-
Notifications
You must be signed in to change notification settings - Fork 0
All Users
This page documents general tasks for all users, primarily account creation and management.
Use of VINCE-NT is subject to Terms and Conditions. Your authentication provider may enforce additional Terms of Use.
To access VINCE-NT visit https://vulnerabilities.cisa.gov/.
It is possible to submit a vulnerability report without creating an account or logging in. To submit a report as a registered user or for all other purposes, you will need to create an account. There are two options to create an account.
-
Most users should follow the instructions for Self-service.
-
If you are a U.S. government employee or partner with a CAC or PIV card, see CAC or PIV card holder.
Create an account through the CISA Registration Portal (which uses Okta as the authentication provider).
-
Select [Log in or sign up]
-
Do not enter a [Username], do not select [Next], do not select [Sign in with PIV / CAC card].
-
Select [New user registration] at the bottom of the screen. You may need to scroll down.
-
If you are notified about the Privacy Policy, select [I Agree].
-
Enter an [Email] address and select [Continue].
-
You should receive a verification code via email. Enter the Verification Code and select [Verify Code].
-
Select [VINCE-NT] from the [Application] drop-down menu then select [Next].
-
Optionally enter [Organization] and [Sub-organization] then select [Continue]. These fields are informational and do not, for example, specify Supplier Group names.
-
Enter [First Name], [Last Name], and [VINCE-NT screen name]. This information will be used to identify you in VINCE-NT. You are not required to use your real names. Select [Submit request].
-
You should see a screen noting [Request Received] and that your request for VINCE-NT access has been granted.
-
You should receive email (from noreply_acess@cisa.dhs.gov) with instructions to activate your account. Select [Activate Okta Account] from the email message, or copy the link and paste it into a web browser.
-
You should see a screen requiring you [Set up security methods]. Under [Required now] select [Set up] to choose a [Password] for your account.
-
Noting the password length and complexity requirements, enter a password in the [Enter password] and [Re-enter password] fields. Then select [Next].
-
You must select at least one additional security method. Select [Set up] for one of:
-
[Google Authenticator]
-
Scan the QR code with Google Authenticator then select [Next].
-
[Enter code] and select [Verify].
-
-
[Okta Verify]
- Scan the QR code with your mobile device (using either your camera app or Okta Verify). Follow the instruction in Okta Verify.
-
[Security Key or Biometric Authenticator]
- Follow the instructions to set up this security method.
-
You may optionally [Set up] additional security methods. When you are done setting up additional security methods, select [Continue].
-
You should see the CISA ICAM screen including a [VINCE-NT] icon under [My Apps]. Select the [VINCE-NT] icon.
- Alternatively, access https://vulnerabilities.cisa.gov/ in a web browser.
-
Select [Log in or sign up].
-
You should now be logged in to VINCE-NT. If your previous session timed out, you will need to [Log in to VINCE-NT].
-
When you first log in, you will be presented with the VINCE-NT Terms and Conditions. Scroll through the text and select [I Accept] to continue to use VINCE-NT.
-
You will be presented with VINCE-NT Terms and Conditions again when they change.
-
[Dashboard] is selected. You may see one or more Groups you can [Request to join].
If you are a U.S. government employee or partner with a CAC or PIV card:
-
Select [Log in or sign up].
-
Do not enter a [Username], do not select [Next], do not select [Sign in with PIV / CAC card].
-
Select [New user registration] at the bottom of the screen. You may need to scroll down.
-
If you are notified about the Privacy Policy, select [I Agree].
-
Enter the email address associated with your PIV or CAC card and select [Continue].
-
On the CISA ICAM Login [Sign In] screen, you should see the email address you previously entered in the [Username] field. Select [Sign in with PIV / CAC card].
-
If prompted, select a certificate.
-
If prompted, enter your PIN.
-
Select [VINCE-NT] from the [Application] drop-down menu then select [Next].
-
On the CISA Registration Portal page, Select [Continue >].
-
Your [Organization] and [Sub-organization] are filled in based on your certificate. Select [Continue >].
-
Enter a [VINCE-NT screen name] and select [Submit request].
-
You should see a screen noting [Request Received] and that your request for VINCE-NT access has been granted. Select [Sign in to your CISA Application >].
