Cryptographic Asset Management Platform (CAMP) — discover and assess CA trust anchors and HSMs across your entire PKI estate
The TYCHON PQC Scanner's port scanning and filesystem walking discover leaf certificates — what endpoints present. But the single highest-priority migration target in any PQC program is the root CA, which is never presented on a TLS handshake. An RSA-2048 root CA issuing all endpoint certificates is critical priority — yet standard port scans never see it.
PKI Platform Integration closes this gap by querying PKI platform APIs directly to enumerate every CA certificate in your forest, assess its quantum readiness, and link CA private keys back to the HSMs that protect them.
Enumerate root and intermediate CAs from ADCS, Venafi, DigiCert, AWS PCA, and Vault PKI. Keyfactor and Entrust are planned for 2.1.0. Every CA receives a full PQC assessment: key algorithm, quantum readiness, migration priority.
Detect Thales Luna, Entrust nShield, IBM Crypto Express, AWS CloudHSM, and Vault Transit via filesystem paths, PKCS#11 library detection, and REST APIs. Capture FIPS level, firmware, and PQC algorithm support.
When a port-scanned or filesystem-discovered certificate matches a PKI-managed cert by SHA-256 fingerprint, the scan event is automatically enriched with: issuing CA name, template, enrollment URL, renewal days, and revocation status.
| Flag | Type | Description |
|---|---|---|
| -scan-pki | bool | Enable PKI platform scanning. Activates all configured platforms in config.enc. Platforms without a config entry are silently skipped. |
| -scan-hsm | bool | Enable HSM detection and inventory via filesystem paths, PKCS#11 library enumeration, process scanning, and Vault Transit API. |
| -pki-enrich | bool | Enrich port and filesystem cert events with PKI provenance metadata. Default: true when -scan-pki is set. Disable with -pki-enrich=false. |
| -adcs-cacert | string | Path to a PEM CA certificate for verifying the ADCS LDAP server's TLS certificate. Use when the DC cert is signed by an internal CA not in the OS trust store. |
| -adcs-basedn | string | Override the auto-discovered LDAP base DN. Useful when RootDSE query is blocked by AD policy. |
-config)Security note: These flags write credentials into the encrypted config.enc file (AES-256-GCM, PBKDF2-SHA256, 600,000 rounds). They are one-time setup operations. Credentials are never accepted as runtime scan flags.
| Flag | Platform | Description |
|---|---|---|
| -config-adcs-user | ADCS | LDAP bind username (UPN: user@domain.com or DN format). Required on Windows — GSSAPI/Kerberos auto-authentication is only available on Linux and macOS. |
| -config-adcs-pass | ADCS | LDAP bind password. Stored encrypted. Refused if -config-adcs-tls none. |
| -config-adcs-host | ADCS | LDAP server hostname or IP. Auto-detected via DNS SRV on domain-joined hosts. |
| -config-adcs-port | ADCS | LDAP port. Default: 636 (LDAPS). Use 389 with -config-adcs-tls starttls. |
| -config-adcs-tls | ADCS | TLS mode: ldaps (default, port 636), starttls (port 389), none (anonymous only — credentials refused). |
| -config-venafi-apikey | Venafi VaaS | CyberArk Certificate Manager SaaS API key (UUID format). Activates VaaS mode when set. |
| -config-venafi-url | Venafi TPP | Venafi TPP base URL, e.g. https://tpp.corp.com. Activates on-prem TPP mode when set. |
| -config-venafi-user | Venafi TPP | TPP service account username (UPN: svc_tychon@corp.com). TPP mode only. |
| -config-venafi-pass | Venafi TPP | TPP service account password. Token exchange via /vedauth/authorize at scan time. TPP mode only. |
| -config-venafi-zone | Venafi TPP | TPP policy folder scope (e.g. \VED\Policy\Certificates). Defaults to \VED\Policy (all certs). TPP mode only. |
| -config-keyfactor-url | Keyfactor Coming soon | Keyfactor Command base URL, e.g. https://keyfactor.corp.com |
| -config-keyfactor-user / -pass | Keyfactor Coming soon | Keyfactor API username and password (Basic auth over HTTPS) |
| -config-digicert-apikey | CertCentral | CertCentral order key (X-DC-DEVKEY). DigiCert ONE Private CAs require a separate TYCHON_DIGICERT_ONE_API_KEY token and optional TYCHON_DIGICERT_ONE_URL; see the DigiCert guide. |
| -config-awspca-region | AWS PCA | AWS region, e.g. us-east-1. Auto-detected from AWS_DEFAULT_REGION env or IMDSv2. |
| -config-awspca-key / -secret | AWS PCA | IAM access key and secret (fallback; env vars and instance role checked first). |
| -config-vault-addr | Vault PKI | Vault server address, e.g. https://vault.corp.com:8200. Auto-detected via VAULT_ADDR env or local port probe. |
| -config-vault-token | Vault PKI | Vault token with read on pki/ca/pem and pki/certs. Also read from VAULT_TOKEN env. |
Active Directory Certificate Services — LDAP enumeration of AD PKI containers, Kerberos/GSSAPI auth, 4-container search.
REST API v10+, Basic/API-key auth, /KeyfactorAPI/CertificateAuthority endpoint.
CertCentral REST API, API-key auth (X-DC-DEVKEY). Paginated order inventory with per-order key size enrichment. 429 rate-limit backoff.
Native HTTP + SigV4 signing (no AWS SDK dependency). IAM credentials via env / IMDSv2 / config.enc. GovCloud, FIPS, C2S, and SC2S supported.
Vault REST API, /v1/pki/ca/pem and /v1/pki/certs. Token auth with 3-tier credential chain. Auto-discovers all PKI mounts; SHA-256 dedup across mounts.
