Credential rotation using a process automation tool
Techniques are described herein for rotating a credential using a process automation tool. A first process automation tool can use an application programming interface (API) call to request an updated credential from an external credential manager to replace an existing credential stored in an internal credential storage system. The first process automation tool can obtain the updated credential from an output of the API call. The first process automation tool can access the existing credential and replace the existing credential with the updated credential. Subsequently, a second process automation tool can access the internal credential storage system to obtain the updated credential. The second process automation tool can perform an authentication process to provide access to a protected computing resource.
1 . A computer-implemented method, comprising:
requesting, by a first process automation tool using an application programming interface (API) call and from an external credential manager, an updated credential to replace an existing credential stored in an internal credential storage system, wherein the first process automation tool comprises a scheduling parameter to automatically initiate the first process automation tool, wherein the scheduling parameter is defined based on a trigger condition corresponding to an expiration date of the existing credential;
obtaining, by the first process automation tool and from an output of the API call, the updated credential provided by the external credential manager;
accessing, by the first process automation tool, the existing credential stored in the internal credential storage system;
replacing, by the first process automation tool, the existing credential stored in the internal credential storage system with the updated credential;
subsequent to the first process automation tool replacing the existing credential stored in the internal credential storage system with the updated credential, accessing, by a second process automation tool, the internal credential storage system to obtain the updated credential, wherein the second process automation tool is a robotic process automation tool configured to perform an automated process involving access to a protected computing resource; and
performing, by the second process automation tool, an authentication process to access the protected computing resource as part of performing the automated process, wherein performing the automated process further comprises mimicking a human-computer interaction involving the protected computing resource.
2 . The computer-implemented method of claim 1 , wherein the API call comprises a non-user identifier identifying the second process automation tool for which to obtain the updated credential from the external credential manager.
3 . The computer-implemented method of claim 1 , wherein the internal credential storage system is part of an automation platform used to build and deploy a plurality of process automation tools comprising the first process automation tool and the second process automation tool.
4 . The computer-implemented method of claim 1 , wherein the first process automation tool is another robotic process automation tool configured to automatically perform a credential rotation process by which a current credential associated with the second process automation tool is continually updated.
5 . The computer-implemented method of claim 4 , further comprising:
receiving, by the robotic process automation tool, a non-user identifier as an input parameter;
locating, by the robotic process automation tool and using the non-user identifier, the existing credential in the internal credential storage system; and
subsequent to locating the existing credential, replacing, by the robotic process automation tool, the existing credential with the updated credential.
6 . The computer-implemented method of claim 1 , wherein the automated process comprises a predefined process having a series of tasks, and wherein performing at least one task of the series of tasks comprises handling data between the protected computing resource and at least one additional computing resource.
7 . The computer-implemented method of claim 1 , further comprising:
prior to the first process automation tool replacing the existing credential stored in the internal credential storage system with the updated credential, pausing an operation of another process automation tool configured to use the existing credential to perform one or more tasks; and
subsequent to the first process automation tool replacing the existing credential stored in the internal credential storage system with the updated credential, resuming the operation of the other process automation tool.
8 . A system, comprising:
one or more processors; and
one or more memories storing computer-executable instructions that, when executed by the one or more processors, causes the one or more processors to:
request, by a first process automation tool using an application programming interface (API) call and from an external credential manager, an updated credential to replace an existing credential stored in an internal credential storage system, wherein the first process automation tool comprises a scheduling parameter to automatically initiate the first process automation tool, wherein the scheduling parameter is defined based on a trigger condition corresponding to an expiration date of the existing credential;
obtain, by the first process automation tool and from an output of the API call, the updated credential provided by the external credential manager;
access, by the first process automation tool, the existing credential stored in the internal credential storage system;
replace, by the first process automation tool, the existing credential stored in the internal credential storage system with the updated credential;
subsequent to the first process automation tool replacing the existing credential stored in the internal credential storage system with the updated credential, access, by a second process automation tool, the internal credential storage system to obtain the updated credential, wherein the second process automation tool is a robotic process automation tool configured to perform an automated process involving access to a protected computing resource; and
perform, by the second process automation tool, an authentication process to access the protected computing resource as part of performing the automated process, wherein performing the automated process further comprises mimicking a human-computer interaction involving the protected computing resource.
