Skip to main content

Filesystem Mode - File & Keystore Scanner

Applies to:
PEM / DER / PKCS#12 / PFXJKS / JCEKS KeystoresPrivate Key DetectionWindows Certificate Storev1.0.0
Status

Implemented - Available in v1.0.0. Built in Rust using walkdir + rayon for parallel traversal and x509-parser for certificate parsing.

Overview​

Filesystem mode performs recursive scanning of directories to discover certificates, keystores, and private keys. It uses parallel file traversal powered by walkdir and rayon, and parses certificates with the x509-parser crate. In addition to file-based scanning, it can optionally enumerate the Windows Certificate Store (via the schannel crate, covering LocalMachine and CurrentUser stores).

How It Works​

Filesystem Mode Flow

1

Directory Traversal

Recursively walks directories using walkdir with configurable max depth

2

Extension Filtering

Filters files by extension (.jks, .p12, .pfx, .pem, .crt, .cer, .key) and excludes configured paths

3

Parallel Processing

Processes discovered files in parallel using rayon (default 4 threads)

4

Format-Specific Parsing

Selects appropriate parser: PEM, DER, PKCS#12/PFX, JKS/JCEKS, or private key

5

Certificate Analysis

Parses X.509 certificates via x509-parser to extract algorithms, key sizes, and expiry

6

Risk Scoring

Calculates quantum vulnerability scores for each discovered asset

Supported Formats​

📄 PEM Format

  • X.509 certificates (.pem, .crt, .cer)
  • Private keys (RSA, EC, generic PKCS#8)
  • Public keys
  • Multiple PEM blocks per file

🔧 DER Format

  • Binary-encoded X.509 certificates (.der, .cer)
  • Binary-encoded private keys
  • Parsed via x509-parser from_der

🔒 PKCS#12 / PFX

  • .p12 and .pfx files
  • Certificate extraction
  • Private key detection
  • Password-protected bundles

☕ Java Keystores

  • JKS (Java KeyStore)
  • JCEKS (Java Cryptography Extension KeyStore)
  • Alias enumeration
  • Password-protected keystore support

🔑 Private Keys

  • RSA private keys
  • EC private keys
  • PKCS#8 wrapped keys
  • Standalone .key files

💻 OS Certificate Stores

  • Windows Certificate Store (schannel crate): LocalMachine & CurrentUser stores
  • Enabled via --scan-windows-certstore (choose the store with --certstore-name: MY, ROOT, CA, TRUST, or ALL)

Usage​

Basic Scanning​

# Scan current directory (default --path is .; scans are recursive with no --recursive flag)
dke-scanner-agent filesystem

# Scan a specific directory
dke-scanner-agent filesystem --path /opt/applications

# Scan with output to a file
dke-scanner-agent filesystem --path /etc/ssl --output certs-report.json

# Scan and output in YAML format
dke-scanner-agent filesystem --path /srv --format yaml

Command-Line Options​

FlagDescriptionDefaultRequired
--path <PATH>Directory path to scan (recursive by default; there is no --recursive flag). (current directory)No
--max-depth <N>Maximum recursion depth (0 = unlimited)10No
--follow-symlinksFollow symbolic links during the walkfalseNo
--extensions <EXT>File extensions to scan (comma-separated).jks,.p12,.pfx,.pem,.crt,.cer,.keyNo
--exclude <PATHS>Directories to exclude (comma-separated)node_modules,.git,targetNo
--threads <N>Number of parallel processing threads4No
--scan-windows-certstoreScan Windows Certificate Store (LocalMachine and CurrentUser)falseNo
--certstore-name <NAME>Windows certstore to scan: MY, ROOT, CA, TRUST, or ALLALLNo
--output <FILE>Output file pathstdoutNo
--format <FMT>Output format: json, yaml, terminal, or htmljsonNo

Advanced Examples​

Architecture​

Filesystem mode uses walkdir for recursive directory traversal and rayon for parallel file processing:

  1. Walk the directory tree up to the configured max depth (default 10), keeping files that match the configured extensions and are not in an excluded path.
  2. Parse the matching files in parallel across the configured thread count.
  3. Optionally enumerate the Windows certificate store (LocalMachine + CurrentUser) when --scan-windows-certstore is set.

Certificate parsing is handled by the x509-parser crate, which provides full X.509 certificate decoding from both PEM and DER formats.

Example Output​

{
"scan_metadata": {
"scanner_version": "1.0.0",
"scan_mode": "filesystem",
"scan_date": "2025-01-30T15:45:22Z",
"scan_path": "/opt/applications",
"recursive": true,
"max_depth": 10
},
"summary": {
"files_scanned": 45678,
"keystores_found": 23,
"certificates_found": 156,
"private_keys_found": 67,
"total_findings": 246
},
"findings": [
{
"id": "fs-001",
"type": "keystore",
"file_path": "/opt/tomcat/conf/keystore.jks",
"format": "JKS",
"password_protected": true,
"certificates": [
{
"alias": "tomcat-ssl",
"subject": "CN=app.example.com",
"issuer": "CN=Example CA",
"not_after": "2025-12-31T23:59:59Z",
"algorithm": "RSA",
"key_size": 2048,
"has_private_key": true,
"quantum_vulnerable": true
}
],
"risk_assessment": {
"quantum_risk_score": 8.0,
"priority": "P1",
"severity": "HIGH"
}
},
{
"id": "fs-002",
"type": "certificate",
"file_path": "/etc/ssl/certs/server.crt",
"format": "PEM",
"certificate": {
"subject": "CN=www.example.com",
"algorithm": "ECDSA",
"curve": "P-256",
"quantum_vulnerable": true
},
"risk_assessment": {
"quantum_risk_score": 8.0,
"priority": "P1",
"severity": "HIGH"
}
}
]
}

Default Behavior​

Default Settings

By default, filesystem mode scans the current directory (.) recursively up to 10 levels deep with 4 threads. It looks for files with extensions .jks, .p12, .pfx, .pem, .crt, .cer, and .key, while automatically excluding node_modules, .git, and target directories.

Troubleshooting​

Best Practices​