Internal does not mean certificate-free
Hypervisors, storage systems, BMCs, application portals and management tools increasingly use HTTPS internally.
Expiry creates operational outages
An expired internal certificate may break automation, API integrations or administrator workflows even when no public user ever sees it.
Names reveal configuration drift
Certificates can expose old hostnames, unexpected domains or systems that were cloned without updating identity.
Auditor can collect TLS clues during discovery
When reachable services expose TLS, Scantide Auditor can use certificate and service evidence as part of the inventory and follow-up process.
Practical depth: examples, failure modes and what to verify
Source note: current Scantide material describes the present platform. Older JufCorp/Red Cloud material is retained as field experience and historical context. Old product names, versions and configuration examples are not presented as current requirements.
Current Scantide detail
Current Scantide source: Windows Network Auditor and Internal Asset DiscoveryDiscover Windows network assets, exposed services and useful operational evidence with Scantide Auditor, designed for authorized internal visibility and readable reporting.
Current Scantide source: Scantide Auditor – Agentless Internal Network Discovery and Security VisibilityScantide Auditor provides authorized internal network discovery, asset inventory, service visibility, CMDB review and readable evidence reports for Windows and Linux environments.
Current Scantide source: Agentless Network Discovery for Servers and InfrastructureScantide Auditor helps administrators discover and document devices, exposed services and useful evidence across authorized internal networks without deploying a heavy endpoint agent to every target.
Current Scantide source: Shadow IT and Rogue Server DiscoveryUse Scantide Auditor to identify reachable internal systems and compare findings with expected assets to support shadow IT and rogue server discovery.
Current Scantide source: Linux Network Auditor and Internal DiscoveryUse Scantide Auditor in Linux environments for authorized network discovery, service visibility and infrastructure evidence without a heavyweight endpoint deployment.
Field experience from the archive
Historical source · JufCorp: Securing your server environment - Part III - Operating systemsWhatever you'll be using your server for. have a look at any information that it "bleeds". This could for instance be headers telling any attacker exactly what version of software you're running. If possible, try to hide such information. There's no need for it to be visible and help a hacker find a way in. Simple checks using telnet to the ports your services might reveal some interesting information . Sadly, it's not possible to remove all headers etc but you should give it a go and remove as many as possible While on the subject, use SSL-certificates for any service where possible. Also make sure to set it up correctly (disable weak ciphers, enable HSTS, set correct HTTP headers, set TLS correctly etc ) . Have a look at Letsencrypt for instance for SSL certificates. It's free, supported by basically everyone and it'll probably get the job done for you . All you have to remember is to check that your certificates are renewed every three months.
Enable logging of login failures, access failures to operating system events etc. In short, log everything. It'll impact performance and use up disk but it's useful for troubleshooting when the time comes.
Historical source · JufCorp: Securing server environments – part II – NetworkingDon’t have computers in the reception connected to the corporate network such as guest access systems. There is absolutely no need for external visitors to be able to browse your internal network.
Historical source · JufCorp: Securing your servers, users and customers onlineUsing MITM (Man In The Middle) attacks is also popular method if you haven't secured your server and your communications with valid SSL certificates. Quite a few actually use self-issued certificates on the websites and on their OWA site and that's not a good thing. When someone who knows what they're doing connect to a site that has a self issued certificate the first thing that comes to mind is .."hmm .. these sysadmins are cheap and lazy and I'm fairly sure they just set this server up using default values.. let's have a look, eh?" .. )
Write your DRP (link in Swedish, sorry ) from the perspective that you're gone (in the freak barbecue accident) and the person reading it has never ever heard of your internal system before.
Practical review checklist
- Discover Windows network assets, exposed services and useful operational evidence with Scantide Auditor, designed for authorized internal visibility and readable reporting.
- Scantide Auditor provides authorized internal network discovery, asset inventory, service visibility, CMDB review and readable evidence reports for Windows and Linux environments.
- Scantide Auditor helps administrators discover and document devices, exposed services and useful evidence across authorized internal networks without deploying a heavy endpoint agent to every target.
- Use Scantide Auditor to identify reachable internal systems and compare findings with expected assets to support shadow IT and rogue server discovery.
- Use Scantide Auditor in Linux environments for authorized network discovery, service visibility and infrastructure evidence without a heavyweight endpoint deployment.
- Enable logging of login failures, access failures to operating system events etc.
- Don’t have computers in the reception connected to the corporate network such as guest access systems.