9 . The system of claim 8 , wherein the API call comprises a non-user identifier identifying the second process automation tool for which to obtain the updated credential from the external credential manager.
10 . The system of claim 8 , wherein the internal credential storage system is part of an automation platform used to build and deploy a plurality of process automation tools comprising the first process automation tool and the second process automation tool.
11 . The system of claim 8 , wherein the first process automation tool is another robotic process automation tool configured to automatically perform a credential rotation process by which a current credential associated with the second process automation tool is continually updated.
12 . The system of claim 11 , wherein the computer-executable instructions are further executable to cause the one or more processors to:
receive, by the robotic process automation tool, a non-user identifier as an input parameter;
locate, by the robotic process automation tool and using the non-user identifier, the existing credential in the internal credential storage system; and
subsequent to locating the existing credential, replace, by the robotic process automation tool, the existing credential with the updated credential.
13 . The system of claim 8 , wherein the automated process comprises a predefined process having a series of tasks, and wherein performing at least one task of the series of tasks comprises handling data between the protected computing resource and at least one additional computing resource.
14 . The system of claim 8 , wherein the computer-executable instructions are further executable to cause the one or more processors to:
prior to the first process automation tool replacing the existing credential stored in the internal credential storage system with the updated credential, pause an operation of another process automation tool configured to use the existing credential to perform one or more tasks; and
subsequent to the first process automation tool replacing the existing credential stored in the internal credential storage system with the updated credential, resume the operation of the other process automation tool.
15 . A non-transitory computer-readable storage medium storing computer-executable instructions that, when executed with one or more processors of a computing device, causes the computing device to:
request, by a first process automation tool using an application programming interface (API) call and from an external credential manager, an updated credential to replace an existing credential stored in an internal credential storage system, wherein the first process automation tool comprises a scheduling parameter to automatically initiate the first process automation tool, wherein the scheduling parameter is defined based on a trigger condition corresponding to an expiration date of the existing credential;
obtain, by the first process automation tool and from an output of the API call, the updated credential provided by the external credential manager;
access, by the first process automation tool, the existing credential stored in the internal credential storage system;
replace, by the first process automation tool, the existing credential stored in the internal credential storage system with the updated credential;
subsequent to the first process automation tool replacing the existing credential stored in the internal credential storage system with the updated credential, access, by a second process automation tool, the internal credential storage system to obtain the updated credential, wherein the second process automation tool is a robotic process automation tool configured to perform an automated process involving access to a protected computing resource; and
perform, by the second process automation tool, an authentication process to access the protected computing resource as part of performing the automated process, wherein performing the automated process further comprises mimicking a human-computer interaction involving the protected computing resource.
16 . The non-transitory computer-readable storage medium of claim 15 , wherein the API call comprises a non-user identifier identifying the second process automation tool for which to obtain the updated credential from the external credential manager.
17 . The non-transitory computer-readable storage medium of claim 15 , wherein the internal credential storage system is part of an automation platform used to build and deploy a plurality of process automation tools comprising the first process automation tool and the second process automation tool.
18 . The non-transitory computer-readable storage medium of claim 15 , wherein the first process automation tool is another robotic process automation tool configured to automatically perform a credential rotation process by which a current credential associated with the second process automation tool is continually updated.
19 . The non-transitory computer-readable storage medium of claim 18 , wherein the computer-executable instructions are further executable to cause the computing device to:
receive, by the robotic process automation tool, a non-user identifier as an input parameter;
locate, by the robotic process automation tool and using the non-user identifier, the existing credential in the internal credential storage system; and
subsequent to locating the existing credential, replace, by the robotic process automation tool, the existing credential with the updated credential.
20 . The non-transitory computer-readable storage medium of claim 15 , wherein the computer-executable instructions are further executable to cause the computing device to:
prior to the first process automation tool replacing the existing credential stored in the internal credential storage system with the updated credential, pause an operation of another process automation tool configured to use the existing credential to perform one or more tasks; and
subsequent to the first process automation tool replacing the existing credential stored in the internal credential storage system with the updated credential, resume the operation of the other process automation tool.