Table of Contents

Class CredentialProfile

Namespace
ArcanaDevelopment.adTempus.Client
Assembly
ArcanaDevelopment.adTempus.Client.dll

Stores a set of login credentials (user ID and password) for Windows or another system.

[ComVisible(true)]
[Guid("619f8180-6a62-460a-9a6d-8396ec3e5a1a")]
public sealed class CredentialProfile : ADTIndependentObject
Inheritance
object
CredentialProfile

Properties

AgentProfiles

A collection of overrides, allowing the credential settings to be overridden for Remote Agents.

public RemoteAgentCredentialProfileCollection AgentProfiles { get; }

Property Value

RemoteAgentCredentialProfileCollection

Remarks

If a different user ID and/or password needs to be used for this job on a particular Remote Agent, add a RemoteAgentCredentialProfile to configure the settings for that Agent.

CanImpersonateSystem

Determines whether this profile is permitted to impersonate the adTempus system account

public bool CanImpersonateSystem { get; set; }

Property Value

bool

Remarks

The caller must be an adTempus Administrator to set this value.

Exceptions

PermissionDeniedException

Thrown if the caller does not have permission to set this value

ClassID

The Class ID for the object

[IgnoreDataMember]
public override ClassID ClassID { get; }

Property Value

ClassID

ClassKeyName

The key name for the class.

public override string ClassKeyName { get; }

Property Value

string

Remarks

This name the name used by adTempus to identify the class and is intended for programmatic use only. Use the ClassName for a user-friendly name.

CredentialSelector

Additional selector or discriminator for use with non-windows credentials.

public string CredentialSelector { get; set; }

Property Value

string

Remarks

The CredentialSelector can be used to specify context information for credentials. For example, if a profile is being used to store database connection credentials, the CredentialSelector may be set to the name of the database server so that all credentials for the server can be easily retrieved, and to prevent naming conflicts if the same user ID needs to be defined for more than one server.

CredentialType

The kind of credentials represented.

public string CredentialType { get; set; }

Property Value

string

Remarks

A CredentialProfile can represent login credentials for many kinds of systems (Windows, a Web server, etc.). The CredentialType indicates the type of login for which these credentials are indended.

The following CredentialTypes are currently defined:

(null or empty string)A Windows login
ArcanaDevelopment.adTempus.SQLServerCredentialsA database login for the DatabaseOperationTask. The database type does not need to be SQL Server, despite the name of the CredentialType (which is retained for backward compatibility). The CredentialSelector can be used to restrict the credentials to a particular database server/database name combination.
ArcanaDevelopment.adTempus.WebCredentialsCredentials for a Web server used by a WebRequestTask.
See Also

CredentialTypeDisplay

The user-friendly type description to display when showing the profile to a user.

public string CredentialTypeDisplay { get; set; }

Property Value

string

Domain

Returns the domain portion of the UserID, if one is present.

public string Domain { get; }

Property Value

string

The domain name for the UserID, or an empty string if the userID does not contain a domain.

Remarks

If the UserID contains a domain and user ID, Domain returns the domain only, without the user name.

See Also

FullyQualifiedID

Gets the fully-qualified ID, which includes the CredentialType, CredentialSelector, and UserID

public string FullyQualifiedID { get; }

Property Value

string

IsDependent

Indicates whether the object is a dependent of (owned by) another object

[IgnoreDataMember]
public override bool IsDependent { get; }

Property Value

bool

Remarks

An independent object (IsDependent is false) is an object that can exist on its own without being part of another object. For example, Jobs, Job Groups, etc.

A dependent object (IsDependent is true) is a part of another object. For example, a JobStep cannot exist independently of a Job, so the JobStep is dependent.

Dependent objects cannot be directly fetched from the server: they are only fetched as part of the object they belong to. They also cannot be saved or deleted independently: they are automatically saved or deleted when the owning object is saved or deleted.

IsLocalSystem

Indicates whether this profile represents the System account on Windows.

public bool IsLocalSystem { get; }

Property Value

bool

IssueExpirationAlerts

Determines whether adTempus should issue alerts when the profile's password is nearing expiration or has expired.

public bool IssueExpirationAlerts { get; set; }

Property Value

bool
See Also

LastPasswordChange

The date/time (in UTC) when the password was last changed.

[ComVisible(false)]
public DateTime? LastPasswordChange { get; set; }

Property Value

DateTime?

