Proper setup and configuration are required to ensure that pVault® can perform all expected operations and functions.
Direct your company’s IT staff to review your application server and verify that the settings detailed in the sections below are configured correctly.
Full compliance with these System Environment requirements not only ensures continued operation as new features and functionality are introduced, but also serves as a buffer of protection from intrusions like crypto-locker and other forms of Ransomware.
Application Server Configuration
•Run all pVault services as a Domain Service Account.
oRecommended account settings (not required):
▪Password should be set to never expire and set so that users cannot change them.
▪If you have a company policy that prohibits the non-expiration of passwords, be aware that our services stop running after reboot once the password expires.
Note: You can enter a new password from the services.msc menu.
•Run all of the following services as the same Domain Service Account.
oApplication
oJob Poll
oWeb
•The Domain Service Account must have full control permissions for the pVault share.
•The Domain Service Account must have full control NTFS permissions for the pVault directory.
•Your standard Domain user accounts do not need NTFS permissions to the pVault directory.
•Your standard Domain user accounts need read-only access to the pVault winclient directory at the share level.
\\%servername%\pvault\deployment\winclient
•Ensure that your standard user accounts have read-only access to the pVault client setup at the share level.
\\%servername%\pvault\deployment\client setup\
•Ensure that your standard user accounts have read-only access to the Addins directories in Server Files at the share level.
\\%servername%\pvault\deployment\Server Files\
•Ensure that your standard user accounts have read-only access to the pVault Application Server Config.
\\%servername%\pvault\deployment\server files\config\peserverconfig.xml
•Ensure that your standard user accounts have read-only access to the pVault Reports Directory at the share level.
\\%servername%\pvault\deployment\reports
•Ensure that your standard user accounts have read-only access to the pVault Attachment Sync Directory at the share level, if applicable.
\\%servername%\pvault\Attachment Sync
•Ensure that the local service account running your SQL server (usually NT Service\MSSQL$PVAULT) has full NTFS permissions to the database directory in our directory.
c:\pvault\database
•If you are in a multi-server environment, your Domain Service Account must be able to see all servers in your configuration.
•If your accounting software uses an ODBC driver, be sure the client of your accounting software is installed on the Application server.
Bridge-level Settings
At the bridge level, an Accounting Software Service Account is required. The required accounting settings are as follows:
•The Service Account must have full access inside the accounting software.
•Password should be set to never expire and set so that users cannot change them.
•If you have a company policy that prohibits the non-expiration of passwords, be aware that bridge connections could stop operating once the password expires.
Note: You can limit individual access to particular items inside pVault.
Firewall/Port Requirements
•For SQL Server and Client Workstations:
Important: Firewall ports need to be open on all related (SQL, Application, Storage) servers and all client workstations.
oIncoming TCP 1433
oIncoming TCP 1434
oIncoming UDP 1433
oIncoming UDP 1434
oOutgoing TCP 1433
oOutgoing TCP 1434
oOutgoing UDP 1433
oOutgoing UDP 1434
oDynamic Port of SQL server.
Located in SQL Server Configuration Manager > SQL Server Network Configuration > Protocols for pVault > TCI/IP > Properties > IP Addresses
•For pVault Application Server:
oWhatever port you have set in the Server Dashboard.
oBy default, this port is 9990. This value is located on the Deployment tab in the Server Dashboard.
•For Web Services:
oYour application server should be able to see the outside web through port 80.
oYou application server should be able to see the outside web through https port 443.
•Whitelist Requirements for Paperless OCR (Xtracta):
oweb1-akl.xtracta.com (PDFs)
oapp.xtracta.com (user interface)
oapi-app.xtracta.com (API)
oapi-app-ui.xtracta.com (user interface if opened through API)
▪Recommended:
•*.xtracta.com
•app.ocr.paperlessenvironments.com