Frequently Asked Questions

Why do my vCenter scan results show Credentialed Checks: "No" even though authentication succeeded?

That is expected. When scanning vCenter-managed ESXi hosts with API credentials, the vCenter host's results always show Credentialed Checks: No. Check the ESXi hosts' results instead — Credentialed Checks: Yes there means that VIBs were collected successfully. Plugin 204872 (Integration Status) is the most direct way to confirm integration authentication.

An ESXi host shows Credentialed Checks: No. Where do I start?

Check the vCenter collection debug log (vmware_vcenter_collect.nbin~Collection_host for 7.0.3+), then run the curl tests in Testing integration connectivity from the scanner. The most common causes are failed vCenter authentication, the host not being returned as a managed ESXi host, or missing vSphere Lifecycle Manager read privileges.

Why can't I run a compliance scan and Auto-Discovery in the same scan?

Compliance scanning is unavailable when Auto-Discovery is enabled. Use two scans: one with Auto-Discovery for vulnerability coverage, and another scan (SSH or SMB) with explicit vCenter/ESXi targets for compliance.

My environment has vCenter 7.0.3 managing older ESXi hosts. Is that supported?

No. Mixed-version environments where the REST API is unavailable on some hosts are not supported. vCenter 8 managing ESXi 7.0.3 is supported.

Does the integration report on the guest operating systems of my virtual machines?

No. The VMware credentials collect management-tier data only. Add SSH or Windows credentials targeting the guest operating systems to assess them.

Why does my Auto-Discovery scan appear to scan the same host more than once?

Auto-Discovery scans should use a scanner group containing a single scanner, with a single initial host entered in the scan. With multiple scanners, targets retrieved from the integration can be scanned multiple times.