Skip to main content

Agent Mode - Persistent Agent & Host Inventory

Applies to:
Windows / Linux / macOSPersistent Cockpit AgentHost Inventory ScanSSH Key DiscoveryCertificate Store Inventory (Windows)v1.0.0
Status

Implemented - Available in v1.0.0. This page covers two distinct capabilities: the persistent agent daemon that keeps a host connected to DuoKey Cockpit, and the one-shot inventory command that performs a full local-host cryptographic discovery scan.

Overview​

Two distinct commands

agent is a long-running process that connects a host to a DuoKey Cockpit server and reports periodic heartbeats — it does not scan anything by itself. The one-time, full local-host cryptographic inventory is a separate command, inventory, covered in the second half of this page.

Use the persistent agent when you want a host to stay continuously registered with a Cockpit instance for fleet visibility. Use the host inventory scan when you want a single, comprehensive sweep of a host's local certificates, keys, and (on Windows) system-level cryptographic configuration.

Persistent Agent​

Enrollment​

Before the agent can run, the host must be enrolled with a Cockpit instance. Generate an installer/enrollment token from the Cockpit UI ("Generate installer"), then enroll:

dke-scanner-agent enroll --server https://cockpit.example.com --token <enrollment-token>

Enrollment stores the issued agent identity and API key in a local configuration profile used by subsequent runs.

Running the Agent​

# Start the persistent agent using the enrolled configuration
dke-scanner-agent agent

# Override the cockpit URL or heartbeat interval for this run
dke-scanner-agent agent --server https://cockpit.example.com --heartbeat-interval 60
FlagDescriptionDefault
--server <URL>Override the cockpit URL from the enrollment configurationEnrolled server
--heartbeat-interval <SECS>Override the heartbeat interval from the enrollment configurationEnrolled interval
--config <PATH>Custom path to the enrollment configuration fileDefault profile location
Note

The agent keeps running until stopped; it periodically reports its status to the cockpit so the host stays visible as an active, connected scanner in the fleet. To upload the result of a one-shot TLS scan to the cockpit, use the upload-scan command; to run a full host inventory locally, use the inventory command below.

Host Inventory Scan​

The inventory command performs a one-shot, full local-host cryptographic inventory. It combines a filesystem certificate sweep with SSH key discovery, and — on Windows — adds certificate store, installed-application, and registry crypto-policy inventories.

Filesystem Sweep

  • Certificates and keystores across the OS-default certificate directories, or custom paths
  • Can be disabled with --no-filesystem

SSH Keys

  • User and host SSH key discovery
  • Can be disabled with --no-ssh

Certificate Store (Windows)

  • Windows certificate store enumeration
  • Can be disabled with --no-registry (registry-driven crypto policy) separately from the store itself

Installed Apps & Browser Stores (Windows)

  • Installed-application inventory — can be disabled with --no-apps
  • Browser certificate store — can be disabled with --no-browser-stores
Note

The certificate store, installed-application, registry policy, and browser certificate store components are Windows-only. On Linux and macOS, the inventory scan covers the filesystem sweep and SSH keys. There is no domain/TLS-endpoint scanning and no process enumeration in this scan — for TLS endpoints, use Domain Mode.

Usage​

# Full host inventory
dke-scanner-agent inventory

# Save to a file
dke-scanner-agent inventory --output inventory-report.json

# Summary output
dke-scanner-agent inventory --format summary

Command-Line Options​

FlagDescriptionDefaultRequired
--no-filesystemSkip the filesystem certificate sweepfalseNo
--no-appsSkip the installed-application inventory (Windows only)falseNo
--no-registrySkip the registry crypto-policy sweep (Windows only)falseNo
--no-sshSkip the SSH key sweepfalseNo
--no-browser-storesSkip the browser certificate store (Windows only)falseNo
--path <PATH>Restrict the filesystem sweep to this path (repeatable). Defaults to the OS-default certificate directories-No
--format <FMT>Output format: json or summaryjsonNo
--output <FILE>Output file pathstdoutNo

Privileges & Permissions​

Elevated Privileges Recommended

The Windows certificate store, installed-application, and registry components need administrator privileges for complete results.

Windows​

# Run from an elevated (Administrator) PowerShell for full results
dke-scanner-agent inventory --output report.json

Linux / macOS​

# Some system certificate directories may require elevated read permissions
sudo dke-scanner-agent inventory --output report.json

When to Use​

Full Host Inventory

Discover all cryptographic assets on a single host in one pass: certificate files, SSH keys, and, on Windows, system stores and policy

Continuous Fleet Visibility

Run the persistent agent so a host stays connected to the cockpit for ongoing fleet management

Compliance Audits

Generate host-level inventory reports as part of PQC readiness audits

Pre-Migration Assessment

Before migrating to PQC, understand the local cryptographic footprint of each server

Troubleshooting​

Best Practices​