How do I manage multiple authentication credentials in a scan profile?
This article describes how to add, reuse, edit, and remove authentication credentials for Linux/Unix and Windows within a scan profile. A single profile can hold multiple credentials for the same operating system, so you can cover assets with different authentication requirements without maintaining separate profiles.
Add a new credential
- Log in to Security Center.
- In the main navigation bar, click Assessments > Profiles.
- Create a new network scan profile, or select an existing one to edit.
- In the profile menu, click Authentication.
- Under Linux/Unix auth or Windows auth, click Add credentials.
- Click New to create a credential, or select an existing authentication record to reuse it.
- Enter a Record name to identify the credential.
- Enter the Port to be used for authentication. Otherwise, the standard port 22 is used for Linux/Unix.
- Select an Authentication method:
- Password. Requires password authentication to be turned on for the SSH service.
- Private key. Requires an SSH-authorized RSA private key.
- BeyondTrust PasswordSafe. Retrieves credentials directly from your BeyondTrust integration.
- Enter the credentials required for the method you selected.
- Click Save changes.
- Done!
Tip: Credential encryption
All credentials are encrypted. Read more about how credentials are protected:
How are we protecting your scan credentials?
Edit or discard changes to a credential
- Open the scan profile and click Authentication.
- Select the credential record you want to edit.
- Update the fields as needed.
- Click Save changes to apply the update, or Discard changes to cancel.
Remove a credential
- Open the scan profile and click Authentication.
- Select the credential record you want to remove.
- Click Delete permanently.
Caution: Deleting a credential
Deleting a credential removes it permanently. If the credential is used in other scan profiles, those profiles will lose access to it.
Additional links
For more information about setting up authentication in a scan profile:
How do I set up authenticated scanning?
For more information about connecting BeyondTrust: Which integrations are supported?