Problems Scanning RHEL-8 For Vulnerabilities
Good afternoon,
Our organization has been using the Tenable Nessus vulnerability scanner to remotely scan RedHat Ver 6 and 7 servers for many years.
After upgrading to RHEL-8, we started having problems running the remote scans. Our security policy states we are not authorized to directly remote-connect into all RedHat servers using a Root/Admin account...we must use SU/SUDO privilege escalation for SSH authentication when running remote scans.
After contacting Tenable technical support they determined the TMUX service on RHEL-8 servers has been the problem since we must use SU/SUDO privilege escalation.
Tenable therefore stated we should contact RedHat Support for instructions on how to properly remove the TMUX service and replace it with an authentication method similar to what is being used with RHEL-6 and RHEL-7 servers...something that will allow full access using SU/SUDO privilege escalation.
Responses