Scanning with credentials
The Credentials page is a single place to store any secure credentials runZero needs, including:
- SNMPv3 credentials
- Access secrets for cloud services like AWS and Azure
- API keys for services such as Censys and Miradore
runZero stores credentials encrypted in its database. Credentials that runZero Explorers use, such as SNMP passwords, are also encrypted in transit to the Explorers. For security reasons, the secret part of any credential can’t be viewed once entered.
When you add a credential, you can make it a global credential available to all organizations, or allow access only to specific organizations. The Allow all and Disallow all buttons apply the same setting across every organization at once, and you can also toggle access for each organization on its own.
You can edit most credential fields after saving. Some fields, like URLs, can’t be edited after saving for security reasons. Sensitive fields, such as passwords or access keys, are hidden but can be overwritten.
Credential settings
The fields and options for a credential depend on its type.
VMware and SNMP credentials, which the runZero Explorer uses, accept a CIDR allow list that limits which scanned IP addresses the credential is used with. That keeps your SNMP or VMware credentials from going to every scanned host on the network and limits them to specific IP addresses or ranges.
Credential verification
You can verify a credential when you create or edit it to confirm it authenticates. Choose Verify & save to run the verification before saving. If verification fails, runZero shows an error message and offers Save anyway, which saves the most recent verification status.
Credential management
Managing credentials takes administrator-level permissions. Users with Administrator as their default role can fully manage all credentials. Users with per-organization permissions can’t access global credentials and can manage credentials only in organizations where they hold administrator permissions. An organization administrator can’t delete a shared credential.