Program product for discovering enterprise certificates
Disclosed herein are several digital certificate discovery and management systems. Detailed information on various example embodiments of the inventions are provided in the Detailed Description below, and the inventions are defined by the appended claims.
1 . A set of computer readable media containing computer instructions for operating a certificate discovery system for discovering digital certificates to servers on a network, the set of computer readable media comprising at least one medium upon which is stored the computer instructions executable by a computing system to achieve the functions of:
receiving an address range corresponding to a network or network portion to be scanned,
contacting network devices within the received address range, said contacting further intended to initiate the transmission of a digital certificate from each of the contacted network devices to said certificate discovery system,
for each contacted network device transmitting a digital certificate, receiving the digital certificate,
for each received digital certificate, creating a certificate record containing a certificate identification, wherein the certificate identification contains sufficient information to identify the received digital certificate and the network device from where it was transmitted, and
storing created certificate records.
2 . A set of computer readable media according to claim 1 , wherein said contacting includes probing IP port 443 using a secure sockets layer protocol.
3 . A set of computer readable media according to claim 1 , wherein said contacting includes probing IP port 80.
4 . A set of computer readable media according to claim 1 , wherein said contacting includes searching for certificates on network mountable file systems.
5 . A set of computer readable media according to claim 1 , wherein said contacting includes executing a search command for certificates in a shell interface.
6 . A set of computer readable media according to claim 1 , wherein said instructions are further executable to parse found certificates for dates of validity.
7 . A set of computer readable media according to claim 1 , wherein said instructions are further executable to parse found certificates for issuing certificate authorities.
8 . A set of computer readable media according to claim 1 , wherein said storing stores certificate records to a database.
9 . A set of computer readable media according to claim 8 , wherein said instructions are further executable to merge created certificate records with a database produced from earlier discovery activity.
10 . A set of computer readable media according to claim 1 , wherein said instructions are further executable to identify the type of servers located to the network devices.
11 . A set of computer readable media according to claim 10 , wherein said instructions are further executable to store server types to a database.
12 . A set of computer readable media containing computer instructions for operating a certificate discovery system for discovering digital certificates to servers on a network, the set of computer readable media comprising at least one medium upon which is stored the computer instructions executable by a computing system to achieve the functions of:
receiving an address range corresponding to a network or network portion to be scanned,
contacting network devices within the received address range, said contacting further intended to initiate the transmission of a digital certificate from each of the contacted network devices to said certificate discovery system, said contacting including probing of IP port 443 using a secure sockets layer protocol,
for network devices having servers installed thereto, attempting to identify the type of server for each,
for each contacted network device transmitting a digital certificate, receiving the digital certificate,
for each received digital certificate, parsing the certificates to retrieve beginning and ending dates of validity,
for each received digital certificate, creating a certificate record containing a certificate identification, wherein the certificate identification contains sufficient information to identify the received digital certificate and the network device from where it was transmitted, and
storing created certificate records to a database.
13 . A set of computer readable media according to claim 12 , wherein said instructions are further executable to parse found certificates for issuing certificate authorities.
14 . A set of computer readable media according to claim 12 , wherein said instructions are further executable to merge created certificate records with a database produced from earlier discovery activity.
15 . A set of computer readable media according to claim 12 , wherein said instructions are further executable to store server types to a database.
16 . A set of computer readable media containing computer instructions for operating a certificate discovery system for discovering digital certificates to servers on a network, the set of computer readable media comprising at least one medium upon which is stored the computer instructions executable by a computing system to achieve the functions of:
receiving an address range corresponding to a network or network portion to be scanned,
contacting network devices within the received address range, said contacting further intended to initiate the transmission of a digital certificate from each of the contacted network devices to said certificate discovery system, said contacting including attempting to access the file systems of the network devices to search for certificates installed thereto,
for network devices having servers installed thereto, attempting to identify the type of server for each,
for each contacted network device transmitting a digital certificate, receiving the digital certificate,
for each received digital certificate, parsing the certificates to retrieve beginning and ending dates of validity,
for each received digital certificate, creating a certificate record containing a certificate identification, wherein the certificate identification contains sufficient information to identify the received digital certificate and the network device from where it was transmitted, and
storing created certificate records to a database.