Skip to content

Discovery

Discovery enables automated identification of SSL/TLS certificates across your infrastructure. It detects unmanaged certificates, validates deployed assets, and reconciles inventory against live environments.

Navigation: Sidebar → Discovery

Discovery


SSL-CLM v2 supports three discovery categories, each with multiple scan methods:

CategoryMethodsRuntime
Network DiscoveryHTTPS, IP Range, CIDR, DomainBackend or Agent
Store DiscoverySingle store, All stores, Cloud syncAgent or Backend
CA DiscoverySingle CA, All CAsBackend or Agent

Network discovery scans infrastructure endpoints to detect exposed TLS certificates by performing TLS handshakes.

The main Discovery page provides a scan input area for immediate scanning:

  1. Enter targets (one per line): IPs, CIDRs, domains, or URLs
  2. Specify the port (default: 443)
  3. Choose execution source:
    • Backend — Platform server performs the scan (for public-facing targets)
    • Agent — A specific agent performs the scan (for private/internal networks)
  4. Click Scan Now

Results appear inline after completion.

TypeInput FormatExampleUse Case
HTTPSURLs or IP:PORThttps://example.com, 192.168.1.10:8443Public endpoints, API servers
IP RangeStart IP – End IP + ports192.168.1.1 – 192.168.1.254, port 443Internal network sweeps
CIDRCIDR notation + ports10.0.0.0/24, port 443,8443Subnet-level scanning
DomainDomain names + portsexample.com, *.internal.corpDNS-based discovery
  • PUBLIC — Targets accessible from the internet; scanned from the backend
  • PRIVATE — Targets on internal networks; requires agent selection for scanning

Create reusable, named scans with scheduling:

  1. Click + New Scan
  2. Configure:
    • Name — Descriptive identifier (e.g., “Production Web Servers”)
    • Targets — List of IPs, CIDRs, or domains
    • Port — Target port(s)
    • Run From — Backend or specific Agent
    • Schedule — Manual, or cron expression for automated execution
ColumnDescription
NameScan identifier
TargetsConfigured domains/IPs (truncated preview)
Run FromBackend or Agent name
ScheduleManual or cron schedule
Last RunTimestamp with status badge (SUCCESS / FAILED)
FoundTotal certificates discovered in last run
NewNewly discovered certificates since previous run
ActionsRun (play icon), Edit, Delete
  • Click the play icon (▶) on any saved scan row to trigger an immediate execution
  • Scheduled scans run automatically per their cron configuration
  • Results are correlated against existing inventory

Scan configured certificate stores to find certificates deployed locally.

  1. Select a specific certificate store
  2. The agent (or backend for agentless stores) scans the store
  3. Found certificates are compared against inventory

Trigger discovery across all configured stores simultaneously.

For cloud-based stores (AWS ACM, Azure Key Vault), synchronize the platform inventory with what’s actually deployed in the cloud service.


Retrieve certificates directly from configured Certificate Authorities to reconcile issued vs. deployed certificates.

  1. Select a specific CA
  2. Platform queries the CA for all issued certificates
  3. Results identify:
    • Managed — Already in inventory and managed
    • Ghost — Issued by the CA but not in inventory
    • Out-of-Sync — In inventory but metadata differs from CA record

Trigger inventory sync across all configured CAs simultaneously.


After any scan completes, results provide:

FieldDescription
HostIP or domain that responded
PortPort on which TLS was detected
Subject (CN)Common Name from the certificate
SANsSubject Alternative Names
IssuerCertificate issuer
Valid From / ToValidity window
Days LeftDays until expiration
Chain ValidWhether the full certificate chain is valid
Chain LengthNumber of certificates in the chain
Is ManagedWhether this certificate is already in managed inventory
FieldDescription
SerialCertificate serial number
SubjectFull subject DN
StatusActive / Revoked / Expired
GhostIssued by CA but not in platform inventory
Out-of-SyncMetadata mismatch between CA and platform

The platform automatically correlates discovery results with the existing inventory:

  • Match — Discovered certificate matches an inventory entry (by fingerprint)
  • New / Unmanaged — Certificate found but not in inventory
  • Ghost — Certificate exists in CA records but not deployed anywhere
  • Out-of-Sync — Deployed certificate differs from inventory record (e.g., different validity, different SAN set)
  • Missing — Certificate in inventory but not found in scan target

From discovery results, you can import certificates into inventory:

  1. Select one or more discovered certificates
  2. Click Import
  3. Choose tier: Managed (active lifecycle) or Monitored (tracking only)
  4. Certificates are added to inventory

ModeBehavior
ImmediateScan runs synchronously; results displayed inline
Job-BasedScan creates a background job; results available after completion

Large scans (hundreds of targets) automatically run as jobs. Quick scans of a few targets run immediately.


For scanning private networks that the backend cannot reach:

  1. Ensure an agent is deployed on the target network (or a jump host with access)
  2. When creating a scan, select the agent under Run From
  3. The agent executes the TLS scan locally and reports results back to the platform

This enables discovery of internal infrastructure without exposing it to the internet.


Saved scans support cron-based scheduling:

ExampleSchedule
0 0 * * 1Every Monday at midnight
0 6 * * *Every day at 6 AM
0 0 1 * *First of every month

Scheduled scans run automatically and results are stored for review.


  • Run network discovery weekly across production infrastructure
  • Enable CA discovery to detect ghost certificates
  • Use store discovery after deployments to verify success
  • Schedule scans during low-traffic windows
  • Monitor “New” counts in saved scans to catch unauthorized certificates
  • Import unmanaged certificates and promote to Managed tier for lifecycle automation