PAM
TLS Certificate Discovery
CoreLink scans external domains and internal IP ranges to automatically discover deployed TLS certificates. Each certificate is fingerprinted by serial number, subject, issuer, SANs, and expiry date. Discovered certs appear in the Certificate Inventory alongside secrets-vault-managed certs, giving operators a unified view.
Scheduled rescans detect newly deployed certs and flag those approaching expiry or using deprecated cipher suites.
Key Configuration
- Scan targets (CIDR ranges / domain lists)
- Scan interval
- Expiry warning threshold (days)
- Alert channels for approaching expiry