logo

Identify insecure TLS services with the enhanced runZero Certificate Inventory

ID: 704f74a3-4119-5d9e-a8fa-0c2d7e33dbb3

STIX ID: report--704f74a3-4119-5d9e-a8fa-0c2d7e33dbb3

Feed Name: runZero Blog

Date Published: 2025-11-06

Date Updated: 2026-04-29

Author: Brandon Turner

...
...

This document introduces updates to runZero’s Certificates Inventory, a capability that discovers and inventories TLS services and X.509 certificates across environments, flags insecure configurations (e.g., deprecated TLS versions, weak ciphers, missing HSTS, self-signed/untrusted certs), and surfaces expiring certificates to prevent outages. It provides practical search queries to find at-risk certificates and services, links certificates to the assets and ports using them for rapid remediation, and contextualizes the urgency with CA/Browser Forum deadlines reducing certificate validity to 100 days by 2027 and 47 days by 2029.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.