Certificate discovery and inventory
Most outages come from the certificate nobody knew about. Every aethercert agent scans its own host for installed certificates and reports them, so the inventory shows what is actually there - not only what aethercert issued.
Discovery and the inventory are included in every plan. See plans and limits
What it does
The agent enumerates the Windows certificate stores that serving certificates live in - LocalMachine\My, WebHosting, Remote Desktop and others - and certificate files under the usual Linux locations such as /etc/ssl, /etc/pki, /etc/letsencrypt/live, /etc/nginx and /etc/postfix. You can add your own scan paths.
Certificates it finds appear in the dashboard as discovered, next to the ones aethercert manages: subject, SANs, issuer, validity, fingerprint and every location the same certificate was found at. Discovered certificates are read-only - aethercert does not change them - but they get expiry tracking like every other certificate.
How it works
- 01
Scan on the host
The agent reads public certificate material from stores and files. Operating-system trust stores are skipped so the inventory is not buried in root CAs.
- 02
Report
Each distinct certificate is reported once, with all of its locations and whether a private key is present in that Windows store.
- 03
Merge
The control plane marks certificates it issued as managed and everything else as discovered.
- 04
Watch
Every certificate in the inventory is checked for expiry; certificates within 14 days raise an expiring-soon event.
Key capabilities
Windows stores and files
Certificate stores on Windows; PEM, CRT and similar files on Linux and Windows.
Managed and discovered in one list
Sort by expiry across everything, regardless of who installed it.
Every location
The same certificate installed in three places shows up once, with all three locations.
Full X.509 details
Subject, SANs, issuer, serial, key algorithm and size, validity and fingerprints.
Custom scan paths
Add directories or files on top of the platform defaults per agent.
Bounded by design
Scans are limited in depth, file size and count, so a mistyped path cannot turn into an unbounded walk.
Compared with a manual inventory
| By hand | With aethercert |
|---|---|
| A spreadsheet compiled once and out of date a week later. | Each agent reports what is installed on its host on every scan. |
| Certificates imported by hand years ago are forgotten. | They show up as discovered, with their expiry date. |
| Checking a certificate means logging on to the server. | Subject, SANs, issuer and locations are in the dashboard. |
Where it looks
Discovery runs on every host with an aethercert agent - Windows and Linux.
Security considerations
Private keys are never read
The scan parses public certificate material only. On Windows it records whether a key exists, never the key itself.
Host-local only
Discovery runs on the host the agent is installed on. aethercert does not scan your network or probe ports.
Read-only
Discovered certificates are not modified. Bringing one under management means issuing a managed replacement.
Example: a newly enrolled Windows server
What the inventory shows minutes after an agent is installed on exch-01.
scanLocalMachine\My and WebHosting enumerated; 4 serving certificates found.reportmail.example.com, autodiscover.example.com and two internal certificates reported.mergeAll four listed as discovered, sorted by expiry with every other certificate.alertOne expires in 9 days: certificate.expiring_soon is written to the event log.
Frequently asked questions
Certificate inventory
Does aethercert scan my network for certificates?
No. Discovery runs on each host that has an agent, against that host's own certificate stores and files. There is no network or port scanning.
Can aethercert renew a discovered certificate?
Discovered certificates are read-only. To automate one, create a managed certificate for the same names with a deploy target; the discovered one can then be retired.
Are private keys uploaded?
No. Only public certificate data and its locations are reported.
See what is installed on your servers
Enroll an agent and its certificates appear in the inventory on the first scan.
Community plan, no card required. Open registration - your account is ready in a few minutes.