Enable the Transfer Layer Security (TLS) port probe [tls_ssl_certs] and scan for
certificates on an IP address or multiple IP addresses.
Before you begin
Know the IP address, range of IP addresses, or list of IP addresses you want to perform
Certificate Discovery on.
Role required: Certificate administrator, discovery_admin, or admin
Procedure
-
Activate the TLS port probe [tls_ssl_certs].
-
Navigate to .
-
Open tls_ssl_certs.
-
To enable the probe, select the Active check box.
By default, the check box for any new installation is cleared.
-
Confirm the Triggered by services has the services you need.
By default, the following services trigger the tls_ssl_certs probe: HTTPS,
tomcat-ssl, IBM Websphere SSL, Idaps, IMAPS, pop3s, ftps-data, ftps, smtp,
pop3, imap, Idap, ftp, submission.
-
Select Update.
-
Create an IP-Based Certificate Discovery Schedule.
-
Navigate to .
-
Select New.
-
Fill out each text field with its corresponding value.
-
Select and hold (or right-click) above Discovery
Schedule and select Save.
By selecting Save, additional configuration options
are available.
-
Select the Use SNMP text field.
-
In the new tabs that appear, select Discovery IP
Ranges.
-
Select New.
-
Fill each field with its corresponding value.
-
Select Submit.
The port tls_ssl_certs will look for Certificates
available inside your selected IPs at the next time interval (daily, weekly,
monthly, etc.).
-
Create an IP-Based Certificate Quick Discovery for immediate
discovery (optional).
-
Navigate to .
-
Select Quick Discovery.
-
Enter your Target IP into the Target IP field.
-
Select OK.
Result
The probe tls_ssl_certs searches for Certificates inside your
selected IP immediately, and reports the certificates it finds.