Discover Certificates in your Network35 minutes to read
You can automatically discover all the certificates available in your network using Key Manager Plus, irrespective of the CA. You can discover the certificates anytime as needed or periodically based on scheduled tasks. The discovery options are quite flexible - you can discover certificates from a single server or multiple servers, and from multiple ports, at one go. Key Manager Plus also allows users to rediscover the expired and about-to-expire certificates from the 'Certificate Expiry' widget in the Dashboard.
1. Configuring Discovery SettingsNote: Discovery settings are aplicable from build 7010 and above only. Key Manager Plus automatically discovers SSL certificates using default discovery settings. However, users can customize these settings to optimize efficiency and performance based on their specific requirements. To manually configure SSL discovery settings, follow these steps:
If you have set the thread count above 20, you may experience performance issues when Key Manager Plus executes large operations alongside the SSL discovery. In such cases, we recommend increasing the application memory for Key Manager Plus. To do so, please follow the below steps:
Customizing these settings allows users to optimize SSL discovery based on network conditions and performance requirements. 2. SSL Discovery Methods Available in Key Manager Plus2.1 Discover SSL Certificates on DemandTo discover the certificates manually:
Note: The file to be imported must be a text file containing the hostname or IP addresses of individual servers, entered on separate lines. Enter the ports to scan on each server separated by a space, entered on separate lines as illustrated below: 0.0.0.0 6565 If you do not specify any port, SSL certificates using the default port 443 will be discovered.
Click Discover. When you click the Discover button, you will be redirected to the Discovery Audit page where the status of the current discovery instance is updated. 2.2 Discover SSL Certificates Automatically through SchedulesSSL Certificate discovery can also be scheduled to occur at periodic intervals.
You will get a message confirming addition of a new schedule. The result of the schedule execution will get updated in the Schedule audit and the Discovery audit tabs. 2.3 Discover Certificates Mapped to User Accounts in Active DirectoryKey Manager Plus helps you discover and manage the certificates mapped to user accounts in Active Directory. To perform AD user certificate discovery,
2.4 Manage Certificates from MS Certificate Store and Local CAKey Manager Plus helps you request, acquire, discover, consolidate, track, and manage certificates from the MS Certificate Store and those issued by Local certificate authority. To begin managing certificates from the MS Certificate Store and Local Certificate Authority, start the Key Manager Plus service using your domain administrator account. If you are using a domain service account to run Key Manager Plus, ensure you have configured the account in your local admin group beforehand. To import certificates from the Microsoft Certificate Store and certificates issued by Local CA,
2.5 Discover SSL Certificates from SMTP ServersYou can discover SSL certificates used by mail servers present in your network and consolidate them in Key Manager Plus' centralized certificate repository. To perform mail server certificate discovery,
On successful discovery, the certificates are fetched from the specified resources and added to Key Manager Plus' repository. 2.6 Discover SSL Certificates from Load BalancersKey Manager Plus also allows you to discover SSL certificates deployed to load balancers within your network and consolidate them in its secure, centralized repository. Key Manager Plus currently supports certificate discovery from Linux-based load balancers only (i.e., Nginx, F5, Citrix etc.,) and the process is tunneled via SSH. To perform load balancer certificate discovery,
Certificate files discovered with extensions .keystore and .pfx require their passphrases to be provided to import the certificates into Key Manager Plus. These types of certificate files are grouped separately under the JKS/PKCS section (located in the top-right corner of the window). Manual Import of Certificates from JKS/PKCS Files into Key Manager Plus Repository:To import the certificates, select JKS/PKCS, and in the window that appears, choose the certificate file from which you wish to import the certificates and click Import from the top menu. In the popup that appears, provide the certificate file's passphrase and click Import. The selected file will be verified with the provided password, and the relevant certificates will be successfully imported and added to Key Manager Plus' certificate repository. Automatic Import of Certificates from JKS/PKCS Files into Key Manager Plus Repository:To automate the import of certificates from the JKS/PKCS files after the discovery process, follow these steps:
