Command Line Arguments
The following command line arguments are supported by Verify Privilege Vault Remote during installation only. They should not be used after installation to start the Verify Privilege Vault Remote.
Application settings were moved to the Registry in the 2.8 release. The command line arguments below apply to installation only. To view or change application settings after installation, see Application Configuration via Windows Registry Editor. If you are using an older version of Verify Privilege Vault Remote, refer to the Application Configuration File.
-disablelocalvault-logo-logocollapsed-ssauthThe
-ssauthoptionsupportstwo values:local, external.-ssname-ssurl-
-ssautoclosebrowserlogin -
-reauthenticateThe
-reauthenticateoption supports the following two values:yandn -
-preferredAuth -
-screenshotsQueueLimit -
-updateOnStartup
You must use double quotes inside the KEYS parameter because the value of the KEYS parameter is quoted itself.
/quiet mode installation works only with Administrative privileges. If a user without administrator privileges runs the MSI with /quiet mode, nothing happens.
If you would like to install the latest version of Verify Privilege Vault Remote via quiet mode installation, you must first remove the previous version before installing the new one.
When installing Verify Privilege Vault Remote via command line options to set the Verify Privilege Vault URL, these options will only be applied to the first user who logs in to Verify Privilege Vault Remote. If you would like to make them the default options, you can use the following workarounds:
-
Prior to their initial log in, new users need to run Verify Privilege Vault Remote via command line with
args -ssurl "your ss url" -ssname "your ss name" -ssauth "your auth type" -
Prior to their initial login, each user admin should create a file in path
C:\ProgramData\Delinea\Connection Manager\repository.datwith the following content:
[
{ "$type":"Delinea.ConnectionManager.Common.Models.SecretServerRepository, Delinea.ConnectionManager.Common",
"Url":"Your SS url",
"PlatformUrl":null,
"UserName":null,
"Password":null,
"Domain":null,
"AuthType":"Local",
"TwoFactorAuthType":"None",
"PinCode":null,
"StoreCredentialsInLocalStorage":false,
"SecretTempletes":null,
"LoadAllTemplates":true,
"Token":null,
"PlatformToken":null,
"ConnectionManagerSettings":null,
"Id":null,
"Name":"your SS name",
"Type":"SecretServer",
"IsAutoload":false
}
]
If your command line parameter includes any spaces or parentheses, be sure to place quotation marks around the MSI file. An example is below.
For example: "C:\Users\MyUser\Downloads\IBMSecurityVerify.PrivilegeVaultRemote
`\IBMSecurityVerify.PrivilegeVaultRemote2.5.0.WindowsInstaller.msi" /quiet RUNCM=runCM
Per User Installation via Quiet Mode
When installing Verify Privilege Vault Remote for yourself only, you will need to add the following parameter: USERMODE=1:
Example:
"C:\Users\MyUser\Downloads\Connection Manager\Delinea.ConnectionManager.2.8.0.WindowsInstaller.msi" /quiet RUNCM=runCM USERMODE=1
The following command line arguments are not supported for per user installation via quiet mode:
-
ssurl
-
ssname
-
ssauth
-
ssautoclosebrowserlogin
Changing the Location of the .DAT File
The default location of the .dat file is: C:User/[UserName]/AppData/Roaming/Delinea/ConnectionManager
You can change the location of the .dat file upon installation by running the following command:
Example for Windows:
Delinea.ConnectionManager.2.8.0.WindowsInstaller.msi /quiet RUNCM=runCM KEYS="-lsPath ""C:\Users\Username\AppData\Roaming\New Delinea\Connection Manager""
Changing the Installation Path
Users can change the Verify Privilege Vault Remote installation path by inserting the INSTALLFOLDER variable on Windows and CustomInstallationPath on MacOS during installation as shown in the examples below:
Example for Windows
IBMSecurityVerify.PrivilegeVaultRemote.msi.2.6.0.WindowsInstaller.msi /quiet RUNCM=runCM INSTALLFOLDER="C:\work"
Example for MacOS:
sudo defaults write /Library/Preferences/com.Delinea.ConnectionManager CustomInstallationPath "/Applications/Delinea12" && sudo installer -pkg D2.7.0-path.pkg -target /
sudo defaults write /Library/Preferences/com.IBMSecurity.VerifyPrivilegeVaultRemote CustomInstallationPath "/Applications/New IBM" && sudo installer -pkg IBM2.8-path.pkg -target /
Pre-Configuring Vault Connections on Install
Administrators can pre-configure IBM Security vault connections so that users do not have to create connections themselves when opening Verify Privilege Vault Remote for the first time. These connections can be pre-configured in the .DAT file:
[
{
"$type": "Delinea.ConnectionManager.Common.Models.SecretServerRepository, Delinea.ConnectionManager.Common",
"Url": "https://yourfirstvaulturl.com",
"PlatformUrl": null,
"UserName": null,
"Password": null,
"Domain": null,
"AuthType": "Local",
"TwoFactorAuthType": "None",
"PinCode": null,
"StoreCredentialsInLocalStorage": false,
"SecretTempletes": null,
"LoadAllTemplates": true,
"Token": null,
"PlatformToken": null,
"ConnectionManagerSettings": null,
"Id": null,
"Name": "First Vault",
"Type": "SecretServer",
"IsAutoload": false
},
{
"$type": "Delinea.ConnectionManager.Common.Models.SecretServerRepository, Delinea.ConnectionManager.Common",
"Url": "https://yoursecondvaulturl.com",
"PlatformUrl": null,
"UserName": null,
"Password": null,
"Domain": null,
"AuthType": "Local",
"TwoFactorAuthType": "None",
"PinCode": null,
"StoreCredentialsInLocalStorage": false,
"SecretTempletes": null,
"LoadAllTemplates": true,
"Token": null,
"PlatformToken": null,
"ConnectionManagerSettings": null,
"Id": null,
"Name": "Second Vault",
"Type": "SecretServer",
"IsAutoload": false
}
]
Disabling Local Vault on Installation
Use this argument to disable the local vault on installation:
-disablelocalvault
Example for Windows
IBMSecurityVerify.PrivilegeVaultRemote.msi /quiet RUNCM=runCM KEYS="-disablelocalvault "
Example for MacOS
sudo installer -pkg ~/Downloads/IBM.pkg -target / && open /Applications/IBMSecurity/IBM\ Security\ Verify\ Privilege\ Vault\ Remote.app --args -disablelocalvault
Enabling/Disabling Auto Reauthenticate
This feature provides the option to configure vault reauthentication behavior in Verify Privilege Vault Remote. Users may keep the existing behavior that automatically restarts the authentication flow or force a fresh login when their vault session/refresh tokens have expired--mimicking the existing web API behavior.
The default value is -reauthenticate y. If the value is set to -reauthenticate n, the behavior will be more similar to the web API which forces a fresh login. The -reauthenticate n option is beneficial for users who use SAML configuration through an external identity provider with a longer session/refresh length and enables audit logs to correctly generate upon logout.
Use this argument to disable auto reauthenticate on installation:
-reauthenticate n
Example
IBMSecurityVerify.PrivilegeVaultRemote.msi /quiet RUNCM=runCM KEYS="-ssurl ""https://secretserver.example.com/ss"" -ss-name ""new server"" -reauthenticate n"
SSH Authentication Method Setup on the Target Host
For more information on this command line, see Troubleshooting SSH Connections.
Example:
Delinea.ConnectionManager.WindowsInstaller.msi /quiet RUNCM=runCM KEYS="-preferredAuth ""keyboard-interactive,publickey,password"""
Setting the Screenshot Queue Limit
For more information on setting the screenshot queue limit see Session Recording.
Example:
Delinea.ConnectionManager.WindowsInstaller.msi /quiet RUNCM=runCM KEYS="-screenshotsQueueLimit 60"
Disabling Update Check on Startup
To disable automatic checking for updates on startup, set the value to n as shown below:
Delinea.ConnectionManager.WindowsInstaller.msi /quiet RUNCM=runCM KEYS="-updateOnStartup n"
Specifying Custom Logo Images to Copy to the Proper Location
The paths to the custom logo files, on Windows, are as follows:
-
C:\ProgramData\IBMSecurity\IBM Security Verify Privilege Vault Remote\Resources\logo.png
-
C:\ProgramData\IBMSecurity\IBM Security Verify Privilege Vault Remote\logo_collapsed.png
Use these arguments to specify custom logo images to be copied to the proper location:
-logo, -logocollapsed
Example for Windows
IBMSecurityVerify.PrivilegeVaultRemote.msi /quiet RUNCM=runCM KEYS="-logo ""/Library/Application Support/IBMSecurity\IBM Security Verify Privilege Vault Remote/Resources2/logo.png"" -logocollapsed ""/Library/Application Support/IBMSecurity\IBM Security Verify Privilege Vault Remote/Resources2/logo_collapsed.png"""
Example for MacOS
sudo installer -pkg ~/Downloads/IBM2.7.0-RC7.pkg -target / && open /Applications/IBMSecurity/IBM\ Security\ Verify\ Privilege\ Vault\ Remote.app --args -logo "/Users/[username]/Downloads/logo.png" -logocollapsed "/Users/[username]/Downloads/logo_collapsed.png"
Example Powershell Command Line
.\IBMSecurityVerify.PrivilegeVaultRemote.msi /quiet RUNCM=runCM KEYS='"-logo ""/Library/Application Support/IBMSecurity\IBM Security Verify Privilege Vault Remote/Resources2/logo.png"" -logocollapsed ""/Library/Application Support/IBMSecurity\IBM Security Verify Privilege Vault Remote/Resources2/logo_collapsed.png"""'
The path to the custom logo files, on a Mac, is as follows:
-
Users/Shared/Application Support/IBMSecurity/IBM Security Verify Privilege Vault Remote
Two files are necessary to use custom logos:
- Logo.png - 50 x 250 pixels
- Logo_collapsed.png - 50 x 100 pixels
Pre-Creating a Verify Privilege Vault Connection
Use these arguments to pre-create a Verify Privilege Vault local or web connection on installation:
-ssurl, -ssname, -ssauth
Customizing External Browser Authentication
Users can customize external browser authentication by running a script containing the argument %url%, which represents login URL. Any parameters recognized by the browser at startup can be used. These settings only need to be applied once and will be saved by Verify Privilege Vault Remote. Both admins and users can apply these settings, but admin settings will override user settings. Examples of possible customization scripts are listed below:
Certain complex scripts that use JavaScript may not work correctly since the browser may truncate the URL. If you are experiencing this issue, consider replacing the %url% value with %eurl% (escaped URL) where only certain cymbols are escaped.
Using the ampersand (&) in command lines is not allowed.
Selecting a browser to launch the authentication flow
Run the following command:
{Browser Name} "%url%"
This will set the default browser used for authentication. You can change this by inputting one of the following supported browsers:
-
chrome
-
msedge
-
firefox
-
explorer (This option launches the authentication flow via your default browser)
Example for Chrome:
chrome "%url%"
If this setting is not applied, Verify Privilege Vault Remote will use the default browser for the authentication flow.
Opening the Browser in a New Window
Example for Chrome:
chrome --new-window "%url%"
Launching a Browser in Incognito Mode
Example for Chrome:
chrome --incognito "%url%"
Example for Edge:
msedge -inprivate "%url%"
Opening a Browser in Limited Mode
Example for Chrome:
chrome --app=%url%
Setting Custom Window Size and Position
Example for Chrome:
chrome --user-data-dir="C:\Temp\ChromeProfile1" --window-position=200,200 --window-size=200,200 --app=%url%
External Browser Connection
Example for Windows
IBMSecurityVerify.PrivilegeVaultRemote.msi /quiet RUNCM=runCM KEYS="-ssurl ""https://secretserver.example.com/ss"" -ss-name ""new server"" -ssauth external"
Example for MacOS
sudo installer -pkg ~/Downloads/IBM.pkg -target / && open /Applications/IBMSecurity/IBM\ Security\ Verify\ Privilege\ Vault\ Remote.app --args -ssurl "https://secretserver.example.com/ss " -ssname "new" -ssauth "external"
Example Powershell Command Line
.\IBMSecurityVerify.PrivilegeVaultRemote.msi /quiet RUNCM=runCM KEYS='"-ssurl https://secretserver.example.com/ss -ssname ""new server"" -ssauth external"'
Local Connection
Example for Windows
IBMSecurityVerify.PrivilegeVaultRemote.msi /quiet RUNCM=runCM KEYS="-ssurl ""https://secretserver.example.com/ss"" -ss-name ""new server"" -ssauth local"'
Example for MacOS
sudo installer -pkg ~/Downloads/IBM.pkg -target / && open /Applications/IBMSecurity/IBM\ Security\ Verify\ Privilege\ Vault\ Remote.app --args -ssurl "https://secretserver.example.com/ss " -ssname "new" -ssauth "local"
Example Powershell Command Line
.\IBMSecurityVerify.PrivilegeVaultRemote.msi /quiet RUNCM=runCM KEYS='"-ssurl https://secretserver.example.com/ss -ssname ""new server"" -ssauth local"'
Internal Browser Connection
Internal browser authentication was deprecated as of the 2.8 release. Use these command lines for versions 2.7 and older.
Example for Windows
IBMSecurityVerify.PrivilegeVaultRemote.msi /quiet RUNCM=runCM KEYS="-ssurl ""https://secretserver.example.com/ss"" -ss-name ""new server"" -ssauth web"
Example for MacOS
sudo installer -pkg ~/Downloads/DelineaConnectionManager.pkg -target / && open /Applications/Delinea/Delinea\ Connection\ Manager.app --args -ssurl "https://secretserver.example.com/ss " -ssname "new" -ssauth "web"
sudo installer -pkg ~/Downloads/IBM.pkg -target / && open /Applications/IBMSecurity/IBM\ Security\ Verify\ Privilege\ Vault\ Remote.app --args -ssurl "https://secretserver.example.com/ss " -ssname "new" -ssauth "web"
Example Powershell Command Line
.\IBMSecurityVerify.PrivilegeVaultRemote.msi /quiet RUNCM=runCM KEYS='"-ssurl https://secretserver.example.com/ss -ssname ""new server"" -ssauth web"'
Disabling Local Vault
Example Powershell Command Line
`.\IBMSecurityVerify.PrivilegeVaultRemote.msi /quiet RUNCM=runCM KEYS='"-disablelocalvault"'
Example for MacOS
sudo installer -pkg ~/Downloads/IBM.pkg -target / && open /Applications/IBMSecurity/IBM\ Security\ Verify\ Privilege\ Vault\ Remote.app --args -disablelocalvault