Automated certificate discovery: finding the certs nobody registered

Every certificate incident starts the same way: someone asks which team owns the cert, and nobody can find it in the spreadsheet. Discovery is not a one-time CMDB project. Hostnames move, SANs get added at the load balancer, acquisitions import unknown CAs, and shadow issuance shows up in Certificate Transparency before your inventory does. Automated discovery means running complementary methods on a schedule — not exporting certmgr once a year.

Method 1: network TLS scanning

Network TLS scanning probes IP ranges and ports, handshakes with live endpoints, and records the served leaf (and often the chain). It finds what the internet or your internal network can reach: VIPs, forgotten dev hosts, appliances listening on 443. It misses internal-only services with no scanner route, client authentication certificates that never present on a listener, and hosts that block automated probes. Scanning answers what is live right now, not what was issued last month to a decommissioned name.

Method 2: Certificate Transparency monitoring

Certificate Transparency logs capture every publicly trusted TLS certificate shortly after issuance. Searching CT for your domains surfaces hostnames your teams never ticketed — including rogue or mistaken issuance if an attacker or a rushed deploy obtained a cert outside your process. The ecosystem is documented at certificate.transparency.dev. CT does not see private-CA certificates, internal enterprise CAs, or most code-signing certs. Pair CT with network scans: CT finds names; scans find what actually terminates TLS today.

Method 3: cloud and API inventory

Cloud and API inventory queries control planes where certificates already live as managed objects: Azure Key Vault, AWS ACM, GCP Certificate Manager, load balancer listener configs, API gateway custom domains. This layer is fast and authoritative for cloud-native estates. It misses file-based PEM bundles on VMs, certs baked into container images, and appliances whose API you have not integrated. The shadow certificate in CT logs post shows how auditors can enumerate your public footprint before your cloud inventory catches up.

Method 4: agent and configuration scanning

Agent and configuration scanning on hosts reads keystores, nginx and Apache configs, Kubernetes secrets references, and automation vault paths. Agents excel at where the private key actually lives — the gap between issued in ACM and deployed on the instance behind it. They require deployment footprint and permission models; they do not replace passive CT or external scanning for assets you do not own agents on yet.

Why discovery must be continuous

Why continuous discovery matters: certificates are created at the speed of projects, not at the speed of quarterly audits. A one-shot discovery project decays the week a product team adds a staging hostname. Mergers import estates nobody mapped — see inherited certificates after an acquisition. Renewal automation without fresh discovery renews the inventory you had, not the inventory you have. Discovery feeds expiry alerts, names the owning team, and catches new SANs before they share a wildcard with production.

Run all four methods where they apply, reconcile duplicates by serial or fingerprint, and diff against yesterday. Alerts on net-new certificates and on certificates that disappeared from endpoints but still show issued in a CA portal. That loop is the floor for everything else — issuance automation, deployment hooks, audit registers. Treat discovery drift like security drift: new listeners and new SANs are normal change, not exceptions you fix at year-end.

Ownership completes the loop

Ownership metadata completes the picture. A discovered cert without a team is a cert that will expire into a shared inbox. Tag sources (CT versus agent versus cloud API) so operators know whether to fix DNS, redeploy a listener, or revoke mistaken issuance. Discovery outputs should feed expiry thresholds and renewal workflows — not a static PDF filed after onboarding.

Automate Certificates combines continuous discovery, cloud API inventory, and agent-driven collection into a single inventory with renewal history — without acting as a certificate authority. Explore continuous discovery and alerting in features.