Discovery object

Defines the data necessary for Trust Protection Platform to perform a Network Discovery scan for certificates and keys. Objects of this class should only be created in the Discovery tree (\VED\Discovery).

Additional attribute descriptions appear in [Venafi installation]\Schema\Counters. If you want to view statistics about Trust Protection Platform events, install the Venafi Statistics Viewer MMC snap-in. For more information, Install the Venafi MMC Snap-In Collection.

Discovery attributes

Attribute

Description

Address Parsing Errors

UI: NA
Required: No

Policy Definable: No. Default: NA

A set of errors that occurred while parsing a range of host IP addresses for a discovery job.

Address Range

UI: Addresses and Ports
Required: No

Policy Definable: No. Default: NA

One or more network addresses with at least one port to scan. The address formats:

  • A single IP address. Example: 192.168.1.100:443.
  • A Fully Qualified Domain Name (FQDN). Example: www.company.com:443.
  • A hostname. Example: prodserver01:443.
  • A range of IP addresses. Example: 192.168.1.100-192.168.1.255:443.

The address includes one or more ports between 1 and 65535 in the following format:

  • A comma separated list of ports.
  • A port ranges. Example: 192.168.0.1-192.168.0.255.
  • A Classless Inter-Domain Routing (CIDR) range. Example 192.168.1.0/24:443.
  • A combination of a port range and list. For Example: 192.168.0.1-192.168.0.255:443,8443,60000-61000.

Automatically Import

UI: NA
Required: No

Policy Definable: No. Default: NA

The setting to determine how to handle the Discovered information:

0 = Allow a user to preview and place the discovered certificates and keys into the Policy tree.

1 = Automatically add the discovered certificates and keys into the Policy tree based on rules.

Certificate Location DN

UI: Certificate Locations
Required: No

Policy Definable: No. Default: NA

The placement locations of discovered certificates.

Completed Assignments

UI: NA
Required: No

Policy Definable: No. Default: NA

The number of completed Discovery work assignments for a discovery survey.

Completed

UI: Completed
Required: No

Policy Definable: No. Default: NA

An informational attribute set only by Trust Protection Platform. The date and time (in Universal date/time format) when the Discovery job last completed.

Configuration

UI: NA
Required: No

Policy Definable: No. Default: NA

A string for storing configuration details about the object.

Creation Date

UI: NA
Required: No

Policy Definable: No. Default: NA

The creation date of the Discovery job.

Device Location DN

UI: NA
Required: No

Policy Definable: No. Default: NA

The creation date of the Discovery job.

Discovery Exclusion DN

UI: NA
Required: No

Policy Definable: No. Default: NA

The Trust Protection Platform distinguished name of a Discovery Exclusion object assigned to the Discovery job.

Multiple values of this attribute indicate the Discovery job is subject to different sets of exclusion criteria.

In Progress

UI: NA
Required: No

Policy Definable: No. Default: NA

An informational attribute set only by Trust Protection Platform. A value of 1 indicates that the Discovery job is running.

Last Update

UI: Last Updated
Required: No

Policy Definable: No. Default: NA

The date that the last Discovery ran.

Placement Rule

UI: NA
Required: No

Policy Definable: No. Default: NA

The rule execution order to apply for certificate placement. The format is rule order: rule object GUID. For example, zero executes first:

0:{07bfe18d-fa7f-4cc9-aaa1-d89523daa4a4}

Placement Summary STILL IN DB

UI: NA
Required: No

Policy Definable: No. Default: NA

One or more destinations of the newly discovered certificates. The Distinguished Names (DNs) maps to a place in the inventory of certificates or Policy folder.

Priority

UI: NA
Required: No

Policy Definable: No. Default: 0

A positive integer representing the priority of the Discovery job relative to other jobs when scheduled to run at the same time.

Protection Key

UI: NA
Required: No

Policy Definable: No. Default: NA

The protection key to secure the private key in Secret Store.

Report DN

UI: NA
Required: No

Policy Definable: No. Default: NA

The Distinguished Name (DN) that contains the Discovery survey results.

Resolve Host

UI: NA
Required: Resolve Host Names

Policy Definable: No. Default: 1

A value of 1 indicates that the Discovery engine should perform a reverse DNS lookup of the IP address and, if successful, capture the result whenever a certificate is found.

Started

UI: Started
Required: No

Policy Definable: No. Default: NA

An informational attribute set only by Trust Protection Platform. The date and time (in universal date/time format) when the Discovery job last started.

Status

UI: Status
Required: No

Policy Definable: No. Default: NA

An informational attribute set only by Trust Protection Platform. A text value assigned by a Discovery engine to indicate the status of the Discovery job. Possible values include: Pending Submission, Pending Execution, Waiting for next Execution Window, Running, Paused, Aborted, and Completed.

Total Assignments

UI: NA
Required: No

Policy Definable: No. Default: NA

The total number of Discovery work assignments generated for the Discovery survey.

Window Days of Month

UI: Day of Month
Required: No

Policy Definable: No. Default: NA

Deprecated. For the new attribute, see Parent class—Schedule Base

Window Days of Week

UI: Day of Week
Required: No

Policy Definable: No. Default: NA

Deprecated. For the new attribute, see Parent class—Schedule Base.

Window End

UI: Time of Day
Required: No

Policy Definable: No. Default: 12:00:00 AM

Deprecated. For the new attribute, see Parent class—Schedule Base.

Window Start

UI: Time of Day
Required: No

Policy Definable: No. Default: 12:00:00 AM

Deprecated. For the new attribute, see Parent class—Schedule Base.

Work Units

UI: Total Ports
Required: No

Policy Definable: No. Default: NA

An informational attribute set only by Trust Protection Platform. The total number of IP:port combinations that the Discovery job is configured to scan.