Test Authentication Record

You can add the authentication record to your web application to test.

To add the authentication record to the web application:

  1. Go to Web Applications > Additional Configuration > Authentication Records.
  2. Select one or more authentication records from the list.

 

To test the authentication for your web application

  1. Go to Web Application > Additional Configuration > Set up Exclusion Lists.
  2. Add a URL Allow List  to your web application and enter only the login URL for authentication.

  3. Run a discovery scan on your web application. Hover over your web application in the list and choose Scan > Discovery Scan from the menu. The scan should only take a few minutes with the white list applied.

If the authentication is successful, remove the Allow List from your web application settings. If the authentication is not successful, check your web site in a browser to determine the correct URL of the login form, and check that the right credentials are used in the authentication record.

Test Authentication - Scan Settings

The authetication record associated with the web application is automatically available. 

Scanner Appliance

Scanner Appliance 

  • If you have an external-facing web application, select External. Perimeter applications can be scanned by Qualys Cloud scanners. 
  • If you have a web application on your internal network, select Individual, and select the scanner from the list of scanners. 
  • If you want to allocate multiple scanners. select Tags (Scanner Pool), and select tags from the list of tags. The scanner appliances with any of the selected tags are added to the scanner pool and can be assigned at the scan run time.

Proxy Support 

Select a proxy configuration from the list of proxy configurations that are available for your account.

The proxy configuration that you have selected while creating a web application is automatically populated. However, you can override the default selection.

DNS Override

Select a DNS Override record to use the mappings in the selected record instead of the default value for the web application URL to crawl the web application and perform scanning. 

This is useful in some scenarios. For example, if the web application does not have a DNS entry, as it's in a non-production environment, or the web application may have a different IP address in a non-production environment (that is,  development or QA) than in production.

HAR Capture

Select the checkbox to capture HTTP Archive (HAR) file during authentication when you perform Selenium-based Test Authentication scans. 

The HAR data is included in the Selenium diagnostic output under QID 150100. The captured data includes request URLs and methods, HTTP headers, status codes, timing details, and redirect chains.

Email Notification 

Select the Send mail at scan completion check box to send an email upon scan completion, failure, or cancellation, and select the email address from which the email should be sent in the From Address list. All users with permissions to view the target web application will get these emails.

Debug Scan

Select the checkbox to capture detailed logs of all HTTP requests, responses, and parameter testing during the scan, helping you troubleshoot issues like authentication failures or missed vulnerabilities.