Verifying a domain
Before you can scan a domain on the Internet, ASoC must verify that you have permission to scan it. Verification is not needed for domains that are not available on the Internet (private sites).
About this task
Procedure
Example
If your application includes links to URLs outside the domain of the starting URL, they must be verified separately to be included in the scan (unless they are private sites and you are using an AppScan Presence). Consider these examples:
Subdomains:
The starting URL is: http://a.com/home/.
The site has links to http://b.a.com, which is a
subdomain of a.com.
The subdomain is automatically included in the verification process but is not scanned by default. To scan subdomains, you must explicitly add them to the 'Domains to test' list in ASoC when you submit a scan or include them in the scan template file.
Parallel or parent domains:
The Starting URL: http://b.a.com/home/.
The site has links to a parallel domain http://c.a.com,
or to parent domain http://a.com, and you want
those links included in the scan.
- Verify
a.com, OR - Verify
b.a.comandc.a.com, and when creating the scan in Create scan > Dynamic (DAST), clear the Include only links in and below this directory check box.



