Qualys

AppViewX integrates with Qualys Vulnerability Management (VM) to assess your organization's readiness for post-quantum cryptography (PQC) without installing any software on your servers.

Overview

Qualys regularly scans the hosts on your network and records the results. AppViewX reads those existing scan results to build a crypto asset inventory for each host capturing the TLS protocols supported, cipher suites in use, open ports, and certificate details such as subject, issuer, expiry, and public key metadata. AppViewX does not perform any additional scanning beyond what Qualys already runs.
The PQC readiness evaluation includes:
  • Cipher suites and security protocols: Which encryption algorithms are active on each host, and whether any are vulnerable to quantum computing attacks.
  • Certificate metadata: Details about digital certificates such as algorithm type and key length, collected from SSL/TLS services.
  • Service configurations and open ports: Which network services (web servers, mail servers, databases) are running and on which ports.
  • Cryptographic libraries (limited): Partial visibility based on what Qualys detects. Coverage may vary.
This topic covers the Qualys-side prerequisites for integration: the specific checks (QIDs) that must be enabled in your Qualys scan policy, the credentials AppViewX requires, and guidance for production deployments.
Note: For AppViewX configuration and usage, see the following topics:
Important: Enable PQC evaluation: When you add the Qualys integration in AppViewX, add the QTH tag to the integration record. Without this tag, AppViewX runs certificate discovery only and does not perform any post-quantum readiness analysis.

Prerequisites

Before you configure the Qualys integration in AppViewX, confirm the following:
Qualys account and scans
  • You have an active Qualys Vulnerability Management (VMDR) subscription.
  • Qualys scans are already configured and running regularly on the hosts you want to assess. AppViewX reads scan results — it does not create or trigger Qualys scans.
  • The Qualys checks listed in QIDs Required for PQC Discovery are enabled in the scan policies applied to those hosts. These checks are on by default in standard Qualys scan templates. Verify that they have not been turned off in a custom template.
Credentials
  • A Qualys username and password that has read access to Qualys VM detection results for the assets in scope. See API Access Requirements.
Network connectivity
  • The AppViewX server can reach your Qualys API Server URL over HTTPS (port 443). The correct URL depends on the Qualys platform region your account uses. See API Access Requirements.

Existing Qualys integration in AppViewX (if applicable)

If your organization already uses AppViewX for certificate lifecycle management (CLM) with Qualys, a Qualys account entry already exists in the vendor integration settings. You extend that entry with the PQC-specific settings described in this topic the existing CLM configuration is not affected.

QIDs Required for PQC Discovery

A QID (Qualys ID) is a unique number Qualys uses to identify each type of detection check similar to a plugin in other security tools. AppViewX reads the following QIDs from your Qualys scan results to collect the cryptographic data it needs for PQC assessment.
These QIDs are enabled by default in standard Qualys scan policies. Verify that they have not been disabled in any custom scan template applied to the hosts you want to include.
QID Name What AppViewX uses it for
82023 Open TCP Services List Identifies every open TCP port and its service name on each host. AppViewX creates one assessment record per host-and-port combination.
45388 TCP Ports in Listening Mode (UNIX) Identifies listening TCP ports on Linux and UNIX hosts. Supplements QID 82023 where that check does not apply.
38116 SSL Server Information Retrieval Identifies the SSL/TLS protocol versions and cipher suites each host supports. AppViewX uses this to flag cipher suites that are vulnerable to quantum computing attacks.
38704 SSL/TLS Key Exchange Methods Identifies the key exchange algorithms in use, such as RSA, ECDH, and DHE. These are a primary indicator of quantum vulnerability.
38047 SSH Daemon Information Identifies the key exchange and host key algorithms used by SSH services, enabling PQC assessment of SSH endpoints.
48118 HTTP Response Method and Header Information Identifies the web server software on a port (for example, NGINX, Apache HTTP Server, Microsoft IIS), so AppViewX can map encryption findings to specific applications.
86990 Apache Tomcat Web Server Running on Target Identifies Apache Tomcat instances and their version for comprehensive web application coverage.
86565 Web Server Supports HTTP Request Pipelining Identifies JBoss and WildFly application servers for inclusion in the PQC assessment.
27113 FTP Server Banner Identifies FTP servers such as ProFTPD and vsftpd for TLS assessment.
74042 SMTP Banner Identifies SMTP mail servers such as Exim, Postfix, and IBM Domino for TLS assessment of email infrastructure.
50010 IMAP Banner Identifies IMAP mail services such as Dovecot and IBM Domino for TLS cipher and certificate evaluation.
50000 POP3 Banner Identifies POP3 mail retrieval services for TLS assessment.
82004 Open UDP Services List Identifies open UDP services/ports detected on the host. This helps populate UDP port/service inventory and identify UDP-based network services exposed by the host.
123815 UDP Sockets in Listening Mode Identifies UDP sockets that are in listening/bound state on the host. This provides host-level visibility into UDP sockets that are actively bound and waiting for incoming traffic.

