Skip navigation
1 2 3 Previous Next

API Notifications

72 Posts authored by: Jeff Leggett Employee

A new release of Qualys Cloud Platform v8.21.2 (VM/PC) includes an updated API which is targeted for release in September 2019. The specific day will differ depending on the platform. See platform release dates on the Qualys Status page. This API notification provides an early preview into the coming API, allowing you to identify use cases that can leverage this updated API.


What’s New
IBM WebSphere App Server and JBoss Server: Instance Discovery, Auto Record Creation and more
/api/2.0/fo/auth/unix/
/api/2.0/fo/auth/windows/
Instance discovery and auto record creation is now supported for IBM WebSphere App Server/JBoss Server (UI and API). As before a single IBM WebSphere/JBoss record may be used when the same record configuration is replicated across hosts in the record.

 

Compliance Posture API: Parameters added to show fail/pass dates for controls
/api/2.0/fo/subscription/option_profile/pc/
We have added 5 new parameters to the Compliance Posture API to show you the following information in the posture information output: 1) for failed controls, the first and last failed dates. 2) for passed controls, the first and last passed dates and 3) previous posture status (failed/passed) for a control.

A new release of Qualys Cloud Platform v8.21 (VM/PC) includes an updated API which is targeted for release in August 2019. The specific day will differ depending on the platform. See platform release dates on the Qualys Status page. This API notification provides an early preview into the coming API, allowing you to identify use cases that can leverage this updated API.


What’s New
API Support for New Vault Types for Cisco and Checkpoint
/api/2.0/fo/auth/unix/
We now support few more vault types as part of authentication record settings for Unix Subtypes: Cisco and Checkpoint Firewall. Newly supported vault types for Cisco authentication records are Azure Key and HashiCorp vaults and newly supported vault type for Checkpoint Firewall is HashiCorp vault. These vaults are already supported for these authentication types in the UI.

A new release of Qualys Cloud Platform v2.40 (WAS) includes an updated API which is targeted for release in August 2019. The specific day will differ depending on the platform. See platform release dates on the Qualys Status page. This API notification provides an early preview into the coming API, allowing you to identify use cases that can leverage this updated API.


What’s New
WAS API: Option to choose all Detections in Option Profile
/qps/rest/3.0/get/was/optionprofile/<id>
/qps/rest/3.0/create/was/optionprofile
/qps/rest/3.0/update/was/optionprofile/<id>
You can now configure the option profile for you scan so that it could include all the WAS related detections. We have now introduced a new option named "Everything" for detection scope of Option Profile that includes every WAS related detection during the scan.

 

WAS API: Unique ID for Findings
/qps/rest/3.0/get/was/finding/<id>
/qps/rest/3.0/search/was/finding
/qps/rest/3.0/count/was/finding
/qps/rest/3.0/ignore/was/finding
/qps/rest/3.0/activate/was/finding
/qps/rest/3.0/editSeverity/was/finding
/qps/rest/3.0/restoreSeverity/was/finding
/qps/rest/3.0/retest/was/finding
We have now introduced 36-bit unique ID (uniqueId) for each finding. The ID would be unique for every finding. Earlier, the combination of three fields namely: finding ID, finding type and finding category would make a finding unique. Now, with the implementation of uniqueId, you can easily distinguish every finding

A new release of Qualys Cloud Platform v2.39 (WAS/AM) includes an updated API which is targeted for release in June 2019. The specific day will differ depending on the platform. See platform release dates on the Qualys Status page. This API notification provides an early preview into the coming API, allowing you to identify use cases that can leverage this updated API.


What’s New
Web Application Scanning API: Enhanced Crawling
/qps/rest/3.0/get/was/optionprofile/<id>
/qps/rest/3.0/create/was/optionprofile
/qps/rest/3.0/update/was/optionprofile/<id>
You can now enable enhanced crawling in your option profile for your scans to improve scan coverage for your web application. With the enhanced crawling enabled, more links can be crawled and will improve scan coverage. We will re-crawl individual directories present in the links which are found during crawling.

 

Asset Management & Tagging API: Search host assets using IBM attributes
/qps/rest/2.0/search/am/hostasset
The Asset Management and Tagging API has been updated to allow searching host assets using IBM attributes.

 

Asset Management & Tagging API: New API for Azure Asset Data Connector

/qps/rest/2.0/create/am/azureassetdataconnector
/qps/rest/2.0/update/am/azureassetdataconnector
/qps/rest/2.0/delete/am/azureassetdataconnector/<id>
/qps/rest/2.0/get/am/azureassetdataconnector
/qps/rest/2.0/search/am/awsassetdataconnector
We have now introduced new API for Azure connectors. You can create, update, delete or view the list of Azure connectors.

