Installation guide
107
The nessuscert.pem file will be used when configuring the Nessus scanner on SecurityCenter. This file
needs to be copied to somewhere accessible for selection from your web browser during the Nessus
configuration.
Configure Nessus Daemons
To enable certificate authentication on the Nessus server, the force_pubkey_auth setting must be enabled. Once
enabled, log in to the Nessus server may only be completed by SSL certificates. Username and password login will be
disabled. As the root (or equivalent) user on the Nessus server, run the following command:
C:\Program Files\Tenable\Nessus\nessus-fix --set force_pubkey_auth=yes
Open the Nessus Server Manager GUI, click “Stop Nessus Server” and then click “Start Nessus Server”.
Change the Nessus Mode of Authentication
From the SecurityCenter web UI, go to “Resources” and then “Nessus Scanners”. Change the authentication mode from
“Password Based” to “SSL Certificate”. During the setup of the Nessus scanner, select the previously created
“nessuscert.pem” file for the “Certificate” field, then click “Submit” to confirm.