SCANTIDE AUDITOR
Scantide Auditor Guide

Why Internal TLS Certificates Deserve Review Too

Internal HTTPS, management interfaces and appliances often use certificates that expire quietly or contain unexpected names. Internal trust failures can disrupt administration just as effectively as public certificate failures.

Technical guideUpdated 25 September 2026Scantide Auditor
Short answer: Internal HTTPS, management interfaces and appliances often use certificates that expire quietly or contain unexpected names. Internal trust failures can disrupt administration just as effectively as public certificate failures.

Internal does not mean certificate-free

Hypervisors, storage systems, BMCs, application portals and management tools increasingly use HTTPS internally.

Expiry creates operational outages

An expired internal certificate may break automation, API integrations or administrator workflows even when no public user ever sees it.

Names reveal configuration drift

Certificates can expose old hostnames, unexpected domains or systems that were cloned without updating identity.

Auditor can collect TLS clues during discovery

When reachable services expose TLS, Scantide Auditor can use certificate and service evidence as part of the inventory and follow-up process.

Practical depth: examples, failure modes and what to verify

Source note: current Scantide material describes the present platform. Older JufCorp/Red Cloud material is retained as field experience and historical context. Old product names, versions and configuration examples are not presented as current requirements.

Current Scantide detail

Current Scantide source: Windows Network Auditor and Internal Asset Discovery

Discover Windows network assets, exposed services and useful operational evidence with Scantide Auditor, designed for authorized internal visibility and readable reporting.

Current Scantide source: Scantide Auditor – Agentless Internal Network Discovery and Security Visibility

Scantide Auditor provides authorized internal network discovery, asset inventory, service visibility, CMDB review and readable evidence reports for Windows and Linux environments.

Current Scantide source: Agentless Network Discovery for Servers and Infrastructure

Scantide Auditor helps administrators discover and document devices, exposed services and useful evidence across authorized internal networks without deploying a heavy endpoint agent to every target.

Current Scantide source: Shadow IT and Rogue Server Discovery

Use Scantide Auditor to identify reachable internal systems and compare findings with expected assets to support shadow IT and rogue server discovery.

Current Scantide source: Linux Network Auditor and Internal Discovery

Use Scantide Auditor in Linux environments for authorized network discovery, service visibility and infrastructure evidence without a heavyweight endpoint deployment.

Field experience from the archive

Historical source · JufCorp: Securing your server environment - Part III - Operating systems

Whatever you'll be using your server for. have a look at any information that it "bleeds". This could for instance be headers telling any attacker exactly what version of software you're running. If possible, try to hide such information. There's no need for it to be visible and help a hacker find a way in. Simple checks using telnet to the ports your services might reveal some interesting information . Sadly, it's not possible to remove all headers etc but you should give it a go and remove as many as possible While on the subject, use SSL-certificates for any service where possible. Also make sure to set it up correctly (disable weak ciphers, enable HSTS, set correct HTTP headers, set TLS correctly etc ) . Have a look at Letsencrypt for instance for SSL certificates. It's free, supported by basically everyone and it'll probably get the job done for you . All you have to remember is to check that your certificates are renewed every three months.

Enable logging of login failures, access failures to operating system events etc. In short, log everything. It'll impact performance and use up disk but it's useful for troubleshooting when the time comes.

Historical source · JufCorp: Securing server environments – part II – Networking

Don’t have computers in the reception connected to the corporate network such as guest access systems. There is absolutely no need for external visitors to be able to browse your internal network.

Historical source · JufCorp: Security Reality Check: Why a Perfect Score Doesn't Mean You're Safe

A developer spins up a test server, forgets about it after project ends. Server runs outdated software with default passwords. Attackers find it, use it as entry point to internal network. This happens more often than you think.

Historical source · JufCorp: Securing your servers, users and customers online

Using MITM (Man In The Middle) attacks is also popular method if you haven't secured your server and your communications with valid SSL certificates. Quite a few actually use self-issued certificates on the websites and on their OWA site and that's not a good thing. When someone who knows what they're doing connect to a site that has a self issued certificate the first thing that comes to mind is .."hmm .. these sysadmins are cheap and lazy and I'm fairly sure they just set this server up using default values.. let's have a look, eh?" .. )

Write your DRP (link in Swedish, sorry ) from the perspective that you're gone (in the freak barbecue accident) and the person reading it has never ever heard of your internal system before.

Practical review checklist

Frequently asked questions

Are self-signed certificates always wrong internally?

No. They can be acceptable in controlled environments, but trust and lifecycle should still be managed.

Why inventory internal certificates?

Because expiry and identity drift can cause outages and reveal unmanaged systems.

Check the evidence with Scantide Auditor

Agentless internal network discovery and security visibility. Scantide is designed to show observable evidence and readable context rather than turn every observation into a vulnerability claim.

Explore Scantide AuditorMore guidesAll Scantide guides