PasswordField - (必須) パスワードの読み込み元のシー クレット テンプレート フィールドのスラグ名です (例: password)。
注:

Delineaの継続的なプラットフォーム移行中は、 PlatformServerUrlSecretServerUrl の両方が必要です。プロキシは PlatformServerUrl を使用して Delinea プラットフォームがアクセス可能であることを確認し、シークレット自体を取得する SecretServerUrl します。

シークレット テンプレート フィールドのスラッグ名は、[管理] > [シークレット テンプレート] > [テンプレート> フィールド] で確認できます。UsernameFieldPasswordField の値は大文字と小文字を区別しません。

このストアにリンクされているアセットとロボットの資格情報では、Delinea Secret Server の数値 のシークレット ID外部名として使用する必要があります。文字列名はサポートされていません。

前提条件と Delinea 側の設定 ( SDK クライアント管理 の有効化、オンボーディング ルールの作成など) については、「 資格情報ストアを連携する 」ページの「 Delinea Secret Server との連携 」のセクションをご覧ください。

HashiCorp Vault/HashiCorp Vault (読み取り専用)

The following sample uses AppRole authentication against a KeyValueV2 secrets engine. For what each parameter means, which ones your authentication method and secrets engine need, and how SecretsEngineMountPath and DataPath resolve to the path of an individual secret, see HashiCorp Vault in Managing credential stores.

...
"SecureStoreConfigurations": [
      {
        "Key": "<MyHashiCorp>",
        "Type": "HashiCorp Vault", // or "HashiCorp Vault (read only)"
        "Context": {
          "VaultUri": "https://vault.example.com:8200",
          "AuthenticationType": "AppRole", // or "UsernamePassword", "Ldap", "Token"
          "AuthenticationMountPath": "", // optional, defaults to the name of the authentication method
          "RoleId": "<RoleId>",
          "SecretId": "<SecretId>",
          "Username": "", // with "UsernamePassword" or "Ldap"
          "Password": "", // with "UsernamePassword" or "Ldap"
          "Token": "", // with "Token"
          "SecretsEngine": "KeyValueV2", // or "KeyValueV1"; read-only also accepts "ActiveDirectory", "OpenLDAP", "LDAP"
          "SecretsEngineMountPath": "uipath/kv", // the mount only - no "data" segment, no secret path
          "DataPath": "orchestrator/assets", // the prefix inside the mount - no mount, no "data" segment
          "Namespace": "", // Vault Enterprise only
          "LdapUseDynamicCredentials": "false", // with the "LDAP" secrets engine
          "KerberosSPN": "" // with Kerberos authentication
        }
      }
    ]
...
...
"SecureStoreConfigurations": [
      {
        "Key": "<MyHashiCorp>",
        "Type": "HashiCorp Vault", // or "HashiCorp Vault (read only)"
        "Context": {
          "VaultUri": "https://vault.example.com:8200",
          "AuthenticationType": "AppRole", // or "UsernamePassword", "Ldap", "Token"
          "AuthenticationMountPath": "", // optional, defaults to the name of the authentication method
          "RoleId": "<RoleId>",
          "SecretId": "<SecretId>",
          "Username": "", // with "UsernamePassword" or "Ldap"
          "Password": "", // with "UsernamePassword" or "Ldap"
          "Token": "", // with "Token"
          "SecretsEngine": "KeyValueV2", // or "KeyValueV1"; read-only also accepts "ActiveDirectory", "OpenLDAP", "LDAP"
          "SecretsEngineMountPath": "uipath/kv", // the mount only - no "data" segment, no secret path
          "DataPath": "orchestrator/assets", // the prefix inside the mount - no mount, no "data" segment
          "Namespace": "", // Vault Enterprise only
          "LdapUseDynamicCredentials": "false", // with the "LDAP" secrets engine
          "KerberosSPN": "" // with Kerberos authentication
        }
      }
    ]
...

Host-level settings go under the AppSettings parameter, the same way they do in Orchestrator. Each store reads only its own prefix, so to configure both stores add each setting twice. For the full list of settings and their defaults, see Host-level settings.

