Scan Results Review
Plugin Families and Plugins
Depending on the credential being used, the following Tenable plugins are relevant when reviewing scan results with the ARCON PAM integration.
Misc. plugin family:
-
Plugin #204872: Integration Status: When using one of the Tenable platform integrations with any PAM Integration, the Integration Status plugin confirms whether credential(s) retrieval was a success or failure.
Settings plugin family:
-
Plugin #14273: SSH Settings: Reads the SSH PAM credential configuration and calls the ARCON PAM integration to retrieve credentials for SSH targets. This plugin is not indicative of authentication issues by itself; authentication failures are reported by the credential status plugins below.
-
Plugin #10870: Login configurations: Reads Windows (SMB) credential configuration and calls the ARCON PAM integration to retrieve credentials for Windows targets.
-
Plugin #33815: Database settings: Reads database credential configuration and calls the ARCON PAM integration to retrieve credentials for database targets.
-
Plugin #57400: VMware vSphere installed VIBs: This plugin reports the installed VIBs collected on a ESXi host after authentication.
-
Plugin #160185: Nutanix Data Collection: Reports the collections of all data from Nutanix PC using REST APIs.
-
Plugin #19506: Nessus Scan Information: Reports metadata about the scan including whether credentialed checks were successful. Check this plugin result first when investigating authentication issues.
-
Plugin #141118: Target Credential Status by Authentication Protocol - Valid Credentials Provided: Confirms credential validity by successfully authenticating to the remote target via the available protocol. This plugin confirms that credentials sourced from ARCON PAM are valid for the authentication process. Expect to see "Proto: SMB" or "Proto: SSH" in the output.
-
Plugin #110095: Target Credential Issues by Authentication Protocol - No Issues Found: Indicates that credentials were provided and authentication succeeded for all targeted protocols. A result from this plugin confirms that the ARCON PAM integration returned credentials and the scanner successfully authenticated. When escalation has failed or you have elected to not use escalation, you may see "Plugin #110385: Target Credential Issues by Authentication Protocol - Insufficient Privilege."
-
Plugin #104410: Target Credential Status by Authentication Protocol - Failure for Provided Credentials: Indicates that credentials were provided but authentication to the target failed. This may indicate that the credentials retrieved from ARCON PAM are incorrect or do not have sufficient permissions on the target host.
-
Plugin #110723: Target Credential Status by Authentication Protocol - No Credentials Provided: Indicates that no credentials were available for the targeted protocol. If this appears when the ARCON PAM credential is configured, it means that the integration likely failed to retrieve the secret.
-
Plugin #117885: Target Credential Issues by Authentication Protocol - Intermittent Authentication Failure: Indicates that authentication succeeded for some targets but not others, which may point to per-target credential differences or intermittent ARCON PAM connectivity issues.
-
Plugin #91822: Database Authentication Failure(s) for Provided Credentials: Indicates that the database credentials retrieved from ARCON PAM could not authenticate to the target database. Check the Credential ID and that the secret contains a valid username and password for the target database.