PasswordExpirationDate

The expiration date (in UTC) for the current password.

[ComVisible(false)]
public DateTime? PasswordExpirationDate { get; set; }

Property Value

DateTime?

PasswordExpirationDays

The number of days after which the password expires.

public int PasswordExpirationDays { get; set; }

Property Value

int

Remarks

This value is stored for calculating the PasswordExpirationDate. Set to 0 for no expiration.

PasswordSet

Indicates whether a password has been set for this profile

public bool PasswordSet { get; }

Property Value

bool

SupportedSecurityActions

List of security actions supported by this object.

public override Dictionary<int, string> SupportedSecurityActions { get; }

Property Value

Dictionary<int, string>

A dictionary of the supported actions. The key is one of the SecurityPermission values and the value is the name of the permission (from GetSecurityPermissionName(SecurityPermission, string); a given SecurityPermission may use different names in different contexts).

UserID

The user ID (including Windows domain, if appropriate).

public string UserID { get; set; }

Property Value

string

UserName

Returns the user name portion of the UserID.

public string UserName { get; }

Property Value

string

The user name part of the UserID.

Remarks

If the UserID contains a domain and user ID, UserName returns the name only, without the domain.

See Also

Methods

CanPerform(SecurityPermission)

Determines whether the user has the necessary permission to perform a specified action on the object

public override bool CanPerform(SecurityPermission action)

Parameters

NameTypeDescription
action SecurityPermission

The operation to check permission for.

Returns

bool

true if the caller has the requested permission or if the object is not secured

Remarks

This method uses cached permission information returned by the server on the last refresh of the object. It is therefore possible for CanPerform to report outdated information if permissions have changed since then.

The permission check considers both inherited and explicit permissions.

For a "child" object (such as a JobStep this method checks the permission on the owning object.

See Also

ChangePassword(string, string, DateTime?)

Changes the password for the profile.

public void ChangePassword(string oldPassword, string newPassword, DateTime? passwordExpirationDate)

Parameters

NameTypeDescription
oldPassword string

The current password for the profile. See Remarks.

newPassword string

The new password.

passwordExpirationDate DateTime?

The expiration date for the password, if expiration tracking is being used.

Remarks

If the caller has Modify permission for the profile, the oldPassword does not need to be specified. If the caller does not have Modify permission, the password can still be changed by specifying both the oldPassword and the newPassword.

See Also

GetObjectDescription()

Gets a description of the object's key settings.

protected override string GetObjectDescription()

Returns

string

Remarks

This method is called by GetDescription() to get a user-friendly description of the object (such as its key settings) for display to the user. The description should contain enough information to distinguish this object from others of the same class.

SetPassword(string)

Sets the password to the new value.

public void SetPassword(string value)

Parameters

NameTypeDescription
value string

The new password for the profile.

Remarks

This method sets the password to the specified value, and sets the LastPasswordChange to the current date/time.

The change takes place only once the CredentialProfile is saved; the caller must have Modify permission for the profile.

See Also

ValidateLoginCredentials(out MessageCollection)

Validates the login credentials on the server

public bool ValidateLoginCredentials(out MessageCollection messages)

Parameters

NameTypeDescription
messages MessageCollection

A collection of error messages reported if validation fails

Returns

bool

Remarks

This method is only valid for Windows login credentials (CredentialType is null or empty). The method performs a Windows login on the adTempus server. Repeated failed calls may result in the user's account being locked out by Windows.

VerifyPassword(string, bool)

Tests to see if a value is the correct password for the profile

public bool VerifyPassword(string passwordToTest, bool addPermission)

Parameters

NameTypeDescription
passwordToTest string

The password to try

addPermission bool

If true the caller is automatically granted permission to use the profile if the password check succeeds.

Returns

bool

true if the passwordToTest is the correct password for the profile.

Remarks

This method is used to allow a user to automatically gain permission to use the Credential Profile if they know the password for the account. Call with addPermission set to true and the user is automatically granted Use permission for the profile if the passwordToTest is correct. This allows users to get permission to use profiles without an administrator having to explicitly grant access.

WriteToConfigurationReport(IADTObjectConfigurationReportWriter)

Writes the object and any contained objects to a configuration report

public override void WriteToConfigurationReport(IADTObjectConfigurationReportWriter reportBuilder)

Parameters

NameTypeDescription
reportBuilder IADTObjectConfigurationReportWriter

The report builder to write the object to.

Inherited Members

See Also