> For the complete documentation index, see [llms.txt](https://docs.keeper.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.keeper.io/user-guides/fr/import-records-1/import-from-cyberark.md).

# Importer depuis CyberArk PACLI

<figure><img src="https://914511346-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LSGVtOTYUIkVBoYtFvK%2Fuploads%2Fp1rub66SO3Rvd4Fod9Hh%2FImport-Keeper-Cyberark.jpg?alt=media&#x26;token=2dd2db77-c695-4c77-bcda-68974a31bdf0" alt=""><figcaption></figcaption></figure>

CyberArk inclut une interface en ligne de commande, PACLI, qui communique directement avec le coffre-fort CyberArk. Elle opère sur des « fichiers » stockés dans des « safes » du coffre-for&#x74;*.* Elle peut exporter les données de *compte* CyberArk, que les clients CyberArk tels que *PrivateArk* et *Password Vault Web Access (PVWA)* stockent sous forme de *fichiers* dans des s*afes*.

Les instructions ci-dessous utilisent un script PowerShell qui s'appuie sur PACLI pour exporter tous les fichiers correspondant à un motif. Avec le motif par défaut « \*, », il exporte tous les fichiers du Safe. Il extrait le Username, l'Address et le mot de passe pour chacun ; toutefois, il peut être configuré pour extraire d'autres champs si nécessaire. Le script fournit les fichiers exportés sous forme d'objets, puis ConvertTo-CSV est utilisé pour les transformer au format CSV (valeurs séparées par des virgules) afin de les importer dans Keeper.

## Prérequis <a href="#prerequisites" id="prerequisites"></a>

Trois composants externes sont requis pour utiliser le script ci-dessous :

1. CyberArk PACLI
2. Un fichier de configuration Vault.ini
3. Un fichier d'identifiants User.ini

### CyberArk PACLI <a href="#cyberark-pacli" id="cyberark-pacli"></a>

Le PACLI est disponible en téléchargement sur le site CyberArk Marketplace. Il s'agit d'un fichier zip contenant le binaire `PACLI.exe` et quelques fichiers associés. Le script attend le chemin du *répertoire* contenant le binaire.

### Vault.ini <a href="#vaultini" id="vaultini"></a>

Le fichier vault.ini contient les paramètres dont PACLI a besoin pour localiser le coffre-fort et s'y connecter. Par exemple :

```ini
VAULT=CAMainVault
ADDRESS=10.11.12.13
PREAUTHSECUREDSESSION=YES
TRUSTSSC=YES
```

Le VAULT peut généralement être laissé sur « CAMainVault ».

L'ADDRESS est le nom d'hôte ou l'adresse IP du serveur de coffre-fort CyberArk.

Les paramètres PREAUTHSECUREDSESSION et TRUSTSSC sont requis lorsque l'utilisateur de connexion est authentifié via LDAP (Active Directory) ou RADIUS. Sinon, ils peuvent être omis.

### User.ini <a href="#userini" id="userini"></a>

Le fichier User.ini est au format INI. Toutefois, il est généré à l'aide de l'outil `CreateCredFile.exe` fourni par CyberArk avec certains de ses composants. Par exemple, génération d'un user.ini pour *Myuser* dans le domaine Active Directory *CORP* :

```powershell
CreateCredFile.exe User.ini Password /Username Myuser /Password "MyPassw0rd!" /ExternalAuth /OSUsername CORP\Myusername
```

La dernière version du zip PACLI contient l'outil. L'exécuter avec le paramètre `/?` expliquera les autres options utiles dans d'autres scénarios d'authentification.

