Qualys
Overview
- Cipher suites and security protocols: Which encryption algorithms are active on each host, and whether any are vulnerable to quantum computing attacks.
- Certificate metadata: Details about digital certificates such as algorithm type and key length, collected from SSL/TLS services.
- Service configurations and open ports: Which network services (web servers, mail servers, databases) are running and on which ports.
- Cryptographic libraries (limited): Partial visibility based on what Qualys detects. Coverage may vary.
- To add the Qualys integration in AppViewX, see Integrating Qualys with AppViewX.
- To run a scan after setup, see ASM Scan.
- To track the PQC evaluation outcome per discovery instance, use the PQC Evaluation Status column described in View discovery summary.
- To review results, see Configuration Scan Inventory.
QTH tag to the integration record. Without this tag, AppViewX runs
certificate discovery only and does not perform any post-quantum readiness analysis.
Prerequisites
- You have an active Qualys Vulnerability Management (VMDR) subscription.
- Qualys scans are already configured and running regularly on the hosts you want to assess. AppViewX reads scan results — it does not create or trigger Qualys scans.
- The Qualys checks listed in QIDs Required for PQC Discovery are enabled in the scan policies applied to those hosts. These checks are on by default in standard Qualys scan templates. Verify that they have not been turned off in a custom template.
- A Qualys username and password that has read access to Qualys VM detection results for the assets in scope. See API Access Requirements.
- The AppViewX server can reach your Qualys API Server URL over HTTPS (port 443). The correct URL depends on the Qualys platform region your account uses. See API Access Requirements.
Existing Qualys integration in AppViewX (if applicable)
If your organization already uses AppViewX for certificate lifecycle management (CLM) with Qualys, a Qualys account entry already exists in the vendor integration settings. You extend that entry with the PQC-specific settings described in this topic the existing CLM configuration is not affected.
QIDs Required for PQC Discovery
| QID | Name | What AppViewX uses it for |
|---|---|---|
| 82023 | Open TCP Services List | Identifies every open TCP port and its service name on each host. AppViewX creates one assessment record per host-and-port combination. |
| 45388 | TCP Ports in Listening Mode (UNIX) | Identifies listening TCP ports on Linux and UNIX hosts. Supplements QID 82023 where that check does not apply. |
| 38116 | SSL Server Information Retrieval | Identifies the SSL/TLS protocol versions and cipher suites each host supports. AppViewX uses this to flag cipher suites that are vulnerable to quantum computing attacks. |
| 38704 | SSL/TLS Key Exchange Methods | Identifies the key exchange algorithms in use, such as RSA, ECDH, and DHE. These are a primary indicator of quantum vulnerability. |
| 38047 | SSH Daemon Information | Identifies the key exchange and host key algorithms used by SSH services, enabling PQC assessment of SSH endpoints. |
| 48118 | HTTP Response Method and Header Information | Identifies the web server software on a port (for example, NGINX, Apache HTTP Server, Microsoft IIS), so AppViewX can map encryption findings to specific applications. |
| 86990 | Apache Tomcat Web Server Running on Target | Identifies Apache Tomcat instances and their version for comprehensive web application coverage. |
| 86565 | Web Server Supports HTTP Request Pipelining | Identifies JBoss and WildFly application servers for inclusion in the PQC assessment. |
| 27113 | FTP Server Banner | Identifies FTP servers such as ProFTPD and vsftpd for TLS assessment. |
| 74042 | SMTP Banner | Identifies SMTP mail servers such as Exim, Postfix, and IBM Domino for TLS assessment of email infrastructure. |
| 50010 | IMAP Banner | Identifies IMAP mail services such as Dovecot and IBM Domino for TLS cipher and certificate evaluation. |
| 50000 | POP3 Banner | Identifies POP3 mail retrieval services for TLS assessment. |
| 82004 | Open UDP Services List | Identifies open UDP services/ports detected on the host. This helps populate UDP port/service inventory and identify UDP-based network services exposed by the host. |
| 123815 | UDP Sockets in Listening Mode | Identifies UDP sockets that are in listening/bound state on the host. This provides host-level visibility into UDP sockets that are actively bound and waiting for incoming traffic. |
API Access Requirements
Credentials
AppViewX connects to Qualys using a username and password. The password is stored securely inside AppViewX and is never written to logs or displayed on screen.
| Credential | Minimum permission required |
|---|---|
| Qualys username and password | Create a dedicated custom role, for example:
QTH-Qualys-ReadOnly-APIThe role should have:
|
API Server URL
AppViewX uses the Qualys API Server URL to retrieve VM detection data. This is separate from the Gateway URL that AppViewX uses for certificate discovery (CLM module).
| Qualys platform | Example API Server URL |
|---|---|
| US Platform 1 (QG1) | https://qualysapi.qualys.com |
| US Platform 2 (QG2) | https://qualysapi.qg2.apps.qualys.com |
| US Platform 3 (QG3) | https://qualysapi.qg3.apps.qualys.com |
| EU Platform 1 | https://qualysapi.qg1.apps.qualys.eu |
- Gateway URL: Used for certificate discovery (CLM module). If your team already configured Qualys for CLM, this value is already set.
