Configure the Delinea Secret Server Integration for Tenable Security Center
The Tenable integration with Delinea Secret Server exists as an authentication method within the SSH, Windows, and Database credentials in Tenable Security Center scan policies.
Required Permissions
To ensure that the Tenable Security Center integration with Delinea Secret Server functions correctly, you must configure all essential roles and permissions.
-
A Tenable Security Center user account with a minimum role of Standard.
-
For API access to the Delinea Secret Server, a user account assigned to the Everybody group and a minimum role of Platform User is required. This can be configured within the Access settings in the Delinea administrative console.
Scan Configuration — Windows, SSH, and Database
Complete the following steps to configure Tenable Security Center with Delinea Secret Server using Windows, SSH, or Database credentials.
-
Log in to your Tenable Security Center user interface.
-
In the left navigation pane, click Scans.
A menu appears.
-
Click Credentials.
The Credentials page appears.
-
Click +Add at the top of the screen.
The Add Credential page appears.
-
In the Windows and SSH sections, click Delinea Secret Server. For Database, select the database type within the Database section, then set Authentication Method to Delinea Secret Server on the next page.
The Delinea Secret Server Add Credential page appears.
-
In the Name box, type a name for the credential.
-
(Optional) Add a description.
-
(Optional) Add a tag to the credential.
For more information about tags, see Asset Tags in the Tenable Security Center user guide.
-
Configure each option for the selected Windows, SSH, or Database credential.
Option Description Required Delinea Secret Name The value of the secret on the Delinea server. The secret is labeled Secret Name on the Delinea server. Yes Delinea Host The Delinea Secret Server Host IP or DNS to pull the secrets from. Note: This value could also be a URL, if your system is set up to use custom URLs. Example: pam.example_dns.com/SecretServer
Yes Delinea Port The Delinea Secret Server port for API requests. By default, Tenable uses 443. Yes Delinea Authentication Method The method used for authenticating to Delinea. Options include: Platform, Credentials, or An API key. By default, Credentials is selected. Yes Delinea Login Name The username to authenticate to the Delinea server. Yes (if using Credential Authentication Method) Delinea Password The password to authenticate to the Delinea server. This is associated with the Delinea Login Name you provided. Yes (if using Credential Authentication Method) Delinea API Key The API key provided by Delinea Secret Server. Yes (if using API Key Authentication Method) Delinea Platform Host The Delinea Platform Host IP address or domain name. Yes (if using Platform Authentication Method) Delinea Service Account ID The application account for the Delinea Platform REST API. Yes (if using Platform Authentication Method) Delinea Service Account Password The password for the application account. Yes (if using Platform Authentication Method) Use Private Key (SSH-only) Use key-based authentication for SSH connections instead of password authentication. No Use SSL If enabled, Tenable Security Center uses SSL for secure communications. No Verify SSL Certificate If enabled, Tenable Security Center verifies the Delinea Secret Server SSL certificate. No Delinea Elevate Privileges with (SSH-only) The privilege escalation method you want to use to increase users' privileges after initial authentication. Multiple options for privilege escalation are supported, including su, su+sudo, and sudo. Your selection determines the specific options you must configure. Note: By default, Nothing is selected. See the Privilege Escalation section of the Dynamic Scanning page.
No -
Click Submit to save your credential.