Qualys Enterprise TruRisk™ Platform (VM Release 10.39.2) API Notification 

Anushka Damle

A new release of Qualys Enterprise TruRisk™ Platform (VM Release 10.39.2), which is released in August 2026, includes updates to existing APIs. This API notification highlights recently released changes, enabling you to identify use cases that can benefit from the updated APIs. 

What’s New?

Scan Authentication API: AD Secrets Engine Support for Unix/SSH Root Delegation 

POST, GET  /api/4.0/fo/auth/unix 

DTD or XSD changes: Yes 

You can now use the HashiCorp Vault Active Directory (AD) Secrets Engine when configuring Unix/SSH root delegation through the Unix authentication API. Previously, Unix/SSH root delegation did not support AD Secrets Engine integration, which prevented you from retrieving root tool passwords using AD-managed secrets through the API. This enhancement extends AD Secrets Engine support to Unix/SSH root delegation and provides a consistent experience across supported authentication types. 

  • You can use the USE_AD_HASHICORP parameter to indicate that passwords should be retrieved from the HashiCorp AD Secrets Engine. 
  • A key-value secret key (SECRET_KV_KEY) is no longer required for password retrieval when USE_AD_HASHICORP is set to 1. 
  • API responses now include the <VAULT_USE_AD_HASHICORP> element for Unix/SSH authentication records configured to use a HashiCorp vault with AD Secrets Engine enabled. 

Cloud Perimeter Scan Support for Oracle Cloud Infrastructure

POST, GET  /api/4.0/fo/scan/cloud/perimeter/job/, /api/6.0/fo/asset/host/, /api/6.0/fo/asset/host/vm/detection/ 

DTD or XSD changes: Yes

You can now launch Cloud Perimeter Scans for Oracle Cloud Infrastructure (OCI) assets and retrieve OCI-specific asset metadata through supported APIs. Previously, Cloud Perimeter Scan and cloud asset visibility were available for AWS, Azure, and GCP environments only. This enhancement extends API support to OCI, enabling you to discover, scan, and track OCI assets using existing Qualys workflows. This helps you retrieve OCI cloud asset details for improved asset tracking and inventory management, and to automate vulnerability assessment of publicly exposed OCI resources through the Cloud Perimeter Scan API. 

  • The Host List API response now includes OCI cloud asset information for tracked OCI assets, including CLOUD_PROVIDER, CLOUD_SERVICE, and CLOUD_RESOURCE_ID. 
  • The Host Detection API now includes OCI cloud perimeter metadata for supported API versions, enabling you to identify and assess OCI assets discovered through Cloud Perimeter Scans. 

Extended Password Length Support for Unix/SSH Authentication Records 

POST  /api/2.0/fo/auth/unix, /api/3.0/fo/auth/unix, /api/4.0/fo/auth/unix 

DTD or XSD changes: No

You can now create and update Unix/SSH authentication records using passwords up to 200 characters long using the Unix authentication APIs. Previously, the maximum supported password length was 100 characters, which could prevent you from using authentication credentials that met your organization’s password requirements. This enhancement increases the supported password length for Unix/SSH authentication records only, while maintaining existing behavior for other authentication types, helping you align authentication record configuration with enterprise password policies. 

For more details, please refer to the release notes here: https://docs.qualys.com/en/vm/release-notes/qweb/release_10_39_2_api.htm

 

Share your Comments

Comments

Your email address will not be published. Required fields are marked *