A new release of Qualys Cloud Platform v8.20 (VM,PC) includes an updated API which is targeted for release in June 2019. The specific day will differ depending on the platform. See platform release dates on the Qualys Status page. This API notification provides an early preview into the coming API, allowing you to identify use cases that can leverage this updated API.


What’s New
New Database UDCs for Oracle and MSSQL
With this release you can now create custom controls for Oracle database and MSSQL database. To support database controls, we’ve added new elements to the XML output and DTDs for Control List Output, Policy Export Output, Posture Info List Output, and the ImportableControl.xsd schema.

 

Control List Output - DTD Change
The Control List Output DTD is used to view the list of compliance controls which are visible in your account.

 

Policy Export Output - DTD Change
The Policy Export Output DTD is used to export compliance policies from your account to an XML file.

 

Subscription API: Import/Export Email Notification Settings for Password Expiry
We have updated the Export Subscription Configurations API output to include configuration settings for password expiry notification emails in the “USERS” element. New settings indicate whether users in the subscription will be notified by email before their password expires, how often password expiration emails will be sent and when to switch to daily emails

 

Subscription API - Import/Export Session Timeout Settings for User Roles
We updated the Export Subscription Configurations API output to include session timeout settings by user role. New settings indicate whether the option to customize session timeout by user role is enabled and the session timeout value for each role. The session timeout setting is configured under Users > Setup > Security in the UI. Note that not all user roles are available in all subscriptions.

A new release of Qualys Cloud Platform v8.20 (VM,PC) includes an updated API which is targeted for release in June 2019. The specific day will differ depending on the platform. See platform release dates on the Qualys Status page. This API notification provides an early preview into the coming API, allowing you to identify use cases that can leverage this updated API.


What’s New
New Database UDCs for Oracle and MSSQL
With this release you can now create custom controls for Oracle database and MSSQL database. To support database controls, we’ve added new elements to the XML output and DTDs for Control List Output, Policy Export Output, Posture Info List Output, and the ImportableControl.xsd schema.

 

Subscription API: Import/Export Email Notification Settings for Password Expiry
We have updated the Export Subscription Configurations API output to include configuration settings for password expiry notification emails in the “USERS” element. New settings indicate whether users in the subscription will be notified by email before their password expires, how often password expiration emails will be sent and when to switch to daily emails

A new release of Qualys Cloud Platform v8.19 (VM,PC) includes an updated API which is targeted for release in May 2019. The specific day will differ depending on the platform. See platform release dates on the Qualys Status page. This API notification provides an early preview into the coming API, allowing you to identify use cases that can leverage this updated API.


What’s New
Sybase Authentication - Password Encryption and Auto Discover Databases
/api/2.0/fo/auth/sybase/
This release introduces 2 new options for Sybase authentication - Password Encryption and Auto Discover Databases.

Password Encryption - Enable this option when your Sybase database instance requires an encrypted password for successful login. If password encryption is required and you do not enable this option then authentication will fail.

Auto Discover Databases - Enable this option and we'll find all Sybase database names on each host for you. This means you no longer have to create a separate Sybase record for each database name. Create one record with Auto Discover Databases enabled to authenticate to multiple databases on the same host.

 

PC - New MS Exchange Server Authentication API
/api/2.0/fo/auth/
Microsoft Exchange Server authentication is now supported for compliance scans. The new MS Exchange Server Authentication API (api/2.0/fo/auth/ms_exchange/) lets you list, create, update and delete MS Exchange Server authentication records. User permissions for this API are the same as other authentication record APIs. Note that the API supports authentication record creation only for MS Exchange Server installed on Windows.

 

New Support for Microsoft Azure Key Vault
/api/2.0/fo/auth/windows/
/api/2.0/fo/auth/unix/
/api/2.0/fo/auth/ms_sql/
/api/2.0/fo/auth/mysql/
/api/2.0/fo/auth/mariadb/
/api/2.0/fo/auth/mongodb/
/api/2.0/fo/auth/oracle/
/api/2.0/fo/auth/postgresql/
This new vault type can be used to retrieve authentication credentials from an Azure key vault. We updated the authentication vault API (create, update, list, view) and the authentication record API (create, update, list) to support the new vault type.