{
// ...
  "AppSettings": {
    // Optional, for Kerberos enablement
    "Plugins.SecureStores.HashiCorp Vault.KerberosEnabled": "true",
    "Plugins.SecureStores.HashiCorp Vault (read only).KerberosEnabled": "true",
    // Optional, for forwarding to the active node
    "Plugins.SecureStores.HashiCorp Vault.ForwardToActiveNode": "true",
    "Plugins.SecureStores.HashiCorp Vault (read only).ForwardToActiveNode": "true"
    // ...
  }
  // ...
}
{
// ...
  "AppSettings": {
    // Optional, for Kerberos enablement
    "Plugins.SecureStores.HashiCorp Vault.KerberosEnabled": "true",
    "Plugins.SecureStores.HashiCorp Vault (read only).KerberosEnabled": "true",
    // Optional, for forwarding to the active node
    "Plugins.SecureStores.HashiCorp Vault.ForwardToActiveNode": "true",
    "Plugins.SecureStores.HashiCorp Vault (read only).ForwardToActiveNode": "true"
    // ...
  }
  // ...
}
Thycotic Secret Server
重要:

Thycotic Secret Server ストアは、上記のセクションで説明されている Delinea Secret Server (読み取り専用) ストアによって引き継がれます。両方のストアは、同じ基盤となる SDK と同じルールベースのオンボーディング メカニズムを共有しているため、 Context フィールドはほぼ同じです。既存の Thycotic 資格情報ストアを新しい Delinea ストアに移行することを強くお勧めします。

...
"SecureStoreConfigurations": [
      {
        "Key": "<MyThicoticServer>",
        "Type": "Thycotic Secret Server",
        "Context": {
          "SecretServerUrl": "<ServerUrl>",
          "RuleName": "<Rule>",
          "RuleKey": "<Key>",
          "UsernameField": "<Username>",
          "PasswordField": "<Password>"
        }
      },
    ]
...
...
"SecureStoreConfigurations": [
      {
        "Key": "<MyThicoticServer>",
        "Type": "Thycotic Secret Server",
        "Context": {
          "SecretServerUrl": "<ServerUrl>",
          "RuleName": "<Rule>",
          "RuleKey": "<Key>",
          "UsernameField": "<Username>",
          "PasswordField": "<Password>"
        }
      },
    ]
...
Google Secret Manager
...
"SecureStoreConfigurations": [
      {
        "Key": "<GoogleSecretManager>",
        "Type": "Google Secret Manager",
        "Context": {
          "ProjectId": "<ProjectId>",
          "ServiceAccountKeyJson": "<ServiceAccountKeyJson>",
        }
      },
    ]
...
...
"SecureStoreConfigurations": [
      {
        "Key": "<GoogleSecretManager>",
        "Type": "Google Secret Manager",
        "Context": {
          "ProjectId": "<ProjectId>",
          "ServiceAccountKeyJson": "<ServiceAccountKeyJson>",
        }
      },
    ]
...
Google Secret Manager (読み取り専用)
...
"SecureStoreConfigurations": [
      {
        "Key": "<GoogleSecretManager>",
        "Type": "Google Secret Manager (read only)",
        "Context": {
          "ProjectId": "<ProjectId>",
          "ServiceAccountKeyJson": "<ServiceAccountKeyJson>",
        }
      },
    ]
...
...
"SecureStoreConfigurations": [
      {
        "Key": "<GoogleSecretManager>",
        "Type": "Google Secret Manager (read only)",
        "Context": {
          "ProjectId": "<ProjectId>",
          "ServiceAccountKeyJson": "<ServiceAccountKeyJson>",
        }
      },
    ]
...
複数の資格情報ストア

複数の資格情報ストアを使用する場合は、以下のように並べて追加できます。

{
...
  "AppSettings": {
  ...
    "SecureStoreConfigurations": [
      {
        "Key": "<SecureStoreKey1>",
        "Type": "AzureKeyVault (read only)",
        "Context": {
          "KeyVaultUri": "<Uri>",
          "DirectoryId": "<DirectoryId>",
          "ClientId": "<ClientId>",
          "ClientSecret": "<ClientSecret>"
        }
      },
      {
        "Key": "<SecureStoreKey2>",
        "Type": "BeyondTrust Password Safe - Managed Accounts",
        "Context": {
          "Hostname": "<Host>",
          "APIRegistrationKey": "<ApiKey>",
          "APIRunAsUsername": "<ApiUsername>",
          "DefaultManagedSystemName": "",
          "SystemAccountDelimiter": "/",
          "ManagedAccountType": "system"
        }
      }
    ]
  ...
  }
}
{
...
  "AppSettings": {
  ...
    "SecureStoreConfigurations": [
      {
        "Key": "<SecureStoreKey1>",
        "Type": "AzureKeyVault (read only)",
        "Context": {
          "KeyVaultUri": "<Uri>",
          "DirectoryId": "<DirectoryId>",
          "ClientId": "<ClientId>",
          "ClientSecret": "<ClientSecret>"
        }
      },
      {
        "Key": "<SecureStoreKey2>",
        "Type": "BeyondTrust Password Safe - Managed Accounts",
        "Context": {
          "Hostname": "<Host>",
          "APIRegistrationKey": "<ApiKey>",
          "APIRunAsUsername": "<ApiUsername>",
          "DefaultManagedSystemName": "",
          "SystemAccountDelimiter": "/",
          "ManagedAccountType": "system"
        }
      }
    ]
  ...
  }
}