API Access Requirements

Gather the API credentials and API Server URL required by AppViewX.

Credentials

AppViewX connects to Qualys using a username and password. The password is stored securely inside AppViewX and is never written to logs or displayed on screen.

Credential Minimum permission required
Qualys username and password Create a dedicated custom role, for example: QTH-Qualys-ReadOnly-API
The role should have:
  • API access enabled
  • VM/VMDR reader permissions
  • Certificate View module access (for CLM certificate discovery)
  • CERTVIEW API access enabled (for CLM certificate discovery)
  • Only the required asset groups and assets assigned to the user
No administrative or scanning permission needed.
Tip: Best practice: Use a dedicated Qualys service account with the minimum permissions listed above. Do not reuse an administrator account. Restrict the account's scope to only the hosts included in your PQC scan.

API Server URL

AppViewX uses the Qualys API Server URL to retrieve VM detection data. This is separate from the Gateway URL that AppViewX uses for certificate discovery (CLM module).

To find the correct API Server URL for your Qualys subscription, visit the Qualys Platform Identification page. You will enter this URL in the integration settings in AppViewX.
Qualys platform Example API Server URL
US Platform 1 (QG1) https://qualysapi.qualys.com
US Platform 2 (QG2) https://qualysapi.qg2.apps.qualys.com
US Platform 3 (QG3) https://qualysapi.qg3.apps.qualys.com
EU Platform 1 https://qualysapi.qg1.apps.qualys.eu
Note: Two URL fields in the integration settings: The Qualys integration page in AppViewX shows two URL fields:
  • Gateway URL: Used for certificate discovery (CLM module). If your team already configured Qualys for CLM, this value is already set.
  • API Server URL: Required for PQC discovery (Quantum Trust Hub). Find this value on the Qualys Platform Identification page and enter it here.

Configuration Settings

Configure the PQC-specific settings when adding or editing the Qualys integration in AppViewX.
When you add or edit the Qualys integration in AppViewX, a settings panel lets you configure PQC-specific options. The table below explains each setting.
Setting Required? Description
apiServerUrl Required The Qualys API Server URL for your subscription platform. Find this value on the Qualys Platform Identification page.
deltaSync Optional Set to true (the default) to fetch only data that changed since the last successful scan. Set to false to perform a full data refresh every time the scan runs.
assetTags Optional Limits discovery to hosts that carry specific Qualys Asset Tags. If not set, all hosts that Qualys has scanned are included. See Asset Filtering.
assetGroups Optional Limits discovery to hosts that belong to specific Qualys Asset Groups. If not set, all scanned hosts are included. See Asset Filtering.
The following example shows a complete configuration:
{
  "apiServerUrl": "https://qualysapi.qualys.com",
  "deltaSync": true,
  "assetTags": {
    "tagSetBy": "id",
    "includeTags": ["11002345", "11002678"],
    "includeSelector": "any",
    "excludeTags": ["11009911"],
    "excludeSelector": "any"
  },
  "assetGroups": {
    "includeAgIds": ["4521", "4522"],
    "includeAgTitles": [],
    "excludeAgIds": [],
    "excludeAgTitles": []
  }
}

Configure Asset Filtering

Configure asset filtering to limit PQC discovery to a specific part of your environment.

