JDBC credentials
Summarize
Summary of JDBC credentials
The JDBC credential type in ServiceNow manages access to Java Database Connectivity (JDBC) connections, primarily used in Discovery and Orchestration processes. It allows secure and organized management of database credentials, facilitating automated discovery and orchestration workflows involving JDBC-enabled systems.
Show less
Key Features
- Name: Assign a unique, descriptive name to identify the credential record clearly.
- Active: Enable or disable credentials to control their availability for use.
- User name: Specify the database user name, ensuring no leading or trailing spaces; for CIM discovery, this user must have the admin role.
- Password: Enter the associated password for the user name.
- Credential ID: Used when leveraging external credential stores; it uniquely identifies the credential in the external system and replaces user name and password fields when external storage is enabled.
- Credential alias: Supports assigning specific credentials to individual or repeated activities within Orchestration workflows and enables credential use for discovering CIs outside the default CI type by specifying the target CI table name.
- External credential store: When selected, switches credential management to an external system (currently supports CyberArk), requiring the External Credential Storage plugin to be activated.
- Applies to: Defines whether credentials apply to all MID Servers or specific ones, controlling credential visibility and usage scope.
- MID servers: Lists MID Servers permitted to access these credentials; applicable only when “Specific MID servers” is chosen.
- Order: Sets the sequence in which Discovery attempts credentials, important for handling multiple credentials and avoiding lockouts after failed login attempts.
- Windows MID Server Service Account: When enabled, the credential represents the service account used by the MID Server.
Practical Considerations
- Ensure credentials are accurate and active to enable successful JDBC connections during Discovery and Orchestration.
- Use the order field to manage credential priority, particularly in environments with many credentials or where security policies limit login attempts.
- Leverage external credential storage for enhanced security and centralized credential management, noting the current CyberArk integration.
- Assign credentials carefully to MID Servers to control access and maintain security boundaries within your network.
The JDBC credential type manages access to a Java Database Connectivity (JDBC) connection. This credential type is available for Discovery and Orchestration.
| Field | Description |
|---|---|
Name |
Enter a unique and descriptive name for this credential. |
Active |
Enable or disable these credentials for use. |
User name |
Enter the user name to create in the Credentials table. Avoid leading or trailing spaces in user names. A warning appears if the platform detects leading or trailing spaces in the user name. For CIM discovery, the user must have the admin role. |
| Password | Enter the password. |
| Credential ID | Enter the unique key configured for external credentials in the JAR file uploaded to the MID Server for an external credential system. The Credential ID field has a limit of 40
characters. This field is only visible when the External credential store check box is selected. |
| Credential alias | Allow workflow creators to assign individual credentials to any activity in an Orchestration workflow or assign different credentials to each occurrence of the same activity type in an Orchestration
workflow. To use the credential for discovering CIs not belonging to this CI type using Service Mapping and Discovery patterns, enter the table name for the CI type to which the CI belongs, for example cmdb_ci_apache_web_server. |
| External credential store | Select this check box to use an external credential storage system. When you select this option the User name and Password fields are replaced with the
Credential ID field. External credential storage is only available when the External Credential Storage plugin in activated. Note: Currently, the only supported external storage system is CyberArk. |
| Applies to | Select whether to apply these credentials to All MID servers in your network, or to one or more Specific MID servers. Specify the MID Servers that should use these credentials in the MID servers field. |
| MID servers | Select one or more MID Servers from the list of available MID Servers. The credentials configured in this record are available to the MID Servers in this list. This field is available only when you select
Specific MID servers from the Applies to field. Note: Selecting Specific Specific MID servers doesn’t affect mid server selection. It’s used
only to decide which mid servers should have visibility to the credential. Specific MID servers isn’t supported in Orchestration activities. |
| Order | Order (sequence) in which Discovery tries this credential as it attempts to log on to devices. The smaller the number, the higher in the list this credential appears. Establish credential order when using large numbers of credentials or when security locks out users after three failed login attempts. If all the credentials have the same order number (or none), the instance tries the credentials in a random order. |
Windows MID Server Service Account |
When active, the defined credential represents the MID Server service account. |