Certificate discovery and TLS security posture
Find local certificates and certificate files, understand expiry and chain health, review private-key readiness, and see TLS client/server posture without automatically changing the server.
See what the server is actually storing
Windows certificate stores
Inspect applicable local-machine certificate stores for subject/SAN, issuer, expiry, chain state, private-key presence/accessibility and exportability information where Windows exposes it.
Certificate files
Discover PFX, P12, PEM, CER, CRT and related certificate files in known and configured paths. Password-protected or unreadable PFX files remain visible as findings.
Likely consumers
Correlate useful hints from HTTP.sys, RDP and application-oriented paths such as CrushFTP, with Linux web/proxy configuration hints where supported.
Graphical findings, with raw evidence when you need it
After a sweep, Guard prioritizes expired, expiring and problematic certificates rather than returning only a count. Individual findings can show the certificate identity, source store or file path, expiry, chain state, private-key state, likely consumer and replacement-readiness status. Technical details remain expandable for troubleshooting.
Client and server TLS are not the same setting
On Windows, Guard reports Schannel protocol posture separately for Server and Client. This makes it clear when an old protocol is disabled for inbound services but still available for outbound client connections, or vice versa. Relevant .NET strong-cryptography/system-default and available cipher/hash policy evidence is included in the posture report.
Linux Guard reviews available OpenSSL/system crypto policy and supported Nginx, Apache or HAProxy protocol configuration evidence. Raw configuration data stays available under expandable technical details.
Validate before Guard is ever allowed to replace
Where a supported renewal provider is configured, Guard can test provider access, download the currently issued certificate and chain, and validate DNS coverage, key continuity and chain material. A successful readiness check means the evidence suggests a future controlled replacement may be possible. It does not install or bind the certificate in 0.8.2.
Bring certificate and TLS posture into fleet visibility
Managed Guards can report a compact last-known certificate and TLS/cryptography posture to Scantide Guard Datacenter. Administrators can review server-by-server posture alongside normal Guard operational status instead of logging into each host separately.
Explore Scantide Guard DatacenterFrequently asked questions
Does Guard renew or replace certificates in 0.8.2?
No. The current implementation is reconnaissance and validation-only.
Can it find a PFX used by applications such as CrushFTP?
Guard can discover certificate files in known/configured locations and show likely-consumer hints. Exact application binding correlation will continue to be expanded.
Does Guard distinguish TLS client and server settings?
Yes. Windows Schannel client and server protocol posture is presented independently.
Does Guard automatically disable TLS 1.0 or 1.1?
No. Guard reports posture and may suggest administrator-controlled remediation; it does not change TLS policy automatically.
Certificate posture as part of Guard, not another isolated scanner
Combine certificate/TLS reconnaissance with server protection, assessments, CVE/lifecycle visibility, Custom Monitors and centralized Datacenter reporting.
Scantide Guard