Configure the Delinea Secret Server Integration for Tenable Nessus
The Tenable integration with Delinea Secret Server exists as an authentication method within the SSH, Windows, Database, VMware ESXi SOAP API, VMware vCenter API, and Nutanix credentials in Tenable Nessus scan policies.
Required Permissions
To ensure that the Tenable Nessus and the Delinea Secret Server integration functions correctly, you must configure all essential roles and permissions.
-
A Tenable Nessus user account with a minimum role of Standard.
-
For API access to the Delinea Secret Server, a user account assigned to the Everybody group and a minimum role of Platform User is required. This can be configured within the Access settings in the Delinea administrative console.
Scan Configuration — Windows, SSH, Database, VMware, and Nutanix
Complete the following steps to configure Tenable Nessus with the Delinea Secret Server integration using the Windows, SSH, or Database credentials.
-
Log in to your Tenable Nessus user interface.
-
In the left navigation pane, click Scans.
The Scans page appears.
-
In the upper-right corner of the page, click the Create a Scan button.
The Select a Scan Template page appears.
-
Select a scan template.
The scan configuration page appears.
-
In the Name box, type a name for the scan.
-
In the Targets box, type an IP address, hostname, or range of IP addresses.
-
(Optional) Add a description, folder location, scanner location, and specify target groups.
-
Click the Credentials tab.
The Credentials pane appears.
-
In the Select a Credential menu, select Windows, SSH, Database, VMware ESXi SOAP API, VMware vCenter API, or Nutanix from the options.
The Settings pane for the selected credential appears.
-
In the Auth Type drop-down box, click Delinea Secret Server.
The Delinea Secret Server options appear.
-
Configure each option for the selected Windows, SSH, Database, VMware, or Nutanix credential.
Option Description Required Delinea Secret Name The value of the secret on the Delinea server. The secret is labeled Secret Name on the Delinea server. Yes Delinea Host The Delinea Secret Server Host IP or DNS to pull the secrets from. Note: This value could also be a URL, if your system is set up to use custom URLs. Example: pam.example_dns.com/SecretServer
Yes Delinea Port The Delinea Secret Server port for API requests. By default, Tenable uses 443. Yes Delinea Authentication Method The method used for authenticating to Delinea. Options include: Platform, Credentials, or An API key. By default, Credentials is selected. Yes Delinea Login Name The username to authenticate to the Delinea server. Yes (if using Credential Authentication Method) Delinea Password The password to authenticate to the Delinea server. This is associated with the Delinea Login Name you provided. Yes (if using Credential Authentication Method) Delinea API Key The API key provided by Delinea Secret Server. Yes (if using API Key Authentication Method) Delinea Platform Host The Delinea Platform Host IP address or domain name. Yes (if using Platform Authentication Method) Delinea Service Account ID The application account for the Delinea Platform REST API. Yes (if using Platform Authentication Method) Delinea Service Account Password The password for the application account. Yes (if using Platform Authentication Method) Use Private Key (SSH-only) Use key-based authentication for SSH connections instead of password authentication. No Use SSL If enabled, Tenable Nessus uses SSL for secure communications. No Verify SSL Certificate If enabled, Tenable Nessus verifies the Delinea Secret Server SSL certificate. No Delinea Elevate Privileges with (SSH-only) The privilege escalation method you want to use to increase users' privileges after initial authentication. Multiple options for privilege escalation are supported, including su, su+sudo, and sudo. Your selection determines the specific options you must configure. Note: By default, Nothing is selected. See the Privilege Escalation section of the Dynamic Scanning page.
No -
Do one of the following:
-
If you want to save without launching the scan, click Save.
-
If you want to save and launch the scan immediately, click Save & Launch.
Note: If you scheduled the scan to run at a later time, the Save & Launch option is not available.
-