> For the complete documentation index, see [llms.txt](https://docs.keeper.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.keeper.io/user-guides/it/import-records-1/import-from-cyberark.md).

# Importazione da CyberArk PACLI

<figure><img src="https://914511346-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LSGVtOTYUIkVBoYtFvK%2Fuploads%2Fp1rub66SO3Rvd4Fod9Hh%2FImport-Keeper-Cyberark.jpg?alt=media&#x26;token=2dd2db77-c695-4c77-bcda-68974a31bdf0" alt=""><figcaption></figcaption></figure>

CyberArk include un'interfaccia a riga di comando, PACLI, che comunica direttamente con CyberArk Vault. Opera su "files" archiviati in "safes" nel vault. Può esportare i dati di *account* di CyberArk, che i client CyberArk come *PrivateArk* e *Password Vault Web Access (PVWA)* archiviano come *files* nei s*afes*.

Le istruzioni seguenti usano uno script PowerShell che utilizza PACLI per esportare tutti i file corrispondenti a un pattern. Con il pattern predefinito "\*," esporta tutti i file dal Safe. Estrae Username, Address e password per ciascuno; tuttavia, può essere configurato per estrarre altri campi se necessario. Lo script fornisce i file esportati come oggetti, quindi ConvertTo-CSV li trasforma in formato Comma-separated Value (CSV) per importarli in Keeper.

## Prerequisiti

Per usare lo script seguente sono necessari tre componenti esterni:

1. CyberArk PACLI
2. Un file di configurazione Vault.ini
3. Un file di credenziali User.ini

### CyberArk PACLI

PACLI è disponibile per il download dal sito CyberArk Marketplace. È un file zip che contiene il binario `PACLI.exe` e alcuni file di supporto. Lo script si aspetta il percorso della *directory* che contiene il binario.

### Vault.ini

Il file vault.ini contiene i parametri di cui PACLI ha bisogno per individuare e accedere al vault. Ad esempio:

```ini
VAULT=CAMainVault
ADDRESS=10.11.12.13
PREAUTHSECUREDSESSION=YES
TRUSTSSC=YES
```

VAULT può in genere restare impostato su "CAMainVault."

ADDRESS è l'hostname o l'indirizzo IP del server CyberArk Vault.

Le impostazioni PREAUTHSECUREDSESSION e TRUSTSSC sono necessarie quando l'utente di accesso viene autenticato tramite LDAP (Active Directory) o RADIUS. Altrimenti possono essere omesse.

### User.ini

Il file User.ini è in formato INI. Tuttavia viene generato con lo strumento `CreateCredFile.exe` incluso da CyberArk in alcuni dei suoi componenti. Ad esempio, generazione di un user.ini per *Myuser* nel dominio Active Directory *CORP*:

```powershell
CreateCredFile.exe User.ini Password /Username Myuser /Password "MyPassw0rd!" /ExternalAuth /OSUsername CORP\Myusername
```

La versione più recente dello zip PACLI contiene lo strumento. Eseguirlo con il parametro `/?` spiega le altre opzioni utili in altri scenari di autenticazione.

