Note: this component has a complexity level of "expert", which means that objects of this type are not expected to be created or altered. Please contact support for assistance if you believe that you have a need to create or modify this type of object.
The Conjur Password Storage Scheme provides a mechanism for authenticating users whose passwords are stored in a CyberArk Conjur instance.
This password storage scheme only supports authenticating users and does not allow password changes. Password changes must be made in the Conjur instance. 
 When updating a user account to use this password storage scheme, the password must be provided in pre-encoded form (which will likely require using the password update behavior request control with the allowPreEncodedPassword element set to true). The encoded password should consist of the prefix "{CYBERARK-CONJUR}" followed by a JSON object with the following fields: 
 {CYBERARK-CONJUR}{"path":"variable/appName%2FsecretName"} 
↓Parent Component
↓Relations from This Component
↓Properties
↓dsconfig Usage
The Conjur Password Storage Scheme component inherits from the Password Storage Scheme
The following components have a direct aggregation relation from Conjur Password Storage Schemes:
The properties supported by this managed object are as follows:
| Basic Properties: | Advanced Properties: | 
|---|---|
| ↓ description | None | 
| ↓ enabled | |
| ↓ conjur-external-server | 
| Description | A description for this Password Storage Scheme | 
| Default Value | None | 
| Allowed Values | A string | 
| Multi-Valued | No | 
| Required | No | 
| Admin Action Required | None. Modification requires no further action | 
| Description | Indicates whether the Password Storage Scheme is enabled for use. | 
| Default Value | None | 
| Allowed Values | true false | 
| Multi-Valued | No | 
| Required | Yes | 
| Admin Action Required | None. Modification requires no further action | 
| Description | An external server definition with information needed to connect and authenticate to the Conjur instance containing user passwords. | 
| Default Value | None | 
| Allowed Values | The DN of any Conjur External Server. | 
| Multi-Valued | No | 
| Required | Yes | 
| Admin Action Required | None. Modification requires no further action | 
To list the configured Password Storage Schemes:
dsconfig list-password-storage-schemes
     [--property {propertyName}] ...
To view the configuration for an existing Password Storage Scheme:
dsconfig get-password-storage-scheme-prop
     --scheme-name {name}
     [--tab-delimited]
     [--script-friendly]
     [--property {propertyName}] ...
To update the configuration for an existing Password Storage Scheme:
dsconfig set-password-storage-scheme-prop
     --scheme-name {name}
     (--set|--add|--remove) {propertyName}:{propertyValue}
     [(--set|--add|--remove) {propertyName}:{propertyValue}] ...
To create a new Conjur Password Storage Scheme:
dsconfig create-password-storage-scheme
     --scheme-name {name}
     --type conjur
     --set enabled:{propertyValue}
     --set conjur-external-server:{propertyValue}
     [--set {propertyName}:{propertyValue}] ...
To delete an existing Password Storage Scheme:
dsconfig delete-password-storage-scheme
     --scheme-name {name}