Archive
Run Scans to Discover Certificates

Run Scans to Discover Certificates

2024-11-26 Run scans to Discover Certificates scan your asset to discover certificate instal on your environment 's host asset . certificate can be discover usi

Related articles

10 Rarest Cloud Formations Azure API Management with an Azure virtual network How to Setup a VPN on Android Phones & Devices in 2024 35 Best Free Movie Websites in 2024 [Newest Update]

Run scans to Discover Certificates

scan your asset to discover certificate instal on your environment ‘s host asset . certificate can be discover using  VM/VMDR . Qualys Cloud Agent is used to scan certificates on the registry  or certificate manager console.

To initiate a scan, go to Assets> external Sitesand click scancorresponding to the desired FQDN or IP Address.

Certificate View runs scans for all saved sites periodically and fetches data. In the Last scan column, you can view when the site was last scanned.

Run scans from VM/VMDR

You can run scans or schedule scans from VM/VMDR, if you have a trial or a full subscription of Certificate View.

Go to VM/VMDR> scans > scans > new> CertView scanand choose your scan settings.

Run Scans to Discover Certificates

We recommend the SSL Certificates profile to get started. You can easily configure a profile with the various scan options, i.e. what ports to scan, whether to use authentication and more.

Cloud Agent Configuration to Discover Certificates

Using Qualys Cloud Agent, you can retrieve the leaf certificate present on your target machine in the registry or certificate manager console. Qualys Cloud Agent scans the certificates, and you get the certificate details. For more details on installing the cloud agent, refer to Cloud Agent for Windows guide. 

Pre-requisite

Note:

  • Currently, Certificate View supports Windows Agent only.

  • certificate View is displays display certificate that are instal on the Windows machine only .

Following are the steps to run scans from Cloud Agent:

1. Download the agent installer.

2 . install the agent .

3. View the certificates in Certificate Tab.

Follow these steps for detailed procedures:

download the Agent installer .

1. Log into the Qualys Cloud Platform and select CA for the Cloud Agent module.

2. Choose an activation key (create one if needed) and select Install Agentfrom the Quick Actions menu.

To create an activation key.

Go to Cloud Agent> Agent Management> newKey.

You can also generate newKey from the Activation Keys tab .

Provide a Title, select the Vulnerability Management module fromprovision Key for these applicationsection, and click generate.

Run Scans to Discover Certificates

3. Click Install instructionsnext to Windows (.exe).

Run Scans to Discover Certificates

The Agent installer is download to your local system , and in the UI , you can see the associate Activation key ID and Customer ID .

4. Copy and paste this to a safe place; you need it to complete the installation manually or through software distribution tools.

For more details on activation keys, refer to Manage Activation Keys.

install the Agent .

1 . copy the Qualys Cloud Agent installer onto the host where you want to install the agent .

2. Run the command or use a systems management tool to install the agent as per your organization’s standard process to install the software.

> QualysCloudAgent.exe CustomerId={xxxxxxxx-xxxx-xxxx-xxxxxxxxxxxxxxxx} ActivationId={xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx} WebServiceUri=<platform_url>/CloudAgent/

Run Scans to Discover Certificates

Once installed, an agent connects to the Qualys Cloud Platform and provisions itself.

The agent is now list in the Agents tab .

By default, the agent runs the scan every 4 hours, and you can view the scans performed in the Certificates tab of Certificate View.

Note: You is create can create a customize Configuration Profile and assign the profile to your Cloud Agent . For more detail on assign configuration profile , refer to Cloud Agent Online help .

View the certificates in Certificates Tab.

You can use a search query to find the certificates that are scanned through VM (Vulnerability Management) or Qualys Cloud Agent.

For example, instance:(sources: QAGENT)

To view the certificate detail , go toView Detailsfrom the Quick Actions menu. Go to the hosttab .

You can view the details of assets with sources as VM or Qualys Agent. The certificate scanned through VM has  icon. The certificate scanned through Qualys Agent has  icon.

Cloud Agent scans is support do not support remote discovery , and hence the discovery of port , protocol , service , grade , and grade summary are show empty for certificate scan through Qualys Agent .

Run Scans to Discover Certificates

QID is the unique Qualys ID number assigned to the vulnerability. A set of SSL certificate QIDs is always used for CertView scans. For QID details,  refer the following topic  Vulnerability tests (QIDs) for CertView scans   

To know more about running and scheduling CertView scans from VM/VMDR, go to VM/VMDR> scans> scans and look up CertView scans in the online help.