Additional Information

Helpful tips

  • Tenable One Vulnerability Management or Tenable Security Center passes the policy and credential values down to Tenable Nessus. These values include the Keeper Commander Engine URL, API Key, Query Mode, and Credential ID or Search Text.

  • The Tenable Nessus scanner communicates directly with the Keeper Commander service API, and the service returns the username and password (or SSH private key) required for target authentication.

  • The scanner then uses those values for target authentication.

  • When using Search string mode, make record titles specific enough that the first search result is always the intended record. If titles are ambiguous, switch to Record UID mode to retrieve the record unambiguously.

  • The integration caches credentials per record UID (or search term) for the duration of the scan. If a record is rotated mid-scan, the cached pre-rotation credential is used for the remainder of that scan.

Testing integration connectivity

You can use curl from the Tenable Nessus scanner host to verify connectivity to the Keeper Commander service and test the v2 async API flow before running a scan. The following commands mirror the three API calls the integration makes for each credential retrieval:

  1. Submit the command:

    Copy
    ENGINE_URL="https://commander.internal:8080"
    API_KEY="<your-api-key>"
    RECORD_UID="<keeper-record-uid>"

    curl -sS -X POST "${ENGINE_URL}/api/v2/executecommand-async" \
      -H "Content-Type: application/json" \
      -H "api-key: ${API_KEY}" \
      -d "{\"command\": \"get ${RECORD_UID} --unmask --format json\"}"

    A successful response contains a request_id field. A 401 response indicates an invalid API key.

  2. Step 2 — poll for completion:

    Copy
    REQUEST_ID="<request_id from step 1>"

    curl -sS "${ENGINE_URL}/api/v2/status/${REQUEST_ID}" \
      -H "api-key: ${API_KEY}"

    Repeat until the status field is completed, failed, or expired. The integration polls once per second for up to 30 seconds.

  3. Step 3 — fetch the result:

    Copy
    curl -sS "${ENGINE_URL}/api/v2/result/${REQUEST_ID}" \
      -H "api-key: ${API_KEY}"

    A successful response contains a data object with record_uid and a fields array. Verify that a login field and either a password or keyPair field are present and non-empty.

To test the v1 synchronous endpoint on an older Keeper Commander deployment, use a single POST:

Copy
curl -sS -X POST "${ENGINE_URL}/api/v1/executecommand" \
  -H "Content-Type: application/json" \
  -H "api-key: ${API_KEY}" \
  -d "{\"command\": \"get ${RECORD_UID} --unmask --format json\"}"

If this returns a result directly (without a request_id), the deployment supports v1 only and the Tenable integration does not work until the Keeper Commander service is upgraded to support the v2 async API.