検証

重要:

これは、非接続の資格情報プロキシにのみ適用されます。

プロキシは、検出した種類が Disconnected の場合、起動時に設定を検証します。

プロキシが実行する検証手順の一部を以下に示します。

  • プロキシにより、上記の「設定」セクションで詳しく説明されている設定が、appsettings.Production.json に想定どおりに含まれていることが確認されます。
  • プロキシにより、SecureStoreConfigurations に重複する Key パラメーターが含まれないように、つまり、appsettings.Production.json ファイルで設定された資格情報ストアが一意であることが確認されます。
  • SecureStoreConfigurations パラメーターは、複数の値を列挙して設定できます。資格情報ストアを、同じ種類のものであっても、必要な数だけ追加できます。たとえば、Key フィールドが一意である限り、複数の Azure Key Vault (読み取り専用) インスタンスを設定できます。
  • プロキシによって、すべての Type 値が有効であることが確認されます。
  • 各 Secure Store の実装に基づいて、コンテナーに正常に到達できることがプロキシによって確認されます。

ログ

Orchestrator Credentials Proxy のログはローカルの C:\Program Files\UiPath\OrchestratorCredentialsProxy フォルダーに保存されます (プロキシのアプリケーション プールにそのパスへの書き込み権限がある場合)。これらは IIS で設定されます。

そのフォルダーへの書き込みアクセス許可を与えない場合は、appsettings.Production.jsonNLog.targets.logfile.fileName パラメーターを使用して、任意の相対パスまたは絶対パスを指定します。

Windows マシンでは、プロキシは Windows イベント ビューアーにもログを保存します。

セキュリティに関する考慮事項

  • Orchestrator only allows secure (HTTPS) URLs for the proxy. The certificate requirements depend on the proxy type:
    • Connected proxy - the HTTPS certificate must be valid for the Public URL and signed by a certificate authority that Orchestrator can validate, meaning a widely recognized public certificate provider. Self-signed certificates are not supported.
    • Disconnected proxy - communication stays inside your own infrastructure, so certificates signed by your internal certificate authority, as well as self-signed certificates, are supported, as long as the machines running your robots trust them.
  • Orchestrator は、Orchestrator Credentials Proxy によって生成されたクライアント シークレットで検証されます。このクライアント シークレットは、Orchestrator Credentials Proxy がインストールされているマシンの構成ファイルに保存され、Orchestrator によって暗号化され、データベースに保存されます。
  • Orchestrator で資格情報ストア プロキシを編集してその URL を変更する場合、クライアント シークレットも入力する必要があります。
  • Orchestrator Credentials Proxy 2.0.0 以降のアクションは、Windows イベント ビューアーに記録されます。
  • バイナリは Windows マシンで署名される必要があります。
  • Docker イメージは署名されている必要があります。

ロード バランサーで Orchestrator Credentials Proxy を使用する

プロキシをロード バランサーと組み合わせて使用する場合は、すべてのノードで同じ構成を維持するようにしてください。

ノード間で同一である必要がある要素

  • プロキシ インストーラーのバージョン。たとえば、バージョン 1.0.0 を使用する場合は、すべてのロード バランサー ノードでも 1.0.0 を使用する必要があります。
  • アプリケーション構成ファイルの設定。ほとんどの場合、appsettings.jsonappsettings.Production.json です。appsettings.Production.json はインストールごとに一意であるため、一貫性を確保するには、手動で各ノードに追加する必要があります。
  • path/plugins に追加された資格情報ストア プラグイン。UiPath がサポートするプラグインはすべてすでにこのフォルダーにあるため、注意が必要なのは追加するカスタム プラグインのみです。

考慮すべき重要事項

  • プロキシのインストール用に提供されている Docker イメージの構成に変更を加える場合は、代わりにカスタム Docker イメージを作成することを強くお勧めします。次に、このカスタム イメージを使用して、すべてのノードにプロキシをデプロイする必要があります。
  • 一部の環境変数は、ランタイムに影響を与える可能性があります。たとえば、appsettings.json 構成値をオーバーライドする環境変数や、.NET 環境に影響を与える環境変数などです。
  • 専用の非認証エンドポイント https://{YourOrchestratorCredentialsProxyURL}/api/v1/Health を使用して、Orchestrator Credentials Proxy がまだ実行中かどうかを確認できます。

Orchestrator Credentials Proxy の証明書を更新する

シングルノードのインストールの場合は、次の手順で SSL 証明書を更新します。

  1. 新しい証明書を、ローカル マシンの証明書コンソール (certlm.msc) の [証明書] の下にある [個人] フォルダーにインポートします。
  2. IIS 管理コンソールで、[サイト] を展開して [UiPath Orchestrator Credential Proxy] を選択します。
  3. 右側のパネルから [バインド...] を選択します。
  4. [バインド...] ビューから既定のhttps レコードを選択し、[選択...] ボタンを使用して証明書を選択します。
  5. [証明書の選択] ポップアップ ウィンドウで、新しく追加した証明書を選択します。
  6. セットアップが完了するまで [OK] を選択します。
    注:

    マルチノードのインストールの場合は、必ずすべてのマシンで証明書を更新してください。

ロード バランサーを使用しているインストールの証明書を更新するには、上記と同じ手順を使用します。Orchestrator Credentials Proxy はステートレスであるため、証明書を更新する際はロード バランサーからノードを削除してください。

キーのローテーション

ダウンタイムを伴うキーのローテーション

注:

この操作では、実行中の Orchestrator Credentials Proxy を停止して再起動する必要があります。これは、Orchestrator によって実行されるライブ要求に影響を与える可能性があります。

  1. Orchestrator Credentials Proxy の標準に従って新しいシークレット キーを生成します。
  2. Orchestrator Credentials Proxy を停止します。
  3. appsettings.Production.json ファイルを編集し、既存のキーを新しいキーで上書きします。
  4. Orchestrator Credentials Proxy を起動します。
  5. Orchestrator で Orchestrator Credentials Proxy に移動し、[Secret] フィールドを編集して新しいシークレットを指定します。

ダウンタイムを伴わないキーのローテーション

注:

この操作には、ロード バランサーを備えた Orchestrator Credentials Proxy と、2 つ以上の Orchestrator Credentials Proxy インスタンスが必要です。詳しくは、「 インストール 」をご覧ください。

  1. Orchestrator Credentials Proxy の標準に従って新しいシークレット キーを生成します。
  2. 新しく生成されたキーを Credentials Proxy インスタンスに追加します。各インスタンスで以下の手順を実行します。
    1. Orchestrator Credentials Proxy インスタンスをロード バランサーから除外します。
    2. Orchestrator Credentials Proxy インスタンスを停止します。
    3. appsettings.Production.json ファイルを開きます。このファイルには次のようなコードが含まれています。
      {
          "Jwt": {
              "Keys": [
                  "{{OldKey}}"
              ],
      {
          "Jwt": {
              "Keys": [
                  "{{OldKey}}"
              ],
      
    4. 既存のキーを保持したまま、新しく生成されたキーを追加します。Keys パラメーターには、複数の値をコンマで区切って指定できます。
      {
          "Jwt": {
              "Keys": [
                  "{{OldKey}}",
                  "{{NewKey}}"
              ],
      {
          "Jwt": {
              "Keys": [
                  "{{OldKey}}",
                  "{{NewKey}}"
              ],
      
    5. Orchestrator Credentials Proxy を起動します。
    6. Orchestrator Credentials Proxy インスタンスをロード バランサーに戻します。
  3. Orchestrator で Orchestrator Credentials Proxy に移動し、[Secret] フィールドを編集して新しいシークレットを指定します。
  4. しばらくしてから、Credentials Proxy インスタンスから古いキーを取得します。各インスタンスで以下の手順を実行します。
    1. Orchestrator Credentials Proxy インスタンスをロード バランサーから除外します。
    2. Orchestrator Credentials Proxy インスタンスを停止します。
    3. appsettings.Production.json ファイルを開きます。このファイルには、前の手順で説明した次の 2 つのキーが含まれています。
      {
          "Jwt": {
              "Keys": [
                  "{{OldKey}}",
                  "{{NewKey}}"
              ],
      {
          "Jwt": {
              "Keys": [
                  "{{OldKey}}",
                  "{{NewKey}}"
              ],
      
    4. ファイルから古いキーを削除して次のようにします: { "Jwt": { "Keys": [ "{{NewKey}}" ],
    5. Orchestrator Credentials Proxy を起動します。
    6. Orchestrator Credentials Proxy インスタンスをロード バランサーに戻します。

このページは役に立ちましたか?

接続

ヘルプ リソース サポート

学習する UiPath アカデミー

質問する UiPath フォーラム

最新情報を取得