Configure Windows Integration

To integrate with Windows:

  1. Log in to Tenable.io.
  2. In the upper-left corner, click the button.

    The left navigation plane appears.

  3. In the left navigation plane, click Settings.

    The Settings page appears.

  4. Click the Credentials widget.

    The Credentials page appears. The credentials table lists the managed credentials you have permission to view.

  5. Click the button next to the Credentials title.

    The credential form plane appears.

  1. In the Host section, click Windows.

    The selected credential options appear.

  2. In the Authentication Method drop-down, select Lieberman.

    The Lieberman options appear.

  3. Configure the Lieberman credentials.

    Option Description Required
    Username The target system’s username.

    yes

    Domain The domain, if the username is part of a domain.

    no

    Lieberman host

    The Lieberman IP/DNS address.

    Note: If your Lieberman installation is in a subdirectory, you must include the subdirectory path. For example, type IP address or hostname / subdirectory path.

    yes

    Lieberman port The port on which Lieberman listens.

    yes

    Lieberman API URL The URL Tenable.io uses to access Lieberman. no
    Lieberman user The Lieberman explicit user for authenticating to the Lieberman RED API.

    yes

    Lieberman password The password for the Lieberman explicit user.

    yes

    Lieberman Authenticator

    The alias used for the authenticator in Lieberman. The name should match the name used in Lieberman.

    Note: If you use this option, append a domain to the Lieberman user option, i.e., domain\user.

    no
    Lieberman Client Certificate

    The file that contains the PEM certificate used to communicate with the Lieberman host.

    Note: If you use this option, you do not have to enter information in the Lieberman user, Lieberman password, and Lieberman Authenticator fields.

    no
    Lieberman Client Certificate Private Key The file that contains the PEM private key for the client certificate. no
    Lieberman Client Certificate Private Key Passphrase The passphrase for the private key, if required. no
    Use SSL

    If Lieberman is configured to support SSL through IIS, check for secure communication.

    no

    Verify SSL Certificate

    If Lieberman is configured to support SSL through IIS and you want to validate the certificate, check this. Refer to custom_CA.inc documentation for how to use self-signed certificates.

    no

    System Name In the rare case your organization uses one default Lieberman entry for all managed systems, enter the default entry name.

    no

  1. Click Save.
  2. To verify the integration works, click the Launch button to initiate an on-demand scan.

  3. Once the scan has completed, select the completed scan and look for the corresponding message - Microsoft Windows SMB Log In Possible: 10394. This validates that authentication was successful.