Agent Mode - Persistent Agent & Host Inventory
Agent Mode
The persistent agent daemon that connects a host to DuoKey Cockpit, and the one-shot host inventory scan for local cryptographic discovery
Implemented - Available in v1.0.0. This page covers two distinct capabilities: the persistent agent daemon that keeps a host connected to DuoKey Cockpit, and the one-shot inventory command that performs a full local-host cryptographic discovery scan.
Overview
agent is a long-running process that connects a host to a DuoKey Cockpit server and reports periodic heartbeats — it does not scan anything by itself. The one-time, full local-host cryptographic inventory is a separate command, inventory, covered in the second half of this page.
Use the persistent agent when you want a host to stay continuously registered with a Cockpit instance for fleet visibility. Use the host inventory scan when you want a single, comprehensive sweep of a host's local certificates, keys, and (on Windows) system-level cryptographic configuration.
Persistent Agent
Enrollment
Before the agent can run, the host must be enrolled with a Cockpit instance. Generate an installer/enrollment token from the Cockpit UI ("Generate installer"), then enroll:
dke-scanner-agent enroll --server https://cockpit.example.com --token <enrollment-token>
Enrollment stores the issued agent identity and API key in a local configuration profile used by subsequent runs.
Running the Agent
# Start the persistent agent using the enrolled configuration
dke-scanner-agent agent
# Override the cockpit URL or heartbeat interval for this run
dke-scanner-agent agent --server https://cockpit.example.com --heartbeat-interval 60
| Flag | Description | Default |
|---|---|---|
| --server <URL> | Override the cockpit URL from the enrollment configuration | Enrolled server |
| --heartbeat-interval <SECS> | Override the heartbeat interval from the enrollment configuration | Enrolled interval |
| --config <PATH> | Custom path to the enrollment configuration file | Default profile location |
The agent keeps running until stopped; it periodically reports its status to the cockpit so the host stays visible as an active, connected scanner in the fleet. To upload the result of a one-shot TLS scan to the cockpit, use the upload-scan command; to run a full host inventory locally, use the inventory command below.
Host Inventory Scan
The inventory command performs a one-shot, full local-host cryptographic inventory. It combines a filesystem certificate sweep with SSH key discovery, and — on Windows — adds certificate store, installed-application, and registry crypto-policy inventories.
Filesystem Sweep
- Certificates and keystores across the OS-default certificate directories, or custom paths
- Can be disabled with
--no-filesystem
SSH Keys
- User and host SSH key discovery
- Can be disabled with
--no-ssh
Certificate Store (Windows)
- Windows certificate store enumeration
- Can be disabled with
--no-registry(registry-driven crypto policy) separately from the store itself
Installed Apps & Browser Stores (Windows)
- Installed-application inventory — can be disabled with
--no-apps - Browser certificate store — can be disabled with
--no-browser-stores
The certificate store, installed-application, registry policy, and browser certificate store components are Windows-only. On Linux and macOS, the inventory scan covers the filesystem sweep and SSH keys. There is no domain/TLS-endpoint scanning and no process enumeration in this scan — for TLS endpoints, use Domain Mode.
Usage
# Full host inventory
dke-scanner-agent inventory
# Save to a file
dke-scanner-agent inventory --output inventory-report.json
# Summary output
dke-scanner-agent inventory --format summary
Command-Line Options
| Flag | Description | Default | Required |
|---|---|---|---|
| --no-filesystem | Skip the filesystem certificate sweep | false | No |
| --no-apps | Skip the installed-application inventory (Windows only) | false | No |
| --no-registry | Skip the registry crypto-policy sweep (Windows only) | false | No |
| --no-ssh | Skip the SSH key sweep | false | No |
| --no-browser-stores | Skip the browser certificate store (Windows only) | false | No |
| --path <PATH> | Restrict the filesystem sweep to this path (repeatable). Defaults to the OS-default certificate directories | - | No |
| --format <FMT> | Output format: json or summary | json | No |
| --output <FILE> | Output file path | stdout | No |
Privileges & Permissions
The Windows certificate store, installed-application, and registry components need administrator privileges for complete results.
Windows
# Run from an elevated (Administrator) PowerShell for full results
dke-scanner-agent inventory --output report.json
Linux / macOS
# Some system certificate directories may require elevated read permissions
sudo dke-scanner-agent inventory --output report.json
When to Use
Full Host Inventory
Discover all cryptographic assets on a single host in one pass: certificate files, SSH keys, and, on Windows, system stores and policy
Continuous Fleet Visibility
Run the persistent agent so a host stays connected to the cockpit for ongoing fleet management
Compliance Audits
Generate host-level inventory reports as part of PQC readiness audits
Pre-Migration Assessment
Before migrating to PQC, understand the local cryptographic footprint of each server