Tenable
- Certificates
- Certificates and associated metadata
- Signature algorithms
- Public key algorithms
- Key sizes
Example: A TLS certificate used by an application shows:- Certificate:
app.company.com - Signature Algorithm:
SHA256withRSA - Public Key Algorithm:
RSA - Key Size:
2048-bit
- Protocols and Cryptographic Configuration
- Security and application protocols
- Cipher suites
- Encryption algorithms
- Hashing algorithms
- Key exchange algorithms
Example: An application endpoint on port 443 is configured with:- Protocol:
TLS 1.2 - Cipher Suite:
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 - Key Exchange:
ECDHE - Authentication:
RSA - Encryption Algorithm:
AES-256-GCM - Hashing Algorithm:
SHA-384
- Cryptographic Libraries (Application-Associated)
- Cryptographic libraries and versions associated with discovered applications.
- Libraries identified only at the endpoint level without application context are not included.
Example: A server hosts applications on ports 443 and 8443. If OpenSSL is detected and associated with the application on port 443, it is displayed. If OpenSSL is detected on the server but cannot be associated with any specific application, it is not displayed.
This topic lists the Tenable-side prerequisites for the integration: the plugins that must be enabled in the Tenable scan policy, the minimum API key role and scope, and operational guidance for production deployments.
For AppViewX configuration and usage, see the following topics:
- To add the Tenable vendor integration, see Integrating Tenable IO with AppViewX or Integrating Tenable SC with AppViewX. Important: To enable PQC evaluation, add the
QTHtag on the integration. Without this tag, the integration is not evaluated for post-quantum readiness. - To run the discovery, see ASM scan ().
- To track the PQC evaluation outcome per discovery instance, use the PQC Evaluation Status column described in View discovery summary.
- To review unified results, see Configuration scan inventory.
Prerequisites
- The plugins listed in Plugins required for PQC
discovery are enabled in the Tenable scan policy. These plugins are enabled by
default in standard Tenable IO and Tenable SC configurations.Note: Verify that the plugins have not been disabled in a custom scan template.
- An API key with the role and scope listed in API key
permissions is available.Important: For Tenable SC, the organization administrator must enable Allow API Keys under .
- The AppViewX deployment can reach the Tenable IO cloud endpoint or the on-premises Tenable SC console URL configured on the vendor integration.
Plugins Required for PQC Discovery
| Plugin ID | Plugin Name | Category | Description |
|---|---|---|---|
| 277654 | TLS Supported Groups | General | Collects supported TLS key exchange groups and elliptic curves exposed by the endpoint. |
| 21643 | SSL Cipher Suites Supported | General | Collects SSL/TLS cipher suites supported by the endpoint. |
| 10863 | SSL Certificate Information | General | Retrieves X.509 certificate chain details, including issuer, subject, signature algorithm, key size, and validity period. |
| 19506 | Nessus SSL/TLS Scanner | General | Identifies supported SSL/TLS protocol versions and cipher suites negotiated |
| 22964 | SSL/TLS Certificate Information | General | Collects certificate and SSL/TLS configuration information presented by the service. |
| 10107 | HTTP Server Type and Version | Web Servers | Identifies the web server software running on the endpoint. |
| 24260 | HyperText Transfer Protocol (HTTP) Information | Web Servers | Collects HTTP response headers, server metadata, and connection information. |
| 141263 | Apache Tomcat Site Enumeration | Web Servers | Discovers sites and applications hosted on Apache Tomcat instances. |
| 142640 | Apache HTTP Server Site Enumeration | Web Servers | Enumerates virtual hosts and sites configured on Apache HTTP Server. |
| 140655 | Microsoft IIS Sites Enumeration | Web Servers | Identifies websites and bindings configured on Microsoft IIS servers. |
| 11219 | Nessus SYN Scanner | Port Scanners | Discovers open TCP ports and network-accessible services using SYN scanning. |
| 10335 | Nessus TCP Scanner | Port Scanners | Detects services running on open TCP ports through TCP connect scanning. |
| 14272 | Netstat Portscanner (SSH) | Port Scanners | Retrieves active listening ports from Linux/Unix systems using SSH. |
| 34220 | Netstat Portscanner (WMI) | Port Scanners | Retrieves active listening ports from Windows systems using WMI. |
| 10092 | FTP Server Detection | Service Detection | Detects FTP and FTPS services exposed by the endpoint. |
| 10185 | POP Server Detection | Service Detection | Identifies POP3 and POP3S mail services. |
| 10263 | SMTP Server Detection | Service Detection | Identifies SMTP and SMTPS mail services. |
| 10719 | MySQL Server Detection | Service Detection | Detects MySQL database services and listeners. |
| 11414 | IMAP Service Banner Retrieval | Service Detection | Detects IMAP and IMAPS services and retrieves service banner information. |
| 20870 | LDAP Server Detection | Service Detection | Identifies LDAP and LDAPS directory services. |
| 26024 | PostgreSQL Server Detection | Service Detection | Detects PostgreSQL database services and listeners. |
| 65914 | MongoDB Detection | Service Detection | Identifies MongoDB database services. |
| 130127 | PostgreSQL Server Installed (Windows) | Service Detection | Detects PostgreSQL installations on Windows hosts. |
API key permissions
| Tenable Product | Minimum Role | Required Permission or Scope |
|---|---|---|
| Tenable IO | Standard user with API key | Permission to invoke the vulns/export endpoint and read scan
results for the assets in scope. |
| Tenable SC | Auditor (or equivalent) with API key | Access to the Analysis endpoint and read access to the
repository or asset list in scope. Important: The organization administrator must enable Allow API
Keys under . |
Operational Considerations
- Concurrency and rate limits (Tenable IO): Vulnerability export jobs are subject
to concurrency limits and rate limits. Schedule large ASM scans to avoid
HTTP 409(duplicate export) andHTTP 429(throttled) responses. - Asset scoping: Use the
assetTagsJSON on the AppViewX vendor integration to limit the scan to a defined subset of Tenable assets. Tag-based filtering is recommended for large deployments to avoid pulling the full vulnerability dataset on every run. For the JSON template, see Tenable IO – dummy JSON template or Tenable SC – dummy JSON template. - Dedicated service account: Use a service account with the minimum role listed above instead of reusing an administrator's key. Restrict its asset or repository scope to the targets in the ASM scan.
Tenable API references:
