SSL Discovery

SSLClosed TLS (Transport Layer Security) and its predecessor SSL (Secure Sockets Layer) are protocols for establishing authenticated and encrypted links between networked computers. network discovery and monitoring are used to scan designated internal or internet-facing IP addresses, ports, and host names to locate certificates at TLSClosed TLS (Transport Layer Security) and its predecessor SSL (Secure Sockets Layer) are protocols for establishing authenticated and encrypted links between networked computers. endpoints. Discovered certificates are imported into Keyfactor Command and monitored for availability and expiration.

Discovery scans locate certificates by connecting to network endpoints, while monitoring scans inspect previously discovered endpoints to verify certificate presence, health, and expiration status and to notify configured recipients of issues.

SSL discovery supports scanning TLS 1.3 endpoints using the cipher suites defined in Appendix B.4 of RFC 8446.

Tip:  Where to find this in the Management Portal:
Locations → SSL Discovery

How SSL Discovery and Monitoring Work

SSL network discovery and monitoring scans are performed by orchestrators assigned to SSL pools. An SSL pool contains one or more approved orchestrators that support SSL discovery and monitoring capabilities.

When a discovery or monitoring scan is initiated—either manually or on a schedule—Keyfactor Command creates one or more scan jobs based on the size of the request. These jobs are distributed across the orchestrators in the assigned SSL pool and executed in parallel. Orchestrators poll the Keyfactor Command service for available jobs and process them as capacity allows.

The orchestratorClosed Keyfactor orchestrators perform a variety of functions, including managing certificate stores and SSH key stores. that discovers a certificate is not required to be the same orchestrator that later monitors that certificate.

Server Name Indication (SNI) Behavior

During discovery scans, orchestrators attempt connections both with and without Server Name Indication (SNIClosed Server name indication (SNI) is an extension to TLS that provides for including the hostname of the target server in the initial handshake request to allow the server to respond with the correct SSL certificate or allow a proxy to forward the request to the appropriate target.) for endpoints defined by host nameClosed The unique identifier that serves as name of a computer. It is sometimes presented as a fully qualified domain name (for example servername.keyexample.com) and sometimes just as a short name (for example servername).. When an endpointClosed An endpoint is a URL that enables the API to gain access to resources on a server. includes a host name, the orchestrator attempts two scans: one standard connection and one using the host name as the SNI value.

During monitoring scans, SNI is used only if an SNI value was identified during discovery.

SSL Pools

Keyfactor Command includes a Default Agent Pool that contains all approved orchestrators configured for SSL discovery and monitoring. You can create additional SSL pools to control how scanning workloads are distributed.

Note:  Orchestrators assigned to an SSL pool must have network access to the addresses they are configured to scan. For best performance and reliability, place orchestrators close to their target networks. Scanning across WAN links or constrained networks can increase scan times and may result in missed certificates due to timeouts or network congestion. Firewalls between orchestrators and target networks must allow connections to the scanned addresses and ports.

SSL Discovery Areas

SSL network discovery and monitoring are organized into three areas:

  • Network Definitions

    Define the networks to be scanned, including IP addresses, ports, and host names, and assign an SSL pool to perform discovery and monitoring. From this area, you can schedule discovery and monitoring scans and configure options such as automatically monitoring discovered endpoints.

  • SSL Pools Definition

    Define SSL pools by grouping approved orchestrators that support SSL discovery and monitoring. SSL pools determine which orchestrators perform scanning for assigned networks.

    Tip:  Previous versions of Keyfactor Command referred to the SSL pools as orchestrator pools.
  • Results

    View endpoints identified during discovery and monitoring scans. Results include endpoints that returned certificates as well as endpoints that responded to connection attempts but did not return a certificate. Monitoring and review status are also shown.

Requirements and Recommendations

SSL network discovery and monitoring require at least one compatible instance of the Keyfactor Universal OrchestratorClosed The Keyfactor Universal Orchestrator, one of Keyfactor's suite of orchestrators, is used to interact with servers and devices for certificate management, run SSL discovery and management tasks, and manage synchronization of certificate authorities in remote forests. With the addition of custom extensions, it can provide certificate management capabilities on a variety of platforms and devices (for example Amazon Web Services (AWS) resources, Citrix\NetScaler devices, F5 devices, IIS stores, JKS keystores, PEM stores, and PKCS #12 stores) and execute tasks outside the standard list of certificate management functions. It runs on either Windows or Linux servers or Linux containers. that has been approved in the Management Portal (see Current Compatibility Matrix (opens page in a new tab)).

Keyfactor recommends installing orchestrators used for SSL discovery and monitoring on servers other than the primary Keyfactor Command servers, particularly when scanning large or complex networks, due to the resource demands of the scanning process.

Tip:  Click the help icon () next to the SSL Discovery page title to open the Keyfactor Software & Documentation Portal to this section. You will receive a prompt indicating:

You are being redirected to an external website ‘software.keyfactor.com'. Would you like to proceed?

You can also find Help in the NavigatorClosed The Navigator is the Keyfactor Command left-hand (newer versions) or top (older versions) navigation menu. Certificate collections and reports can be configured to be added to the menu using user-defined Show in Navigator settings.. From here you can choose to open either the Keyfactor Software & Documentation Portal at the home page or the Keyfactor API Endpoint Utility.

Keyfactor provides two sets of documentation: the On-Premises Documentation Suite and the Managed Services Documentation Suite. Which documentation set is accessed is determined by the Application Settings: On-Prem Documentation setting (see Application Settings: Console Tab).