- API Server URL: Required for PQC discovery (Quantum Trust Hub). Find this value on the Qualys Platform Identification page and enter it here.
Configuration Settings
| Setting | Required? | Description |
|---|---|---|
apiServerUrl |
Required | The Qualys API Server URL for your subscription platform. Find this value on the Qualys Platform Identification page. |
deltaSync |
Optional | Set to true (the default) to fetch only data that changed
since the last successful scan. Set to false to perform a full
data refresh every time the scan runs. |
assetTags |
Optional | Limits discovery to hosts that carry specific Qualys Asset Tags. If not set, all hosts that Qualys has scanned are included. See Asset Filtering. |
assetGroups |
Optional | Limits discovery to hosts that belong to specific Qualys Asset Groups. If not set, all scanned hosts are included. See Asset Filtering. |
{
"apiServerUrl": "https://qualysapi.qualys.com",
"deltaSync": true,
"assetTags": {
"tagSetBy": "id",
"includeTags": ["11002345", "11002678"],
"includeSelector": "any",
"excludeTags": ["11009911"],
"excludeSelector": "any"
},
"assetGroups": {
"includeAgIds": ["4521", "4522"],
"includeAgTitles": [],
"excludeAgIds": [],
"excludeAgTitles": []
}
}Configure Asset Filtering
By default, AppViewX processes every host that Qualys has scanned. Asset filtering lets you narrow discovery to a specific part of your environment for example, production servers only, or a specific business unit. Two filtering options are available and can be used together.
| Option | Accepted values | Description |
|---|---|---|
tagSetBy |
id or name |
Whether the tag values in includeTags and
excludeTags are Qualys tag IDs or tag names. Defaults to
id. |
includeTags |
List of tag IDs or names | Only hosts that match these tags are included in discovery. |
includeSelector |
any or all |
any includes a host if it carries at least one of the
listed tags (OR logic). all includes a host only if it
carries every listed tag (AND logic). |
excludeTags |
List of tag IDs or names | Hosts carrying these tags are excluded from discovery. |
excludeSelector |
any or all |
Applies the same OR / AND logic to the exclusion list. |
Filter by Qualys Asset Group
| Option | Description |
|---|---|
includeAgIds |
List of Qualys Asset Group IDs to include. Using IDs is recommended because they stay the same even if a group is renamed. |
includeAgTitles |
List of Qualys Asset Group names to include. Use only when IDs are not available. |
Operational Considerations
Rate limits
Qualys limits how many API requests can run at the same time, and the threshold varies by subscription tier. AppViewX automatically detects when a rate limit is reached, pauses for the required period, and then resumes no data is lost and no manual action is needed. If discovery runs are consistently slower than expected, contact your Qualys account team to confirm the concurrency allowance for your plan.
Delta sync - incremental updates
The first time you run an ASM scan with the Qualys integration, AppViewX fetches all
available detection data for the assets in scope. On subsequent runs, with
deltaSync set to true (the default), AppViewX
fetches only the records that changed since the last successful scan. This keeps scan
times short on regular runs.
deltaSync enabled for regularly scheduled
scans. Disable it only when you want a complete refresh for example, after making
significant changes to your Qualys scan policies or asset coverage. AppViewX does not scan hosts
AppViewX reads existing Qualys detection data. It does not connect to your hosts directly, does not run any port scans, and does not change anything in Qualys. Your Qualys scan schedule is unaffected.
Proxy support
If your AppViewX deployment uses a network proxy to reach external services, connections to Qualys automatically use the proxy settings configured in the AppViewX platform. No separate proxy configuration is needed on the Qualys integration settings page.
Dedicated service account
Use a dedicated Qualys account with the minimum read-only permissions. Avoid reusing an administrator account, and scope the account to only the assets that are part of your PQC assessment.
What AppViewX Discovers
- SSL/TLS protocol versions per host and port
- Cipher suites supported by each endpoint
- TLS key exchange algorithms (RSA, ECDH, DHE)
- Open and listening TCP ports
- SSH key exchange and host key algorithms
- Application and service identification (web servers, mail servers)
- Cryptographic library details (we discover whatever qualys library info along with associated application that we show)
- Digital certificates (handled separately by the CLM module)
