Integrating TLS Protect Data Center with Secret Server

Third-party vendors create and maintain this integration. Delinea does not guarantee that the integration will work properly or that it respects Delinea product limitations. Delinea has not reviewed this integration and Delinea Support staff can only assist with the Delinea side of setup.

Venafi TLS Protect Data Center (now part of CyberArk Machine Identity Security) integrates with Delinea Secret Server to retrieve privileged credentials at runtime during certificate lifecycle operations. The integration enables Venafi to authenticate to target endpoints (web servers, load balancers, application servers, network devices) for certificate provisioning, renewal, and installation without storing those endpoint credentials inside Venafi. Credentials remain stored, rotated, and audited in Secret Server, which serves as the single source of truth. This integration supports closer collaboration between PKI/machine identity teams and PAM teams, and reduces the risk of certificate-related outages caused by stale credentials.

Venafi TLS Protect Data Center is compatible with all Secret Server deployment models and requires a dedicated application account for authentication:

  • Secret Server On-Premises: The Venafi TPP server must be able to reach the Secret Server URL and REST API.

  • Secret Server Cloud: The Venafi TPP server connects to the customer's Secret Server Cloud tenant URL.

  • Secret Server on the Delinea Platform: Supported as long as the application account used for the integration remains in Secret Server. Once the account is migrated to the Platform service account model, the existing integration will no longer function, because identity data will be maintained on the Delinea Platform rather than in Secret Server.

This integration offers the following benefits:

  • Centralizes credential storage, rotation, and auditing in Secret Server, eliminating credential sprawl across systems.

  • Reduces the risk of certificate-related outages caused by stale or expired credentials.

  • Supports collaboration between PKI/machine identity teams and PAM teams through a shared credential management model.

How the Integration Works

This integration uses Venafi's Adaptable Credentials framework. A PowerShell driver script runs on the Venafi Trust Protection Platform (TPP) server. The script authenticates to Secret Server using a dedicated application account and the Secret Server REST API. When Venafi performs a certificate provisioning, renewal, or installation task on a target endpoint, it invokes the driver script. The script retrieves the required credential from Secret Server and returns it to Venafi for that single operation. Credentials are never cached or persisted in Venafi; each operation triggers a fresh retrieval from Secret Server.

To learn more about this third-party integration, see the Delinea Credentials integration on the CyberArk Marketplace.