Audit user role with read-only audits and credentialed tool scans
The security tool usually requires a login to the appliance, such that, the login user has all privileges to read all files. Currently
ssmcadmin
user does not have read privileges to all files in the appliance. SSMC does not support to enable root user for security purposes. Hence, SSMC has a special audit user with adequate permissions that are required for a security scanning tool to perform its tasks.
The rights for ssmcaudit user can read any file on the SSMC virtual appliance.
When you do a scan using the ssmcaudit credentials, their scan reports look similar to the reports generated by using root credentials.