Encryption settings for Pega Robotic Automation
Windows Data Protection API (DPAPI) is a cryptographic application programming interface that is available as a built-in component in Microsoft Windows. The e Pega Robotic Automation credential store uses DPAPI to securely store assisted sign-on credentials on the desktop.
DPAPI encrypts data by using a key derived from the logged-in Windows user's credentials. The use of this key ensures that the assisted sign-on credentials cannot be decrypted by anyone other than the user who initially entered them. DPAPI uses industry-standard encryption algorithms.
The Pega Robotic Automation team has tested DPAPI on the following configurations to determine the algorithms and settings used by the following versions of 64-bit Windows.
- Windows 10 Enterprise
- Windows 11
- Windows Server 2019
- Windows Server 2022
Windows version | 10 | 11 | Server 2019 | Server 2022 |
Encryption | AES-256 | AES-256 | AES-256 | AES-256 |
Hashing | SHA-512 | SHA-512 | SHA-512 | SHA-512 |
Iteration | 8000 | 800 | 8000 | 8000 |
Customer security teams can use this information when evaluating the security of the credential store component.
Previous topic Encryption and the Assisted Sign-On component Next topic Configuring BeyondTrust Password Safe