We're reclaiming inactive PDIs to keep them available for active builders. Learn what's changing, who's affected, and how to protect your work. Read More

NetApp Discovery Security – Using HTTPS Instead of HTTP Classifier with Basic Authentication?

OMT
Giga Guru

Hello ServiceNow Community,

we are currently reviewing the security of our NetApp Discovery implementation and would appreciate any guidance or best practices from others who have faced a similar situation.

After testing, we determined that NetApp Discovery requires:

  • Basic Authentication 
  • SNMPv3

Recently, our security/penetration testing team identified a security issue: credentials used for Basic Authentication were found in clear text on some network devices, which resulted in a security incident being raised.

Our main concern is the use of the HTTP Classifier with Basic Authentication over HTTP. We would like to understand how we can improve the security of NetApp Discovery.

Specifically:

  1. Is it possible to configure NetApp Discovery to use HTTPS instead of HTTP for classification and credential validation?
  2. Are there any recommended best practices for securing NetApp Discovery credentials?
  3. Has anyone successfully implemented a more secure authentication method instead of Basic Authentication with HTTP?
  4. Are there specific ServiceNow Discovery patterns, classifiers, or MID Server configurations that can help mitigate this risk?

We are looking for recommendations from anyone who has implemented NetApp Discovery in a security-sensitive environment.

Thank you in advance for your help and insights.

Best regards,

Tahir

1 REPLY 1

Tanushree Maiti
Tera Patron

Hi  @OMT 

 

As per ServiceNow Documentation: Run discovery through an HTTP or HTTPS REST call 

 

Important:

The HTTP Classify probe no longer attempts credentials over the HTTP protocol by default. To override this behavior, you can enable mid.http_classy.allow_credentials_over_http. However, enabling this setting can expose credentials to man-in-the-middle (MitM) attacks. Therefore, it’s strongly recommended to keep this property set to false and use HTTPS whenever possible.
 
 
Please Accept the solution if it assisted you with your question & Mark this response as Helpful.
Regards
Tanushree Maiti
ServiceNow Technical Architect
LinkedIn: https://www.linkedin.com/in/tanushreemaiti