For many organizations, SSL/TLS certificate management still means a spreadsheet, a calendar reminder, and a 3:00 AM phone call when something expires unexpectedly. The risks go beyond outages: weak hashing algorithms like SHA-1 and MD5, short key lengths, self-signed certificates that were never replaced after a dev-to-production promotion, and unauthorized certificate authorities can all persist undetected across an enterprise environment. Tanium Certificate Manager was built to address exactly this problem, starting with visibility and now extending into full certificate lifecycle control.
In this episode, Laura walks through the two categories of certificates Certificate Manager surfaces: listening service certificates discovered through self-directed port scans and at-rest certificates found on disk in locations like the Windows Certificate Store and predefined Linux file paths.
She then demonstrates the complete replacement workflow live. The demo covers CSR generation directly within Tanium, certificate distribution to all endpoints that held the original certificate, service configuration using reusable package templates, and the finalization step that cleans up intermediate staging artifacts including private keys.
If you manage certificates across a large endpoint fleet and want to see what a structured, auditable replacement process looks like inside a single platform (including how Tanium handles wildcard certificates spread across multiple machines without requiring manual RDP sessions), this walkthrough is worth your time. Watch the full demo in the video below.
Key takeaways
- Spreadsheets drove the module: Tanium Certificate Manager originated from customers reporting they were tracking certificates in Excel, making it difficult to know what was expiring and when, which led Tanium to build visibility capabilities directly on the endpoint.
“Basically we had customers coming to us telling us that they're tracking certificates in Excel, and that obviously is not ideal for many reasons, chief among them, it's hard to keep track of what's expiring and when.”Tanium Director of Product Management for Certificate Manager Laura Iliescu
- Two certificate categories: Certificate Manager distinguishes between listening service certificates (what the industry calls a service cert, discovered via port scan) and at-risk certificates found on disk, which are classified as at-rest and include certificates like VPN and Wi-Fi client certs.
- Port scans are self-directed: When port scanning is enabled, the device scans itself (iterating on a port to see what version of TLS it supports, what cipher suites it supports, and then making that TCP connection and performing various TLS/SSL handshakes) rather than performing network scans or authenticated scans. Port scanning is optional and configurable, with the ability to exclude specific ports.
- Certificate risks surfaced automatically: The overview page surfaces certificate risks including short keys, weak hashing algorithms such as SHA-1 and MD5, self-signed certificates, and unauthorized certificate authorities, giving teams immediate visibility into risks they may not have known existed in their environment.
“And my goal is wherever you see a certificate, put it in Tanium.”Tanium Certificate Manager Product Manager Laura Iliescu
- End-to-end replacement workflow: The replacement process moves through four stages: CSR generation with pre-populated and editable certificate details, distribution of the new certificate and private key to all endpoints that held the original, service configuration using reusable stop/restart/verify package templates, and finalization, which cleans up the intermediate staging step and is configurable with a default 14-day timeout.
- Private keys do not travel across the Tanium linear chain during the replacement workflow: Certificate distribution is handled by direct communication to the endpoint. The certificate distribution workflow does not send the private key across the Tanium linear chain, and at finalization, the private key is cleaned out of the Tanium secrets service.
“Yeah, so for one, in terms of the fact that we can replace this at scale, that's huge. You're not having to manually go and RDP into every device when you have wildcards.”Tanium Director of Product Management for Certificate Manager Laura Iliescu
- Wildcard replacement at scale: Because Tanium tracks which endpoints held the original certificate, it handles targeting automatically in the background, enabling wildcard certificates spread across multiple machines to be replaced at scale without manually connecting to each device.
Additional resources
- Tanium Certificate Manager: Learn how Tanium delivers real‑time visibility into certificates across endpoints to help teams detect weak, unknown, and expiring certificates before they cause outages or security gaps.
- Gain advanced visibility and control with Tanium Certificate Manager: Discover how Tanium extends endpoint management with real‑time certificate visibility and automated replacement workflows to help reduce expiration risk and close certificate‑related exposures.
- Certificate Manager–Tech Talks #56: Visibility and lifecycle control for enterprise certificates: A focused look at Tanium Certificate Manager capabilities, including discovery of certificates across servers and workstations, inventory of certificates and ciphers to support quantum‑readiness efforts, and identification of weak ciphers and configurations that increase security and outage risk.
- How to manage SSL/TLS certificate lifecycle across enterprise endpoints: An overview of the challenges organizations face tracking and replacing certificates at scale, and how endpoint-based approaches improve visibility and reduce expiration risk.
- Tanium Certificate Manager configuration and certificate discovery settings: Technical documentation covering how to configure port scanning, define trusted certificate authorities, and set up certificate sources including the Windows Certificate Store and Linux file paths.
