NIST National Vulnerabilities Database (NVD)
introduction this guide tells you how to authenticate the nist national vulnerabilities database (nvd) connector in swimlane using an api key the connector allows you to retrieve common vulnerabilities and exposures (cves) and common platform enumeration (cpe) information directly from the national vulnerability database an api key is optional but strongly recommended because it increases the api rate limit from 5 requests per 30 seconds to 50 requests per 30 seconds prerequisites nist access requirements you must have access to the national vulnerability database (nvd) a valid email address to request an api key internet access to the nvd rest apis required credentials during setup, you will collect nist api key nist setup take the following steps to generate an api key navigate to the nist api key request page enter your first name last name email address read and accept the terms of use click submit check your email inbox for a message from nvd noreply\@nist gov open the activation link contained in the email copy and securely save your api key important the activation link is valid for 7 days each email address can have only one active api key requesting and activating a new key invalidates the previous key associated with that email address connector configuration in swimlane log in to turbine from the left hand navigation pane, click orchestration and click assets asset homepage opens click the plus icon to open the configure your connector asset window select nist national vulnerabilities database from the asset type list fill in the asset settings and asset input as shown field description required/optional api key nist api key optional (recommended) verify ssl enable/disable ssl verification optional http proxy optional proxy configuration optional fields with marks are required click create troubleshooting api rate limit reached if you receive rate limit errors verify that your api key has been entered correctly use an api key to increase your request limit reduce the frequency of api requests if necessary authentication failed verify that the api key has been activated the api key has been copied correctly the api key has not been regenerated or revoked unable to connect verify that your internet connection allows outbound https traffic proxy settings are configured correctly if your environment uses a proxy ssl errors if ssl verification fails verify that your system trusts the nist ssl certificate disable verify ssl only for testing if permitted by your organization's security policy result you have successfully authenticated the nist national vulnerabilities database connector in swimlane sources nist national vulnerability database api key requests https //nvd nist gov/developers/request an api key https //nvd nist gov/developers/request an api key nist national vulnerability database api documentation https //nvd nist gov/developers/start here https //nvd nist gov/developers/start here