-
You should see the CISA ICAM screen including a [VINCE-NT] icon under [My Apps]. Select the [VINCE-NT] icon.
- Alternatively, access https://vulnerabilities.cisa.gov/ in a web browser.
-
Select [Log in or sign up].
-
You should now be logged in to VINCE-NT. If your previous session timed out, you will need to [Log in to VINCE-NT].
-
When you first log in, you will be presented with the VINCE-NT Terms and Conditions. Scroll through the text and select [I Accept] to continue to use VINCE-NT.
-
You will be presented with VINCE-NT Terms and Conditions again when they change.
-
[Dashboard] is selected. You may see one or more Groups you can [Request to join].
After creating an account you can log in to VINCE-NT.
-
If you have a current valid authentication provider session, you will be logged in automatically.
-
If you are not logged in automatically, select [Log in or sign up].
-
You may need to enter your email address and select [Next].
-
You may also need to select either an MFA method, password, or both, and follow the prompts.
-
You should now be logged in to VINCE-NT.
-
Select [Log in or sign up].
-
Select [Sign in with PIV / CAC card].
-
You should now be logged in to VINCE-NT.
-
As a Reporter, you might want to report a vulnerability or view Cases you have previously reported.
-
If you are a Supplier, you might want to create or join an existing Supplier Group or view your Cases.
-
Select your profile icon in the upper right corner.
-
Select [Log Out].
-
Select [Sign Out] on the confirmation screen. This will log you out of VINCE-NT but not your authentication provider.
- If you log in to VINCE-NT while your authentication provider session is still valid, you will not need to provide credentials.
-
On the VINCE-NT log out screen, select [Log out of the authentication provider.].
- Alternatively, visit https://login.access.cisa.gov/
-
In the CISA ICAM screen, select your name and [CISA ICAM Login] in the upper right corner.
-
Select [Sign out].
-
You will be returned to the CISA ICAM login screen. If you authenticate again from this screen, you will be taken to the CISA ICAM screen. You should see a VINCE-NT App icon, select this to return to the VINCE-NT login screen. Select [Log in or sign up] and you will be automatically logged in to VINCE-NT.
-
Click [Log in or sign up].
-
Enter your email address and select [Next].
-
If prompted with the password screen, proceed to step 5.
- If prompted with a non-password authentication option, select [Verify with something else] then select [Password]
-
Select [Forgot Password?].
-
Select [Send me an email].
- A reset email will be sent to your email address.
-
Select the [Reset Password] button in the password reset email.
- If you have Okta set up as a form of authentication, you may also use the code provided in the email instead.
-
Enter and re-enter a new password and confirm it.
-
Select [Reset Password]. You may be logged in directly after this step.
-
If not logged in already, select [Login] or return to the original login window and enter your new credentials.
-
If necessary, log in.
-
Select the dropdown under your profile name in the top right, select [Account settings].
-
Scroll down to Security Methods.
-
Edit, Set up, or Remove authentication methods as desired.
For issues related to logging in, including multi-factor security method and password resets:
-
Visit https://access.cisa.gov/faq.
-
Send mail to the CISA Technical Operations Center.
-
Visit the CISA VINCE-NT GitHub repository and review existing issues. If you do not find a relevant existing issue, file a new issue.
-
Alternatively, send mail to the CISA CVD team.
-
Report the vulnerability within VINCE-NT.
-
File a private report through GitHub.
-
Send mail to the CISA CVD team.
-
Send mail to the CISA CVD team.
-
If the issue involves the CISA CVD team, send mail to central@cisa.dhs.gov.
-
Select the user icon in the upper right corner of most screens.
-
Select [Profile].
-
Select the [Account] tab.
-
Make any desired changes.
- You can change the color of your user icon, upload or remove ([Reset]) a profile photo, change your name, organization, and title, and change your time zone.
-
Select [Save changes] at the bottom of the screen.
10.2 Generate an API Key
-
Select the [MFA/API] tab.
-
Select [Generate API Key].
-
Save the API key somewhere securely. Anyone with the valid API key can perform actions as you in VINCE-NT.
-
Select [Ok].
-
To generate a new API key select [Refresh API Key].
- If you are concerned that your API key was exposed, generate a new API key. This invalidates the previous API key.
-
Select the [Email Preferences] tab.
-
Make any desired changes.
-
Select [Save Changes] at the bottom of the screen.