## Esporta

Incolli quanto segue in un file con estensione *.ps1*, ad esempio *Export-CyberArkSafeFiles.ps1*

```powershell
<#
.SYNOPSIS
Exports 'files', i.e., CyberArk Account passwords from a CyberArk Safe using PACLI.

.DESCRIPTION
Uses CyberArk's PACLI command to export files from a CyberArk Safe.
It retrieves files, their categories, and contents and exports an object for each.
It uses filepattern=* to get all files in the safe by default.
The default categories are 'Address' and 'UserName'.
#>
param (
    # The name of the 'Vault' in CyberArk, e.g., 'CAMainVault'
    [Parameter(Mandatory = $true)][string]$VaultName,
    # The name of the 'Safe' in CyberArk
    [Parameter(Mandatory = $true)][ValidateNotNullOrEmpty()][string]$SafeName,
    # The CyberArk log on user (must match credentials in the User.ini)
    [Parameter(Mandatory = $true)][ValidateNotNullOrEmpty()][string]$Username,
    # The path to the PACLI directory containing PACLI.exe
    [Parameter(Mandatory = $true)]
    [ValidateScript({ Test-Path -PathType Leaf (Join-Path $_ 'PACLI.exe') })]
    [string]$PACLIPath,
    # Arguments `findfiles` uses to generate the list of files to export
    [string[]]$FindFilesArguments = 'filepattern=*',
    # The categories to export from the files
    [Parameter()][string[]]$Categories = @('Address', 'UserName'),
    # A CyberArk Vault.ini file
    [Parameter()][ValidateScript({ Test-Path $_ -PathType Leaf })]
    [string]$VaultIniPath = 'Vault.ini',
    # A CyberArk User.ini (or .cred) file as generated by CreateCredFile.exe
    [Parameter()][ValidateScript({ Test-Path $_ -PathType Leaf })]
    [string]$UserIniPath = 'User.ini',
    # The folder in the safe to export files from--most use 'Root'
    [string]$FolderName = 'Root',
    # The session ID to use for the underlying PACLI commands
    [Parameter()][ValidateNotNullOrEmpty()][string]$SessionId,
    # ErrorAction for retrievefile errors
    [Parameter()][ValidateSet('Stop', 'Continue', 'SilentlyContinue')]
    [string]$PACLIErrorAction = 'Continue'
)

$PACLI = Join-Path $PACLIPath 'PACLI.exe' -Resolve

function Invoke-PACLI {
    param (
        [Parameter(Mandatory = $True)][string]$Command,
        [Parameter(ValueFromRemainingArguments)][string[]]$Arguments
    )
    $Executable = ".\{0}" -f (Split-Path -Leaf $PACLI)
    $CommandLine = "$Executable $Command $($Arguments -join ' ')"
    try {
        Push-Location $(Split-Path -Parent $PACLI) -StackName 'PACLI'
        $Output = (& $Executable $Command $Arguments 2>$null)
        if ($LastExitCode -eq 0) {
            $Output
        }
        else {
            switch ($PACLIErrorAction) {
                'Continue' {
                    Write-Error "'$CommandLine' exited with code $LastExitCode"
                }
                'Stop' { throw "'$CommandLine' exited with code $LastExitCode" }
            }
        }
    }
    finally {
        Pop-Location -StackName 'PACLI'
    }
}

Invoke-PACLI init

$PACLIDefaults = "vault=$VaultName", "user=$Username", "safe=$SafeName", 
"folder=$FolderName"
if ($SessionId) {
    $PACLIDefaults += "sessionId=$SessionId"
}
Invoke-PACLI default @PACLIDefaults
Invoke-PACLI definefromfile vault=$VaultName parmfile=(Resolve-Path $VaultIniPath) |
Out-Null
Invoke-PACLI logon logonfile=(Resolve-Path $UserIniPath) | Out-Null
Invoke-PACLI opensafe | Out-Null

try {
    # Create a temporary file to store the file contents during processing
    $tempFile = [IO.Path]::GetTempFileName()
    # Split the tempFile path into the folder and the filename for 'retrievefile'
    $localFolder = Split-Path $tempFile
    $localFile = Split-Path -Leaf $tempFile

    # Get the list of files in the safe
    Invoke-PACLI findfiles $FindFilesArguments 'output(name)' |
    Where-Object { $_.Trim() -ne '' } |
    ForEach-Object {
        $file = @{ Name = $_ }
        # Retrieve the file and store the contents (the password) in the file object
        Invoke-PACLI retrievefile file=$_ localfolder=$localFolder localfile=$localFile
        if ($LastExitCode -ne 0) { return }
        $file.Password = (Get-Content $tempFile).TrimEnd([Char]0) # Can be null-padded
        # Get the list of categories for the file as a quoted CSV string
        Invoke-PACLI listfilecategories file=$_ 'output(all,enclose)' |
        ForEach-Object {
            # Get the category name and value and strip the quotes
            $category = ($_ -split ',' | ForEach-Object { $_.Trim('"') })[0..1]
            # Add the category to the file object if it is on the list
            if ($category[0] -in $Categories) {
                $file[$category[0]] = $category[1]
            }
        }
        [PSCustomObject]$file
    }
}
finally {
    Remove-Item -Path $tempFile -Force
}

Invoke-PACLI closesafe vault=$VaultName user=$Username safe=$SafeName | Out-Null
Invoke-PACLI logoff vault=$VaultName user=$Username | Out-Null
Invoke-PACLI term | Out-Null
```

Estragga PACLI.zip nella stessa directory o in una sottodirectory della directory che contiene lo script.

Apra PowerShell e si sposti nella directory che contiene lo script.

Esegua lo script e indirizzi l'output a [Export-CSV](https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.utility/export-csv) (in inglese):

```powershell
.\Export-CyberArkSafeFiles.ps1 CAMainVault MySafe Myuser .\PACLI-Rls-v11.5.3 |
Export-CSV Records.csv -Delimiter "`t" -Encoding utf8 -NoHeader -UseQuotes Never
```

Nota: l'uso di caratteri di tabulazione invece delle virgole, la codifica UTF-8, l'esclusione dell'intestazione e l'assenza di virgolette sui dati aiutano Keeper a importare correttamente i dati.

### Trasformazione

PowerShell può aiutare a trasformare i dati oltre a formattarli come CSV. Questo esempio più avanzato crea il campo "login" combinando i campi Username e Address e lo usa anche come campo "title".

```powershell
.\Export-CyberArkSafeFiles.ps1 CAMainVault MySafe Myuser .\PACLI-Rls-v11.5.3 |
Select-Object @{l='Folder';e={$_.Name -replace "-$($_.Address)-$($_.Username)", '' }},
 @{l='Login';e={'{0}@{1}' -f $_.Username, $_.Address}}, Password |
Select-Object Folder, @{l='Title';e={$_.Login}}, Login, Password |
Export-Csv Records.csv -Delimiter "`t" -Encoding utf8 -NoHeader -UseQuotes Never
```

## Importa

Segua le istruzioni per [Importare file di testo (.csv, .xls, .tsv)](/user-guides/it/import-records-1/import-a-.csv-file.md).


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.keeper.io/user-guides/it/import-records-1/import-from-cyberark.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