By default, AppViewX processes every host that Qualys has scanned. Asset filtering lets you narrow discovery to a specific part of your environment for example, production servers only, or a specific business unit. Two filtering options are available and can be used together.

Filter by Qualys Asset Tag
A Qualys Asset Tag is a label you assign to hosts in Qualys to organize them — for example, "Production", "Linux", or "PCI-Scope". If you configure asset tags in AppViewX, only hosts carrying matching tags are included in PQC discovery.
Option Accepted values Description
tagSetBy id or name Whether the tag values in includeTags and excludeTags are Qualys tag IDs or tag names. Defaults to id.
includeTags List of tag IDs or names Only hosts that match these tags are included in discovery.
includeSelector any or all any includes a host if it carries at least one of the listed tags (OR logic). all includes a host only if it carries every listed tag (AND logic).
excludeTags List of tag IDs or names Hosts carrying these tags are excluded from discovery.
excludeSelector any or all Applies the same OR / AND logic to the exclusion list.

Filter by Qualys Asset Group

A Qualys Asset Group is a named collection of hosts you define in Qualys for example, "Production-Servers" or "DMZ". You can include specific groups in PQC discovery.
Option Description
includeAgIds List of Qualys Asset Group IDs to include. Using IDs is recommended because they stay the same even if a group is renamed.
includeAgTitles List of Qualys Asset Group names to include. Use only when IDs are not available.

Operational Considerations

After the integration is configured and the ASM scan runs, AppViewX builds a crypto asset inventory from the Qualys detection data. The following operational considerations apply to ongoing use:

Rate limits

Qualys limits how many API requests can run at the same time, and the threshold varies by subscription tier. AppViewX automatically detects when a rate limit is reached, pauses for the required period, and then resumes no data is lost and no manual action is needed. If discovery runs are consistently slower than expected, contact your Qualys account team to confirm the concurrency allowance for your plan.

Delta sync - incremental updates

The first time you run an ASM scan with the Qualys integration, AppViewX fetches all available detection data for the assets in scope. On subsequent runs, with deltaSync set to true (the default), AppViewX fetches only the records that changed since the last successful scan. This keeps scan times short on regular runs.

Tip: Best practice: Keep deltaSync enabled for regularly scheduled scans. Disable it only when you want a complete refresh for example, after making significant changes to your Qualys scan policies or asset coverage.

AppViewX does not scan hosts

AppViewX reads existing Qualys detection data. It does not connect to your hosts directly, does not run any port scans, and does not change anything in Qualys. Your Qualys scan schedule is unaffected.

Proxy support

If your AppViewX deployment uses a network proxy to reach external services, connections to Qualys automatically use the proxy settings configured in the AppViewX platform. No separate proxy configuration is needed on the Qualys integration settings page.

Dedicated service account

Use a dedicated Qualys account with the minimum read-only permissions. Avoid reusing an administrator account, and scope the account to only the assets that are part of your PQC assessment.

What AppViewX Discovers

  • SSL/TLS protocol versions per host and port
  • Cipher suites supported by each endpoint
  • TLS key exchange algorithms (RSA, ECDH, DHE)
  • Open and listening TCP ports
  • SSH key exchange and host key algorithms
  • Application and service identification (web servers, mail servers)
  • Cryptographic library details (we discover whatever qualys library info along with associated application that we show)
  • Digital certificates (handled separately by the CLM module)