Skip to main content
The Linux scan module signs in to the system over SSH and reads it out. It can sign in as root, as a user with sudo, or with a private key. It requires a connected gateway.

Captured data

Each system becomes an asset of the type Linux. The detail page groups the data as follows: How the detail page of the type is structured is described in Systems.

Setting up the job

The wizard follows the standard path Basics › Targets › Schedule › Summary—see Creating a Scan Job. The Targets step is what sets this module apart. Each row carries four columns: An entry of the type SSH Access carries Username and Method: with Password or with Private Key, and with a private key optionally a Passphrase. An entry in Credentials for all targets applies to every row without an assignment of its own.

Prerequisites

Ports and protocols

If a system uses a different SSH port, enter it in the Port column.

Permissions

The account matches one of these three variants: Supported key types: ecdsa-sha2-nistp256, ecdsa-sha2-nistp384, ecdsa-sha2-nistp521, ssh-ed25519 and ssh-rsa.
A user with sudo but without a login shell returns an incomplete scan, even though the sudo configuration is correct. Create the user with adduser; the user then gets a login shell automatically.
How you run gensudo.sh and add its line to the sudoers file is in Scanning by Script.

Network requirements

  • SSH is enabled on the Linux system.
  • The firewall allows the port.
  • The distribution is supported.
If SSH is not available, or neither root nor sudo can be set up, scan the system with the Discovery-Linux (64-bit) or Discovery-Linux-Legacy (32-bit) scan script—see Scanning by Script. The script also suits IGEL thin clients running Linux; they then appear as a Linux system, not as a thin client.

Common issues

After it is created, the job appears among the jobs; how you watch and adjust it is in Managing Jobs. You capture Macs with macOS.