Skip to main content
TLS endpointshosts · devicesScanner agentsnetwork + agent-based fleetDiscoveredcertificatesImport to inventorybring under managementSSL / TLS auditper-certificateComplianceMozilla · NIST · PCI DSS
Network and agent-based scanners discover every certificate across the estate — then import, audit and score them for compliance.
Applies to:
DuoKey Cockpit v2Network & agent-based scanningMozilla · NIST · PCI DSS

Overview​

You cannot manage what you cannot see. DuoKey's discovery subsystem finds certificates across your network and endpoints — including ones issued outside the platform — imports them for tracking, and evaluates each one's SSL/TLS posture against recognized compliance baselines.

Discover

Network scanners and installed agents locate TLS endpoints and certificates across the estate.

Import & track

Bring discovered certificates under management to monitor expiry and ownership.

Audit & score

Run a per-certificate SSL/TLS audit and evaluate compliance against Mozilla / NIST / PCI DSS.

Scanning​

Scanners can run from the network or via installed agents (a managed fleet with key rotation, revocation and downloadable install bundles). Discovered certificates can be reviewed and imported into the certificate inventory.

SSL/TLS audit and compliance​

Each discovered or managed certificate can be run through a per-certificate SSL/TLS audit, with history and re-runs, and evaluated against compliance frameworks (Mozilla configurations, NIST guidance, PCI DSS) or your own tenant policies.

API reference
Detailed API endpoints — for managing scanners and agents, importing discovered certificates, and running SSL/TLS audits and compliance evaluations — are documented separately in the Developer Docs → PKI API.
Tip

Pair discovery with the enrollment protocols and deployment tooling: find an out-of-policy or expiring certificate, re-issue it from a compliant CA, and deploy the replacement — all from one console.