Qualys Vulnerability Scanner
introduction this guide explains how to authenticate the qualys vulnerability scanner connector in swimlane using http basic authentication you will obtain your qualys api endpoint, confirm your api credentials, and configure the connector in swimlane prerequisites qualys access requirements ensure that you have a qualys vmdr (or supported qualys platform) account a user account with permission to access the qualys api a valid qualys username and password the qualys api endpoint (based on your qualys platform/soc) if your qualys account uses vip two factor authentication (2fa) , you can still use the qualys api two factor authentication is only required when logging in to the qualys web portal and is not used for api authentication required credentials during setup, you will collect qualys api url username password qualys setup take the following steps to identify your qualys api url log in to your qualys account note the url displayed in your browser use the appropriate api endpoint for your qualys platform example https //qualysapi qualys com customers hosted in other qualys platforms (eu, india, canada, etc ) should use the api endpoint provided for their region verify api access log in to the qualys portal navigate to help or account information (location varies by platform) verify that your account has api access enabled if api access is unavailable, contact your qualys administrator connector configuration in swimlane log in to turbine from the left hand navigation pane, click orchestration > assets the assets page opens click the plus (+) icon to create a new connector asset select qualys vulnerability scanner from the asset type list configure the asset using the following values field description required/optional url qualys api endpoint required username qualys username required password qualys password required verify ssl verify the server ssl certificate optional http proxy proxy server used to route requests optional fields marked with are required click create troubleshooting authentication failed (401 unauthorized) verify that the username and password are correct the account is active api access is enabled for the account the correct qualys platform url is configured permission denied (403 forbidden) verify that your user account has permission to access the qualys api the account has sufficient privileges to retrieve vulnerability information unable to connect verify that the qualys api url is correct your firewall or proxy allows outbound https connections the qualys platform is reachable ssl certificate errors if ssl verification fails verify that the qualys endpoint presents a trusted ssl certificate confirm that any corporate proxy is not replacing the certificate disable verify ssl only for testing if permitted by your organization's security policy result you have successfully authenticated the qualys vulnerability scanner connector in swimlane sources qualys api documentation https //docs qualys com/en/vm/api/ https //docs qualys com/en/vm/api/ qualys api user guide https //docs qualys com/ https //docs qualys com/ qualys platform documentation https //www qualys com/documentation/ https //www qualys com/documentation/