Debug Log Reporting

Logs generated by other plugins are reported by Plugin #84239: Debugging Log Report. Debug logs for the Keeper Commander integration are written by the Tenable Nessus scanner during the scan. Debugging log report output is controlled by the debug logging settings in Tenable Nessus.

The integration writes to log files named after the credential plugin that invoked it, with "Keeper Commander" appended so the PAM-integration log lines can be distinguished from the target-authentication log lines:

  • SSH: ssh_settings.nasl~Keeper Commander

  • Windows (SMB): logins.nasl~Keeper Commander

  • Database: database_settings.nasl~Keeper Commander

What the Logs Contain

  • Configuration settings loaded from the scan policy, with sensitive values (API key, passwords, and private key material) automatically masked.

  • The query mode in use (UID or search) and the lookup value.

  • Whether a cached credential was found before any API call was made.

  • Each Keeper Commander API request — command submitted (with sensitive details hidden), HTTP response status, and for v2 async requests, the poll attempt count and each intermediate status value.

  • Whether the record was successfully parsed and which credential type (pamUser or sshKeys) was extracted.

  • Escalation credential retrieval details when privilege escalation is configured, including the escalation record UID used.

  • Any errors returned by the Keeper Commander service, including HTTP error codes and Keeper Commander-level error messages.

Common Reasons for Credentialed Checks Showing "no" Status

  • The Keeper Commander service is unreachable from the scanner because of a firewall, an incorrect Engine URL, or an incorrect port.

  • The API Key is invalid, expired, or does not have read access to the target Keeper Commander record.

  • The Keeper Commander service has lost its authenticated session to the Keeper Commander cloud. When this happens the service returns a 200 response with "data":null and a message such as "Logging in to Keeper as <email>" — the API call appears to succeed but contains no credential data. Re-authenticate on the Keeper Commander host by opening an interactive Keeper Commander shell (keeper shell) and running login <email> to re-establish the session, then restart the Keeper Commander service.

  • The record UID supplied in Credential ID does not exist in the vault, or the search term in Search Text matches no records.

  • The Keeper Commander record type does not match the selected SSH Private Key setting — for example, an sshKeys record is referenced but SSH Private Key is set to No, causing the integration to look for a password field that is not present in an sshKeys record.

  • The Keeper Commander record is missing a login field, which is required regardless of record type.

  • The Keeper Commander service exposes only the v1 API (/api/v1/executecommand). The integration requires the v2 async API endpoints.

  • SSL certificate verification fails because the Keeper Commander instance uses a self-signed certificate and Verify SSL Certificate is enabled. Either add the certificate to the scanner's trust store or disable Verify SSL Certificate.

  • The v2 async request timed out — the integration polls for up to 30 seconds. If the Keeper Commander service does not complete the command within that window, credential retrieval fails.