Skip to content

Step 4 of 8

A network scan finds the servers that answer on your network and reads the certificate on each TLS port. On day one you get an overview of expiry dates and can see which servers need a service agent.

Nothing in the following steps depends on the scan. To go straight to the first certificate, continue to step 5, Connect servers. The certificates on a server with a service agent are found automatically when the agent reports in.

The scan runs from the appliance, so the appliance must be able to reach the addresses you scan.

  1. Open Find servers › Discovery. The page is headed Discovery.

  2. Click New network scan.

  3. Under IP ranges, enter the addresses to scan, one per line: single IP addresses, CIDR ranges such as 192.168.1.0/24, or address ranges.

  4. Leave Ports as it is, unless you want to scan ports other than the defaults (see below). A name for the scan is optional.

  5. Click Start scan.

The result is listed under Discovered servers with IP address, hostname, operating system, open ports and when the server was last seen. The Discovered certificates card shows how many different certificates the scan has seen on the TLS ports. Scan history shows the scans that have run.

Click Details on a server to see each port with issuer, expiry date and a grade for the TLS configuration. From there you can:

  • click Enable, so the appliance scans the server’s TLS ports again every night at 04:00;
  • click Manage, so the server is created in sslbrain. A Windows server gets certificates installed through the service agent (step 5).

Unless you give other ports, the appliance scans the 24 ports below and the ports that installed agent packages declare:

22, 25, 110, 135, 143, 389, 443, 445, 465, 587, 636, 993, 995,
1433, 3306, 3389, 5001, 5432, 5985, 5986, 8006, 8080, 8443, 9090

Tick OS detection (no TLS) to only guess the operating system, without reading certificates.

Find servers › TLS scanning reads the certificate on one address and port and grades the connection.

  1. Open Find servers › TLS scanning. The page is headed TLS Scanner.

  2. Click New scan.

  3. Enter the hostname and port, for example intranet.example.com and 443, and start the scan.

The result shows the certificate and a Grade for the TLS configuration. The appliance must be able to resolve the name and reach the port.

Scheduled network scanning is off until you switch it on and enter addresses. It is set up under Find servers › Settings. The page is headed Discovery. Everyone can see the page; only an administrator can save.

FieldDefaultWhat it does
Aktiver discoveryoffSwitches the scheduled scan on.
ScanfrekvensDagligtHver time (hourly), Dagligt (daily) or Ugentligt (weekly). The appliance checks every hour whether the next scan is due.
IP-intervalleremptyCIDR ranges separated by commas, for example 10.0.0.0/24, 192.168.1.0/24. Without ranges, nothing is scanned.
PorteemptyEmpty means the default ports above, whatever ports the help text below the field mentions.
Ekstra TCP-porteemptyPorts that are only checked for being open.
Ekstra direkte TLS-porteemptyPorts where the appliance also attempts a TLS connection and reads the certificate.
Opbevaringstid (dage)90Discovered servers that have not been enabled, and scans, are deleted after this many days.
TCP probe threads3How many connections the scan attempts at the same time.
Delay mellem batches (ms)0A pause between each batch of connections, so the scan puts less load on the network.

Click Save settings.

Certificates › Found on servers shows valid certificates that sslbrain has not installed itself. The list fills up when a service agent reports in and reads the server’s certificate store, and with certificates from Windows CA and certificates you upload without a profile. See Discovery on the server.

sslbrain does not renew the certificates on this list. If one of them should renew automatically, create a rule for the server in step 8.

Certificates that expired within the last 90 days are under Certificates › Expired, and certificates superseded by a newer one under Certificates › Replaced.

A certificate that neither the scan nor an agent can reach can be uploaded, so you can keep an eye on its expiry date.

  1. Open Certificates and click Upload certificate.

  2. Choose the file under Certificate file. The formats are PEM, CRT, CER, DER, PFX, P12 and JKS, up to 5 MB per file.

  3. Add the private key, the chain (PEM) and the password for a PFX, P12 or JKS file, if you have them. Certificate display name is optional.

  4. Click Upload certificate.

Without a private key, the certificate is used only to monitor its expiry. With the key, it can be installed on a server. An uploaded certificate is not renewed through a CA, and an upload does not install anything.

  • Find servers › Discovery lists the servers under Discovered servers with their open ports.
  • Details on a server shows the expiry date and issuer for each TLS port.
  • An uploaded certificate is listed under Certificates.
  • The scan finds no servers: the appliance must be able to reach the scanned addresses. Check that any firewall between the appliance and the network allows the connections. See The server cannot be reached.
  • The scheduled scan does not run: Aktiver discovery must be switched on, and IP-intervaller must not be empty.
  • Found on servers is empty: the list only fills up once a service agent has reported in. See step 5.