A new release of Qualys Cloud Platform v8.19 (VM,PC) includes an updated API which is targeted for release in April 2019. The specific day will differ depending on the platform. See platform release dates on the Qualys Status page. This API notification provides an early preview into the coming API, allowing you to identify use cases that can leverage this updated API.


What’s New
Sybase Authentication - Password Encryption and Auto Discover Databases
/api/2.0/fo/auth/sybase/
This release introduces 2 new options for Sybase authentication - Password Encryption and Auto Discover Databases.

Password Encryption - Enable this option when your Sybase database instance requires an encrypted password for successful login. If password encryption is required and you do not enable this option then authentication will fail.

Auto Discover Databases - Enable this option and we'll find all Sybase database names on each host for you. This means you no longer have to create a separate Sybase record for each database name. Create one record with Auto Discover Databases enabled to authenticate to multiple databases on the same host.

 

PC - New MS Exchange Server Authentication API
/api/2.0/fo/auth/
Microsoft Exchange Server authentication is now supported for compliance scans. The new MS Exchange Server Authentication API (api/2.0/fo/auth/ms_exchange/) lets you list, create, update and delete MS Exchange Server authentication records. User permissions for this API are the same as other authentication record APIs. Note that the API supports authentication record creation only for MS Exchange Server installed on Windows.

A new release of Qualys Cloud Platform v2.38 (WAS) includes an updated API which is targeted for release in April 2019. The specific day will differ depending on the platform. See platform release dates on the Qualys Status page. This API notification provides an early preview into the coming API, allowing you to identify use cases that can leverage this updated API.


What’s New
WAS API: Enhancements to Finding API response

/qps/rest/3.0/get/was/finding/<id>/

/qps/rest/3.0/search/was/finding
We have now improved the response for Finding API to include following details:
-the tags associated with the web application on which the finding was detected.
-details related to ignored finding

A new release of Qualys Cloud Platform v1.8 (Cloudview) includes an updated API which is targeted for release in April 2019. The specific day will differ depending on the platform. See platform release dates on the Qualys Status page. This API notification provides an early preview into the coming API, allowing you to identify use cases that can leverage this updated API.


What’s New
CloudView API URLs updated
With the CloudView 1.8, the URLs for all the CLoudView REST APIs are updated. The API URLs that currently use 1.5 will be replaced with v1 across all the CloudView API URLs. Additionally, we have also updated the "lastsynch" to "lastSyncedOn" in the response.

 

AWS API Updates
We have now added a new element named isPortalConnector. The new element is a boolean flag to indicate whether the AWS connector is also created in Portal module or not (Asset View). If not, you can set this element to true and automatically create the same connector in AssetView module. However, if the connector is created in AssetView as well, then the authentication information associated with the connector is linked to CloudView as well. If you update the authentication information for the connector in AssetView, it will automatically reflect in CloudView as well.

 

Azure APIs (New)
We have now introduced APIs for your Azure Connectors. We support the following operations and evaluations for your Azure Connector:
Get list of connectors
Get the details of Azure connector
Create a new Azure connector
Run the specified Azure connector
Update the existing Azure connector
Delete the Azure connectors
Azure Evaluations

 

GCP APIs (New)
We support the following operations for GCP Connector:
Get list of GCP connectors
Get the details of a specified GCP connector
Create a new GCP connector
Run the specified GCP connector
Update the existing GCP connector
Delete the specified GCP connectors
GCP Evaluations

 

Reports API (New)
We support the following operations for Reports API:
Get list of report configurations
Get list of all supported mandates
Get list of all supported policies
Get the complete data of the specified report
Get the details of specified report configuration
Create a new report configuration
Update the existing report configurations
Delete the provided report configurations

A new release of Qualys Cloud Suite QWEB 8.18.1 (VM/PC) includes an updated API which is targeted for release in April 2019. The specific day will differ depending on the platform. See platform release dates on the Qualys Status page. This API notification provides an early preview into the coming API, allowing you to identify use cases that can leverage this updated API.

 

What’s New
New Support for HashiCorp Vault
/api/2.0/fo/vault
/api/2.0/fo/auth/windows/
/api/2.0/fo/auth/unix/
This new vault type can be used to retrieve authentication credentials from a HashiCorp vault. We updated the authentication vault API (create, update, list, view) and the authentication record API (create, update, list) to support the new vault type. We updated the DTDs for listing Windows and Unix record.