How does this Assign Passwords Work during the Discovery Process?For example, in a certificate discovery process for Citrix, fill in the respective fields as mentioned above for the certificate discovery and click Assign Passwords. In the pop-up that opens, select the file with the JKS/PKCS filenames and passwords relevant to the Citrix load balancer's server and click Use Passwords. Upon certificate discovery from the Citrix load balancer, the discovered JKS/PKCS files will be matched with the file names provided in the uploaded file. If the file name matches, it will verify the password, and the respective certificates will be automatically imported into the SSL section of the Key Manager Plus repository. 2.7 Discover SSL Certificates from a Shared Directory PathKey Manager Plus allows you to discover SSL certificates that are saved in a shared directory path within your network and consolidate them in its secure, centralized repository. Using this option, you can discover all the certificate files saved in a particular folder and then, either add all the certificates to the repository or choose the ones you want to import. During the discovery process, Key Manager Plus will scan only the folder specified in the path and nowhere else in the target machine. Follow the below steps to discover and import SSL certificates from a shared directory path:
To check the status of the discovery, click the Discovery Audit tab. Note: Certificate files that are over 30 KB in size will not be imported during this discovery operation. 2.8 Discover SSL Certificates using KMP AgentsKey Manager Plus provides IT administrators the option to discover SSL certificates deployed across their network through agents. This functionality enables them to download and deploy Key Manager Plus agents to target systems, discover, and import certificates from those systems into a centralized certificate repository directly from the Key Manager Plus web interface. The connection between the Key Manager Plus server and the server(s) in which the agent is deployed is over HTTPS and is completely secure. Currently, Key Manager Plus agents are available only for Windows servers. Performing certificate discovery through agents is helpful in the following scenarios:
Steps to perform SSL certificate discovery through Key Manager Plus agent:
The certificates are discovered from the servers in which the agent is installed and imported into Key Manager Plus' certificate repository. a. Discover SSL Certificates from a Directory Path in a Remote MachineKey Manager Plus allows you to discover SSL certificates that are saved in a directory path in a remote machine that is not directly accessible by the Key Manager Plus server—this is achieved through the Key Manager Plus agent. Once the certificates are discovered, you can consolidate them into Key Manager Plus's centralized repository. Using this option, you can discover all the certificate files saved in a particular folder and either add all the certificates to the repository or select only the ones you require. During the discovery process, the Key Manager Plus agent will scan only the folder specified in the path and nowhere else in the target machine. Follow the below steps to discover and import SSL certificates from a directory path in remote machine:
To check the status of discovery, click the Discovery Audit tab. Notes: 2.9 Discover SSL Certificates Hosted on AWS (ACM & IAM)Key Manager Plus enables you to discover, import, and configure expiry notifications for SSL certificates hosted in the following Amazon Web Services: AWS Certificate Manager (ACM) and AWS Identity and Access Management (IAM). Follow the steps below to discover and import SSL certificates from ACM / IAM into Key Manager Plus. Step 1: Configure AWS credentials in Key Manager Plus To add your AWS credentials in Key Manager Plus,
Step 2: Discovery and Import
User certificates are imported into Key Manager Plus. 3. Rediscover SSL CertificatesFrom KMP build 6000 onwards, Key Manager Plus allows you to rediscover SSL certificates from the same source using the server details entered during the previous discovery operation. Follow the below steps to perform certificate rediscovery:
![]() The rediscovery operation begins immediately. You can track the discovery status in the Discovery Audit page. Please note that for agent-based discovery to work properly, upgrade Key Manager Plus Agent to version 6000 before commencing the discovery operation. 4. Centralized Certificate RepositoryAll the discovered SSL certificates, those that are discovered manually as well as those discovered through scheduled discovery operations are automatically added to the centralized repository of Key Manager Plus. You can view these certificates from the SSL >> Certificates tab in the user interface. 4.1 Search SSL CertificatesKMP allows you to search certificates using Common Name, DNS Name, Issuer, Key Size, Signature Algorithm, Description, additional fields, etc.
5. Export Private Key / Keystore FileKey Manager Plus allows you to identify and export the private keys / Keystore files of SSL certificates stored in the certificate repository. You can also export certificates in other formats such as PKCS12/PFX or PEM format. Click the Keystore icon ( To export the private key or the certificate file:
6. Update Servers with Latest Certificate VersionsIn case of wildcard certificates or single SSL certificate deployed to multiple servers, it is necessary to keep track of servers in which the certificate is deployed and also check if the latest certificate version is in use. Key Manager Plus helps you ensure this.
Also, you can edit details pertaining to a particular certificate or delete irrelevant certificates by selecting the certificate and clicking the More dropdown. ©2025, Zoho Corporation Pvt. Ltd. All Rights Reserved. |