Using network discovery
CyberArk Trust Protection Foundation™'s Network Discovery feature provides an easy and convenient way to inventory your network’s SSL certificates and SSH server keys.
During a network discovery, the Discovery server scans designated IPv4 address ranges and ports to identify SSL certificates or SSH public keys. You can also perform an instant discovery on an individual IPv4 or IPv6 address and port. During the scan process, Trust Protection Foundation sends SSL and SSH requests to the target ports at the designated IP addresses. If the server responds, Trust Protection Foundation retrieves the server’s certificate or SSH public key.
NOTE Instant Discovery retrieves only the certificate information; however, you are given the option of bringing the discovered certificate under management.
Network Discovery identifies where SSL certificates and SSH servers are deployed and provides valuable information. In the case of network SSL certificates, the discovery scan identifies the certificate common name (CN), the IP address of the server where the certificate is located, the certificate expiration date, and the CA. In the case of SSH server keys, the network discovery identifies where SSH servers are deployed and whether those servers are configured in compliance with corporate folders, including key lengths, protocol versions, supported authentication methods and other information.
The discovery results update each time the discovery runs, giving you a centralized, always-current inventory of certificates, SSH systems, configuration information, keys and trust relationships.
When the Update certificate configuration on rediscovery option is enabled on a discovery job, Trust Protection Foundation can also update existing certificate configurations when it detects changes. For example, if a certificate is renewed outside of Trust Protection Foundation with additional Subject Alternative Names (SANs), the discovery job will update the certificate object's configuration to reflect these changes. This ensures that when Trust Protection Foundation renews the certificate, it requests the latest configuration rather than an outdated one.
As discovery runs, it can place the discovered certificates and public SSH server keys under management in Trust Protection Foundation. This is the fastest and easiest way to bring encryption assets under management. This placement happens for items as they are discovered, thus during a discovery it is not uncommon to see items appear in management before the discovery job is complete.
Certificate reconciliation
An important feature of Network Discovery is automatic certificate reconciliation. When Network Discovery rediscovers a certificate that already exists in Trust Protection Foundation, the system automatically combines the certificates to maintain a single, up-to-date record. If the discovered certificate is newer and has different Subject Alternative Names (SANs), Trust Protection Foundation automatically updates the SAN renewal settings to ensure that future renewals include all current SANs from the deployed certificate.
This automatic reconciliation ensures that your certificate inventory remains current and that certificates renewed in Trust Protection Foundation reflect the actual deployed configuration, even when certificates are modified outside of Trust Protection Foundation.
For more information about how certificate reconciliation works, see About certificate reconciliation during discovery. For information about bypassing automatic reconciliation in specific scenarios, see Discovery root node settings.