Configuring Qualys Credential Manager

Integrating Qualys with Strobes is a key step for automating vulnerability ingestion and management. This guide will walk you through how to securely configure your Qualys credentials using the Credential Manager within the Strobes platform.

Prerequisites

Before you begin, make sure you have:

  • An active Qualys account with valid login credentials.
  • The correct Qualys API server URL (this varies by region).
  • Admin or equivalent privileges on Strobes to access Settings > Credential Manager.

Step-by-Step Instructions

Step 1: Navigate to Credential Manager

  1. Log in to your Strobes instance.
  2. On the left-hand navigation pane, click on Settings.
  3. Select Credential Manager from the settings menu.

Step 2: Add a New Credential

  1. Click the “Add Credential” button on the top right.
  2. In the Connector Type dropdown, select Qualys.

Step 3: Fill in Qualys Configuration Details

You will see a form with the following fields:

  • Name:
    Enter a descriptive name for this configuration (e.g., Qualys Prod Connector).
  • Qualys Server URL:
    Select your Qualys server URL from the dropdown. This should match the region where your Qualys account is hosted.
     Examples:
    • https://qualysapi.qualys.com (US)
    • https://qualysapi.qualys.eu (EU)
    • https://qualysapi.qualys.in (India)
  • Username:
    Enter the Qualys username used for API access.
  • Password:
    Enter the Qualys password associated with the above username.

     Note: Ensure this account has sufficient permissions to pull vulnerability scan data.

Step 4: Save the Configuration

Once all fields are filled in:

  1. Click on the “Save” button.
  2. You will see a success message indicating that the credentials have been stored securely.

What Happens Next?

  • The credentials are encrypted and stored within the platform.
  • These credentials will now be used whenever a connector or automated workflow interacts with Qualys.
  • You can test the connection during integration setup to ensure everything is working as expected.

Tips & Best Practices

  • Avoid using personal accounts. Prefer using a dedicated Qualys API user for integrations.
  • Rotate passwords periodically and update them in Strobes to avoid disruption.
  • If your organization uses multi-factor authentication (MFA), ensure the API user is exempted or uses an alternative token mechanism.


 

Was this article helpful?