Provide current and historical ownership information on domains / IPs. Identify all connections between domains, registrants, registrars, and DNS servers.
Most often, SSL/TLS certificates are issued for specific websites: one certificate for one hostname or website. But for larger organizations, this creates problems with certificate management — they pile up, they expire at different times, it becomes harder to spot rogue certificates, and so on.
This problem is solved by so-called SAN certificates, or multi-domain certificates, which can secure multiple domain names or hostnames with the help of the Subject Alternative Names (SAN) field. This post covers what a SAN certificate actually is, how it works, how to get one, and how security teams use SAN data for asset discovery.