 

Option Profile API - DTD/XSD Change
We added VAULT_SECRET_KV_PATH?, VAULT_SECRET_KV_NAME?, VAULT_SECRET_KV_KEY to the Windows and Unix Authentication List Output DTDs. The Cisco authentication record uses Unix Authentication List Output DTD.

A new release of Qualys Cloud Suite v2.37.1 (AM) includes an updated API which is targeted for release in April 2019. The specific day will differ depending on the platform. See platform release dates on the Qualys Status page. This API notification provides an early preview into the coming API, allowing you to identify use cases that can leverage this updated API.

 

What’s New
Asset Management and Tagging API: Enable connector for CloudView
/qps/rest/2.0/create/am/awsassetdataconnector/
/qps/rest/2.0/update/am/awsassetdataconnector/
/qps/rest/2.0/get/am/awsassetdataconnector/
/qps/rest/2.0/search/am/awsassetdataconnector/

The Asset Management and Tagging API has been updated to provide a new parameter for enabling an AWS connector for CloudView. While creating a new connector or editing an existing connector, you can enable that AWS connector to make it available in the CloudView App as well.

A new release of Qualys Cloud Suite 8.18 (VM/PC) includes an updated API which is targeted for release in March 2019. The specific day will differ depending on the platform. See platform release dates on the Qualys Status page. This API notification provides an early preview into the coming API, allowing you to identify use cases that can leverage this updated API.

 

What's new
New InformixDB Auth records /api/2.0/fo/auth/informixdb/
InformixDB authentication is now supported for compliance scans. The new InformixDB Authentication API (api/2.0/fo/auth/informixdb/) lets you list, create, update and delete InformixDB authentication records. User permissions for this API are the same as other authentication record APIs. Note that the API supports authentication record creation only for InformixDB installed on Unix.

 

Scan EC2 Assets for Certificate Information
/api/2.0/fo/schedule/scan/
/api/2.0/fo/scan/
You can now collect certificate information from EC2 assets using EC2 CertView scans. We added a new input parameter (scan_type=ec2certview) to scheduled/scan and /scan APIs.

A new release of Qualys Cloud Suite v2.37 (AM/WAS) includes an updated API which is targeted for release in March 2019. The specific day will differ depending on the platform. See platform release dates on the Qualys Status page. This API notification provides an early preview into the coming API, allowing you to identify use cases that can leverage this updated API.

 

What's new
Asset Management and Tagging API: Fetch AWS Account ID
/qps/rest/2.0/get/am/assetdataconnector/<id>
/qps/rest/2.0/search/am/assetdataconnector
/qps/rest/2.0/get/am/awsassetdataconnector/<id>
The Asset Management and Tagging API has been updated to fetch the AWS Account ID for Asset Data Connectors. You can fetch the AWS Account ID while getting the connector information and search for connectors using a particular AWS Account ID.

 

Asset Management and Tagging API: Activate EC2 Assets in CertView Module
/qps/rest/2.0/get/am/assetdataconnector/<id>
/qps/rest/2.0/update/am/assetdataconnector
/qps/rest/2.0/get/am/awsassetdataconnector/<id>
/qps/rest/2.0/update/am/awsassetdataconnector
/qps/rest/2.0/create/am/awsassetdataconnector
The Asset Management and Tagging API has been updated to add a new connector for the CertView module for AWS Asset Data Connectors.

 

Web Application Scanning API: Send Email only on completion of Multi-Scan
/qps/rest/3.0/get/was/wasscan/<id>
/qps/rest/3.0/launch/was/wasscan
/qps/rest/3.0/get/was/wasscanschedule/<id>
/qps/rest/3.0/create/was/wasscanschedule/
/qps/rest/3.0/update/was/wasscanschedule/<id>
We have now added a new parameter for a multi-scan to configure when the email should be sent: completion of multi-scan or completion of individual scan in a multi-scan.

A new release of Qualys Cloud Suite v8.18 (VM/PC) includes an updated API which is targeted for release in March 2019. The specific day will differ depending on the platform. See platform release dates on the Qualys Status page. This API notification provides an early preview into the coming API, allowing you to identify use cases that can leverage this updated API.

 

What's new
New InformixDB Auth records /api/2.0/fo/auth/informixdb/
InformixDB authentication is now supported for compliance scans. The new InformixDB Authentication API (api/2.0/fo/auth/informixdb/) lets you list, create, update and delete InformixDB authentication records. User permissions for this API are the same as other authentication record APIs. Note that the API supports authentication record creation only for InformixDB installed on Unix.

Filter Blog

By date: By tag: