ManageEngine today launched Key Manager Plus, a comprehensive, web-based, SSH key management solution at RSA Conference, 2016. Available immediately, the new product joins ManageEngine’s privileged identity management suite(PIMS) to help administrators take control of SSH keys. Key Manager Plus provides visibility into the SSH environment, enabling administrators to pre-empt breaches and compliance issues.
Safeguarding data in transit has always been a big challenge for security administrators. Most IT organizations today use SSH for remote administrative access and data transfer. While robust and convenient when compared to password-based authentication, SSH keys present some unique challenges. When keys are left unmonitored and unmanaged, organizations are vulnerable to cyber-attacks. In the absence of an automated system, getting the list of all the keys in use, finding and restricting access privileges, and ensuring periodic rotation is a herculean task. ManageEngine Key Manager Plus solves those issues.
“SSH has become the protocol of choice for remote access to business-critical systems both within the corporate network and in the cloud,” said Rajesh Ganesan, Director of Product Management at ManageEngine. “With identity thefts and unauthorized privileged access lying at the root of modern day cyber-attacks, managing the SSH key life cycle has become a significant aspect of privileged access management programs. With Key Manager Plus, we’re helping organizations deploy a complete privileged access management solution.”
Key Manager Plus enables centralized management and visibility over the SSH keys across the network. The new product discovers the SSH systems in the network, enumerates users, and finds existing private keys.It consolidates all discovered SSH keys and stores them in a secure, centralized repository for easy access and management.It centrally creates new public and private key pairs and associates private keys with their users and deploys new or existing public keys on the required systems.It tightens security by periodically rotating key pairs and prevents their misuse. It also provides a holistic view of the key to user relationship across the organization.It enables users launch a direct, SSH connection with target systems using the SSH keys stored in Key Manager Plus and Audits and tracks all user activities and generate reports.Apart from these it associates specific resources to users, establishes granular access controls, helps to delete any unwanted keys from the database, terminate access immediately, and prevent violations by obsolete accounts.Ans last but not the least it improves SSH key management and helps comply with industry regulations such as SOX, FISMA, PCI-DSS, NERC-CIP and HIPAA.
With Key Manager Plus added to its privileged identity management suite, ManageEngine now gives users the tools needed to consolidate, control, manage, monitor and audit the entire life cycle of all types of privileged identities – passwords and SSH keys alike. The suite also includes Password Manager Pro, the company’s privileged password manager for enterprises that need privileged account management, remote access management and session management.