Skip to content

General options

The General options module groups the global settings that change Bastion behaviour beyond the scope of a single domain or contract. It is intended for an administrator who wants to enable or disable transverse features (vault, syslog, serial authentication, activity measurement, etc.) and to adjust the related delays.

The screen is organised into several collapsible fieldsets. Each fieldset can be opened or collapsed independently. A single Save action at the bottom of the window persists all changes.

Specific confirmations

If the vault mode is changed, a confirmation dialog is displayed before saving. If the change requires a full reload of the console, the application offers to reload the page.


Vault

This section controls the vault mode used by Bastion and the behaviour of alias passwords.

Field Description
Select password vault mode Non-editable drop-down list. Three values: Embedded (default), Systancia Access, Keeper Security. Switching mode dynamically adapts the visible fields below and triggers a confirmation dialog at save time.
Aliases cache renewal period (minutes) Visible only in Keeper Security mode. Duration in minutes (between 1 and 1440, default 30) after which the local copy of the password is renewed.
Allow password display in alias Visible in Embedded and Systancia Access modes. Allows the password to be displayed in plain text in the alias edition form (Embedded) or the managed account edition form (Systancia Access).
Exposed password renewal period (min) Duration in minutes (between 1 and 1440, default 30) after which an exposed password is renewed. Enabled only if the previous option is checked.
Trigger rotation for the used password at the end of any recorded session if it is exposed and not yet renewed Triggers a rotation for the password of an alias at the end of a recorded session, but only if the password was exposed and the renewal period has not yet elapsed. Disabled if password display is not allowed or if the systematic rotation below is checked.
Trigger rotation for the used password at the end of any recorded session Triggers a rotation at the end of every recorded session, even if the password was never exposed.

Consequence of changing the mode

When the vault mode is changed, existing aliases can still be used and deleted but can no longer be modified. Modification is allowed only in the mode in which the alias was originally created. For more information, see the Vault page.


Syslog

Field Description
Send platform events via syslog Sends the events reported in the console (users, configuration, contracts, etc.) to the syslog server.
Send video events to syslog Sends the data traced during recorded sessions to the syslog server: keystrokes, program launches, and so on.

Prerequisite

Both options are enabled only if the system console authorises sending events to syslog for this organisation. Otherwise they are visible but disabled.


Serial authentication

Field Description
Enable serial authentication Enables the global feature. Authentication domains then offer the related options.
Maximum number of authentication attempts for serial authentication Integer strictly greater than 0 (default 3). Enabled only if the feature is enabled.
Enable password change Asks the user to change the password on a successful serial authentication. Enabled only if the feature is enabled.

Applications

Field Description
If the user has a single application then launch it automatically Automatically launches the single available application when the user connects to the user portal, as if they had clicked on it.
Obfuscate keystrokes in database Obfuscates the keystrokes traced during recorded sessions before they are stored in the database.
Web recording sessions expiration time (seconds) Duration in seconds (between 10 and 28800, default 60) after which a web recording session is considered expired.

User activity measurement

Field Description
Enable user's activity measure Enables the quantification of user activity (measured at minute granularity).
Display stickers Represents each graphical session with a colour sticker. Enabled only if activity measurement is enabled.
Display index Represents each archived session with a colour and a number. Enabled only if activity measurement is enabled.
Display outlines Represents each graphical session with a coloured outline. Enabled only if activity measurement is enabled.