Discovery
The Discovery feature in TLS Connect allows you to identify TLS certificates across your environment by scanning network endpoints or the local Windows Certificate Store. This provides visibility into the number, type, and status of certificates in use on your network.
Scan Profiles
Scan Profiles define where and how TLS Connect searches for certificates.
-
Open the TLS Connect application and navigate to the Discovery > Scan Profiles tab.
-
Click Create New Scan Profile.
-
Enter a Profile Name.
-
Select the scan type:
The new scan profile appears in the table at the bottom of the screen. From this table, you can:
- Run the scan profile.
- Edit the profile.
- Delete the profile.
License Behavior
-
With a Standard license, scan profiles run only when you manually click the Play (green arrow) button next to a scan profile to view the result and status.
-
With a Premium license, you can enable an automation service that continuously runs all scan profiles at a configurable interval.
Inventory
The Inventory section displays all certificates discovered through your scan profiles.
From this view, you can:
-
See certificates that are valid, expired, or nearing expiration.
-
Sort and filter the inventory using multiple criteria.
-
View detailed certificate information.
-
Download individual certificates.
-
Export CSV - Use this option to export the certificate inventory to a CSV file for offline review or reporting.
-
Purge Profile - Use this option to remove all certificates discovered by a specific scan profile. This is useful if a scan profile was misconfigured and you want to quickly clean up the inventory. All certificates discovered by the selected scan profile are removed from the inventory.