Hello everyone,
we recently migrated from our previous password management solution to Passbolt and are currently trying to identify the community’s best practice for a specific use case.
For security reasons, our Passbolt server is only accessible through a VPN connection.
The challenge is that many of our technicians work directly on customer systems. In these situations they often need credentials stored in Passbolt, but at the same time they must disconnect from our corporate VPN in order to connect to the customer’s environment.
Our current workflow looks like this:
- Connect to our VPN.
- Open Passbolt and retrieve the required credentials.
- Copy the credentials into a temporary clipboard or note.
- Disconnect the VPN.
- Connect to the customer’s system and use the credentials.
While this works, it feels somewhat clunky and potentially less secure than we’d like.
With our previous password manager we had the option to keep a locally synchronized encrypted database on the device, allowing offline access when needed.
Since we are still relatively new to Passbolt, we are wondering:
- Are we using Passbolt incorrectly for this scenario?
- How do other organizations handle situations where users need credentials while disconnected from the Passbolt server?
- Is there a recommended or best practice approach for VPN-only deployments?
- Do you rely on browser extensions, mobile apps, a second VPN connection, caching mechanisms, or some other workflow?
We would be very interested in learning how the community handles this use case in practice.
Thank you in advance for sharing your experience and recommendations!