## Exporter <a href="#export" id="export"></a>

Coller le contenu suivant dans un fichier se terminant par *.ps1*, par exemple *Export-CyberArkSafeFiles.ps1*

```powershell
<#
.SYNOPSIS
Exports 'files', i.e., CyberArk Account passwords from a CyberArk Safe using PACLI.

.DESCRIPTION
Uses CyberArk's PACLI command to export files from a CyberArk Safe.
It retrieves files, their categories, and contents and exports an object for each.
It uses filepattern=* to get all files in the safe by default.
The default categories are 'Address' and 'UserName'.
#>
param (
    # The name of the 'Vault' in CyberArk, e.g., 'CAMainVault'
    [Parameter(Mandatory = $true)][string]$VaultName,
    # The name of the 'Safe' in CyberArk
    [Parameter(Mandatory = $true)][ValidateNotNullOrEmpty()][string]$SafeName,
    # The CyberArk log on user (must match credentials in the User.ini)
    [Parameter(Mandatory = $true)][ValidateNotNullOrEmpty()][string]$Username,
    # The path to the PACLI directory containing PACLI.exe
    [Parameter(Mandatory = $true)]
    [ValidateScript({ Test-Path -PathType Leaf (Join-Path $_ 'PACLI.exe') })]
    [string]$PACLIPath,
    # Arguments `findfiles` uses to generate the list of files to export
    [string[]]$FindFilesArguments = 'filepattern=*',
    # The categories to export from the files
    [Parameter()][string[]]$Categories = @('Address', 'UserName'),
    # A CyberArk Vault.ini file
    [Parameter()][ValidateScript({ Test-Path $_ -PathType Leaf })]
    [string]$VaultIniPath = 'Vault.ini',
    # A CyberArk User.ini (or .cred) file as generated by CreateCredFile.exe
    [Parameter()][ValidateScript({ Test-Path $_ -PathType Leaf })]
    [string]$UserIniPath = 'User.ini',
    # The folder in the safe to export files from--most use 'Root'
    [string]$FolderName = 'Root',
    # The session ID to use for the underlying PACLI commands
    [Parameter()][ValidateNotNullOrEmpty()][string]$SessionId,
    # ErrorAction for retrievefile errors
    [Parameter()][ValidateSet('Stop', 'Continue', 'SilentlyContinue')]
    [string]$PACLIErrorAction = 'Continue'
)

$PACLI = Join-Path $PACLIPath 'PACLI.exe' -Resolve

function Invoke-PACLI {
    param (
        [Parameter(Mandatory = $True)][string]$Command,
        [Parameter(ValueFromRemainingArguments)][string[]]$Arguments
    )
    $Executable = ".\{0}" -f (Split-Path -Leaf $PACLI)
    $CommandLine = "$Executable $Command $($Arguments -join ' ')"
    try {
        Push-Location $(Split-Path -Parent $PACLI) -StackName 'PACLI'
        $Output = (& $Executable $Command $Arguments 2>$null)
        if ($LastExitCode -eq 0) {
            $Output
        }
        else {
            switch ($PACLIErrorAction) {
                'Continue' {
                    Write-Error "'$CommandLine' exited with code $LastExitCode"
                }
                'Stop' { throw "'$CommandLine' exited with code $LastExitCode" }
            }
        }
    }
    finally {
        Pop-Location -StackName 'PACLI'
    }
}

Invoke-PACLI init

$PACLIDefaults = "vault=$VaultName", "user=$Username", "safe=$SafeName", 
"folder=$FolderName"
if ($SessionId) {
    $PACLIDefaults += "sessionId=$SessionId"
}
Invoke-PACLI default @PACLIDefaults
Invoke-PACLI definefromfile vault=$VaultName parmfile=(Resolve-Path $VaultIniPath) |
Out-Null
Invoke-PACLI logon logonfile=(Resolve-Path $UserIniPath) | Out-Null
Invoke-PACLI opensafe | Out-Null

try {
    # Create a temporary file to store the file contents during processing
    $tempFile = [IO.Path]::GetTempFileName()
    # Split the tempFile path into the folder and the filename for 'retrievefile'
    $localFolder = Split-Path $tempFile
    $localFile = Split-Path -Leaf $tempFile

    # Get the list of files in the safe
    Invoke-PACLI findfiles $FindFilesArguments 'output(name)' |
    Where-Object { $_.Trim() -ne '' } |
    ForEach-Object {
        $file = @{ Name = $_ }
        # Retrieve the file and store the contents (the password) in the file object
        Invoke-PACLI retrievefile file=$_ localfolder=$localFolder localfile=$localFile
        if ($LastExitCode -ne 0) { return }
        $file.Password = (Get-Content $tempFile).TrimEnd([Char]0) # Can be null-padded
        # Get the list of categories for the file as a quoted CSV string
        Invoke-PACLI listfilecategories file=$_ 'output(all,enclose)' |
        ForEach-Object {
            # Get the category name and value and strip the quotes
            $category = ($_ -split ',' | ForEach-Object { $_.Trim('"') })[0..1]
            # Add the category to the file object if it is on the list
            if ($category[0] -in $Categories) {
                $file[$category[0]] = $category[1]
            }
        }
        [PSCustomObject]$file
    }
}
finally {
    Remove-Item -Path $tempFile -Force
}

Invoke-PACLI closesafe vault=$VaultName user=$Username safe=$SafeName | Out-Null
Invoke-PACLI logoff vault=$VaultName user=$Username | Out-Null
Invoke-PACLI term | Out-Null
```

Extraire le fichier PACLI.zip dans le même répertoire ou un sous-répertoire du répertoire contenant le script.

Ouvrir PowerShell et se placer dans le répertoire contenant le script.

Exécuter le script et rediriger la sortie vers [Export-CSV](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.utility/export-csv) (en anglais) :

```powershell
.\Export-CyberArkSafeFiles.ps1 CAMainVault MySafe Myuser .\PACLI-Rls-v11.5.3 |
Export-CSV Records.csv -Delimiter "`t" -Encoding utf8 -NoHeader -UseQuotes Never
```

Notez que l'utilisation de tabulations au lieu de virgules, l'encodage UTF-8, l'exclusion d'un en-tête et l'absence de guillemets autour des données aident Keeper à importer correctement les données.

### Transformation <a href="#transformation" id="transformation"></a>

PowerShell peut aider à transformer les données au-delà du simple formatage CSV. Cet exemple plus avancé crée le champ « login » en combinant les champs Username et Address, et l'utilise également comme champ « title ».

```powershell
.\Export-CyberArkSafeFiles.ps1 CAMainVault MySafe Myuser .\PACLI-Rls-v11.5.3 |
Select-Object @{l='Folder';e={$_.Name -replace "-$($_.Address)-$($_.Username)", '' }},
 @{l='Login';e={'{0}@{1}' -f $_.Username, $_.Address}}, Password |
Select-Object Folder, @{l='Title';e={$_.Login}}, Login, Password |
Export-Csv Records.csv -Delimiter "`t" -Encoding utf8 -NoHeader -UseQuotes Never
```

## Importer <a href="#import" id="import"></a>

Suivez les instructions pour [Importer un fichier texte (.csv, .xls, .tsv)](/user-guides/fr/import-records-1/import-a-.csv-file.md).


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.keeper.io/user-guides/fr/import-records-1/import-from-cyberark.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
