KSA Domain Migration Status for Qualys Cloud Agent

Spencer Brown

Following our earlier announcement of the introduction of KSA domain update notifications, Qualys has introduced new .sa domain endpoints to enhance regional performance and service delivery. This update provides the latest status of the Qualys Cloud Agent migration and outlines the required actions to ensure continued connectivity.

Note: This notification applies only to customers with subscriptions on the Kingdom of Saudi Arabia (KSA) platform. To identify your platform, please visit Identify your Qualys platform.

Automatic Migration Status

All supported Qualys Cloud Agents will be migrated from the legacy .com domain to the new .sa domain by July 20, 2026, in a phased rollout. Once migrated, they will communicate with the updated endpoints without requiring any customer action.

Endpoint Mapping

Old DomainNew DomainIP Address
qagpublic.qg1.apps.qualysksa.comqagpublic.qg1.apps.qualys.sa141.147.134.190
cask.qg1.apps.qualysksa.comcask.qg1.apps.qualys.sa150.230.54.51

Container-Based Platforms

Automatic migration does not apply to the following container-optimized operating systems:

  • Container-Optimized OS from Google
  • Bottlerocket
  • CoreOS

Required Action

Customers must redeploy containers using updated YAML configurations that reference the new .sa domain. Existing deployments will not transition automatically.

Availability of Updated Agent Binaries

By July 10, 2026, updated agent binaries with the new domain configuration will be available for download on the KSA pod.

Note: Cloud Agent for Windows is not platform-specific; therefore, no new binary will be released.

PlatformVersion
Linux Intel7.3.0-47
Linux ARM6.1.2-4
Mac Intel6.2.1-42
Mac M16.3.1-40
AIX6.0.0-44
BSD7.1.0-31
PPCLE3.21-9
Solaris SPARC7.1.0-21
ZLinux3.31.1-15

Important: Locally Stored Agent Binaries Require an Update

Customers deploying agents from internally stored or previously downloaded binaries should note the following:

  • These binaries are still configured to use the legacy .com domain.
  • Agents installed using these binaries will continue to connect to the legacy .com domain.
  • They will not automatically switch to the new .sa domain.

Required Action

Customers must download and deploy the latest agent binaries from the KSA platform to ensure that agents connect to the new .sa domain.

Manual Update for Agents Connecting to the Legacy .com Domain

If an agent is deployed using an older binary and continues to communicate with the legacy .com domain, customers can manually update it to point to the new endpoint. This can be done by executing the following command on the host system:

/usr/local/qualys/cloud-agent/bin/qualys-cloud-agent.shServerUri=https://qagpublic.qg1.apps.qualys.sa/CloudAgent/

This immediately switches the agent to the new .sa domain without requiring redeployment.

Timeline and Impact

  • Migration for supported Qualys Cloud Agents: July 20, 2026
  • Updated agent binaries available: July 10, 2026
  • Legacy .com domain retirement: November 30, 2027

After the retirement date, any agent still configured to use the legacy .com domain will lose connectivity.

Identifying Agents Using the Legacy Domain

Customers can identify impacted agents by using:

QID 45781 – Qualys Cloud Agent Configured with Legacy KSA .com Endpoint
Available in: VULNSIGS-2.6.622-3

Token: vulnerabilities.vulnerability.qid:45781

  • After the auto-migration is complete by July 20, 2026, validate that agents are communicating with the .sa domain using QID 45781 to identify any remaining legacy configurations.
  • Replace any locally stored binaries with the latest versions.
  • Redeploy container-based agents using updated YAML files.
  • If you have questions or need assistance, contact your TAM or Qualys Support.

Share your Comments

Comments

Your email address will not be published. Required fields are marked *