Scantide Guard 0.8.2 · reconnaissance and validation

Certificate discovery and TLS security posture

Find local certificates and certificate files, understand expiry and chain health, review private-key readiness, and see TLS client/server posture without automatically changing the server.

Under development. The 0.8.2 certificate workflow is deliberately read-only. Guard does not automatically replace certificates, export private keys, alter trust roots or rebind IIS, RDP, Exchange, CrushFTP or other services. Test thoroughly before relying on the results in production.
Certificate reconnaissance

See what the server is actually storing

Windows certificate stores

Inspect applicable local-machine certificate stores for subject/SAN, issuer, expiry, chain state, private-key presence/accessibility and exportability information where Windows exposes it.

Certificate files

Discover PFX, P12, PEM, CER, CRT and related certificate files in known and configured paths. Password-protected or unreadable PFX files remain visible as findings.

Likely consumers

Correlate useful hints from HTTP.sys, RDP and application-oriented paths such as CrushFTP, with Linux web/proxy configuration hints where supported.

Graphical findings, with raw evidence when you need it

After a sweep, Guard prioritizes expired, expiring and problematic certificates rather than returning only a count. Individual findings can show the certificate identity, source store or file path, expiry, chain state, private-key state, likely consumer and replacement-readiness status. Technical details remain expandable for troubleshooting.

TLS and cryptography

Client and server TLS are not the same setting

On Windows, Guard reports Schannel protocol posture separately for Server and Client. This makes it clear when an old protocol is disabled for inbound services but still available for outbound client connections, or vice versa. Relevant .NET strong-cryptography/system-default and available cipher/hash policy evidence is included in the posture report.

Linux Guard reviews available OpenSSL/system crypto policy and supported Nginx, Apache or HAProxy protocol configuration evidence. Raw configuration data stays available under expandable technical details.

Renewal readiness

Validate before Guard is ever allowed to replace

Where a supported renewal provider is configured, Guard can test provider access, download the currently issued certificate and chain, and validate DNS coverage, key continuity and chain material. A successful readiness check means the evidence suggests a future controlled replacement may be possible. It does not install or bind the certificate in 0.8.2.

Datacenter

Bring certificate and TLS posture into fleet visibility

Managed Guards can report a compact last-known certificate and TLS/cryptography posture to Scantide Guard Datacenter. Administrators can review server-by-server posture alongside normal Guard operational status instead of logging into each host separately.

Explore Scantide Guard Datacenter

Frequently asked questions

Does Guard renew or replace certificates in 0.8.2?

No. The current implementation is reconnaissance and validation-only.

Can it find a PFX used by applications such as CrushFTP?

Guard can discover certificate files in known/configured locations and show likely-consumer hints. Exact application binding correlation will continue to be expanded.

Does Guard distinguish TLS client and server settings?

Yes. Windows Schannel client and server protocol posture is presented independently.

Does Guard automatically disable TLS 1.0 or 1.1?

No. Guard reports posture and may suggest administrator-controlled remediation; it does not change TLS policy automatically.

Certificate posture as part of Guard, not another isolated scanner

Combine certificate/TLS reconnaissance with server protection, assessments, CVE/lifecycle visibility, Custom Monitors and centralized Datacenter reporting.

Scantide Guard