Create Service Accounts for the Java Agent
The Java Agent makes use of up to two service accounts to allow it to communicate with the Keyfactor Command server. These two service accounts work together to transfer information from the Java Agent to the Keyfactor Command server. The two service accounts can be thought of as players on two sides of a fence, with the service account for the Java Agent lobbing information over the fence to the service account on the Keyfactor Command server side to catch and hand to the Keyfactor Command server:
-
Java Agent Side
On the Java Agent side of the fence, you may use either a local account or an Active Directory service account. - Keyfactor Command Server Side
On the Keyfactor Command server side of the fence, an Active Directory service account in the primary Keyfactor Command server forestis used. This can be the same service account used for other Keyfactor Command server services. This service account appears in the Management Portal Orchestrator
Management grid as the Identity for the Java Agent.
If the Java Agent is installed on a domain-joined machine in the same forest as the Keyfactor Command server, the same Active Directory service account may be used on both sides of the fence.
The service accounts need to be created prior to installation of the Java Agent software, and the person installing the Java Agent software needs to know the domain, username and password of each service account.