Discovery

Mar 12, 2026

The Discovery feature in TLS Connect allows you to identify TLS certificates across your environment by scanning network endpoints or the local Windows Certificate Store. This provides visibility into the number, type, and status of certificates in use on your network. 

Scan Profiles 

Scan Profiles define where and how TLS Connect searches for certificates. 

  1. Open the TLS Connect application and navigate to the Discovery > Scan Profiles tab. 

  2. Enter a name for the scan profile. 

  3. Select the scan type: 

    1. Network scan (SSL handshake) to discover certificates presented by endpoints. 

    2. Local machine store scan to scan the Windows Certificate Store on the local system. 

  4. Enter the scan target, such as host names, IP addresses, or CIDR ranges, and specify the port number. Multiple targets can be added to a single scan profile. NOTE: A network scan performs an SSL handshake for the specified host name. TLS Connect does not automatically scan all subdomains of a given FQDN; each subdomain must be added as a separate target. 

  5. Click Save Profile. 

The new scan profile appears in the table at the bottom of the screen. From this table, you can: 

  • Run the scan profile 

  • Edit or delete the profile 

  • View scan results. 

 

License Behavior 

  • With a Standard license, scan profiles run only when you manually click the Play (green arrow) button next to a scan profile.  

  • With a Premium license, you can enable an automation service that continuously runs all scan profiles at a configurable interval. 

 

Inventory 

The Inventory section displays all certificates discovered through your scan profiles. From this view, you can: 

  • See certificates that are valid, expired, or nearing expiration 

  • Sort and filter the inventory using multiple criteria 

  • View detailed certificate information 

  • Download individual certificates. 

 

Export CSV 

Use this option to export the certificate inventory to a CSV file for offline review or reporting. 

 

Purge Profile 

Use this option to remove all certificates discovered by a specific scan profile. This is useful if a scan profile was misconfigured and you want to quickly clean up the inventory.  

  1. Open the TLS Connect application and navigate to the Discovery > Inventory tab. 

  2. Select the scan profile from in the  drop-down menu. 

  3. Click Purge Profile.  

  4. All certificates discovered by the selected scan profile are removed from the inventory. 

GlobalSign System Alerts

View recent system alerts.

View Alerts

Atlas Discovery

Scan your endpoints to locate all of your Certificates.

Sign Up

SSL Configuration Test

Check your certificate installation for SSL issues and vulnerabilities.

Contact Support