TLS Protect Cloud (VaaS) API-key + TPP OAuth2 bearer token (client_id=tychon-scanner). Policy folder scoping. Internal CA cert supported.
| Vendor / Product | Detection Method | FIPS Level | PQC Capable |
|---|---|---|---|
| Thales Luna Network HSM 7 | Filesystem paths + PKCS#11 lib | 140-3 Level 3 | Yes (fw 7.7.1+) |
| IBM CEX8S (4770 PCIe) | Filesystem + CCA/EP11 lib + cssd process | 140-3 Level 4 | Yes (fw 7.15+) |
| IBM CEX7S (4769 PCIe) | Filesystem + CCA/EP11 lib + cssd process | 140-2 Level 4 | Limited |
| Entrust nShield Connect XC | Filesystem /opt/nfast + PKCS#11 |
140-2 Level 3 | No |
| Amazon CloudHSM Gen3 | CloudHSM CLI + PKCS#11 lib detection | 140-3 Level 3 | No |
| HashiCorp Vault (Transit) | Vault API /v1/transit/keys |
Software | Limited |
| Generic PKCS#11 Device | /dev/crypto, /usr/lib/pkcs11/ enumeration |
Unknown | Unknown |
Each PKI platform connector uses a four-tier priority strategy. In common deployments, you do not need to specify platform URLs — the scanner finds them automatically.
-adcs-basedn, -adcs-cacert etc. for one-time overrides without changing stored config.-config -config-adcs-host dc01.corp.com, used on every subsequent scan.VAULT_ADDR, AWS_DEFAULT_REGION, USERDNSDOMAIN, etc.USERDNSDOMAIN env → DNS SRV _ldap._tcp.dc._msdcs.{domain}HKLM\SYSTEM\...\Netlogon\Parameters\DnsDomainNameAdcsHost from config.encVAULT_ADDR environment variablevault process running locallyhttp://127.0.0.1:8200/v1/sys/health (1-second timeout)VaultAddress from config.encAWS_DEFAULT_REGION environment variableAWS_ACCESS_KEY_ID + AWS_SECRET_ACCESS_KEY env~/.aws/credentials INI parse (stdlib)VenafiURL from config.encHKLM\SOFTWARE\Venafi\Platform\TPPServerRegistry auto-detection only works on the TPP server itself. Set VenafiURL in config.enc for remote scans.
When -pki-enrich is active (default when -scan-pki is set), the scanner correlates every port-scan and filesystem-discovered certificate against PKI platform records by SHA-256 fingerprint. On match, additional fields are added to the existing scan event — no new events are emitted.
| Field | Type | Description |
|---|---|---|
| certificate.pki_managed_by | keyword | adcs | venafi_vaas | venafi_tpp | digicert | aws_pca | vault_pki | keyfactor* | entrust* (*planned 2.1.0) |
| certificate.pki_platform_host | keyword | PKI platform server hostname |
| certificate.pki_issuing_ca | keyword | Name of the issuing CA in the PKI platform |
| certificate.pki_template | keyword | Certificate template name (ADCS) or equivalent profile |
| certificate.pki_enrollment_url | keyword | Enrollment URL used to issue this certificate |
| certificate.pki_renewal_days | integer | Days until certificate renewal (from PKI lifecycle record) |
| certificate.pki_revocation_status | keyword | valid | revoked | suspended |
Highest value in remote mode: One PKI platform query enriches thousands of port-scan cert discoveries fleet-wide. Run -scan-pki -mode remote -host targets.txt against 500 servers — every TLS cert found on every remote target gets enriched from a single ADCS or Venafi query.
{
"event": {
"action": "pki_ca_discovered",
"category": ["configuration"],
"dataset": "pki_certificate",
"type": ["info"]
},
"tychon": {
"pki": {
"platform": {
"type": "adcs",
"vendor": "Microsoft",
"product": "Active Directory Certificate Services",
"host": "dc01.corp.example.com",
"source_proto": "ldap"
},
"ca": {
"name": "Corp-Root-CA",
"type": "root",
"status": "active",
"hsm_backed": true, // heuristic: set when an HSM is detected on the same host as the CA process — not cryptographic proof
"hsm_vendor": "Thales",
"quantum_ready": false,
"pqc_vulnerable": true,
"migration_priority": "critical",
"enrollment_url": "https://dc01.corp.com/certsrv/mscep/mscep.dll"
}
}
},
"x509": {
"serial_number": "...",
"subject": { "distinguished_name": "CN=Corp-Root-CA,DC=corp,DC=example,DC=com" },
"public_key_algorithm": "RSA",
"public_key_size": 2048
},
"certificate": {
"sha256_fingerprint": "...",
"is_ca": true,
"source_file_path": "ldap://dc01.corp.example.com/CN=Corp-Root-CA,..."
},
"pqc": {
"vulnerable": true,
"quantum_risk": "high",
"migration_priority": "critical"
}
}
{
"event": {
"action": "hsm_discovered",
"category": ["configuration", "host"],
"dataset": "hsm",
"type": ["info"]
},
"tychon": {
"hsm": {
"vendor": "Thales",
"product": "Luna Network HSM 7",
"model": "A790",
"firmware_version": "7.7.1",
"fips_level": "140-3",
"fips_level_number": 3,
"quantum_capable": true,
"pqc_algorithms": ["ML-DSA-65", "ML-KEM-768"],
"integration_type": "pkcs11",
"detection_method": "filesystem_path"
}
}
}
-scan-pki is independent of the port-scan mode (-mode local or -mode remote). The ADCS LDAP query, Vault REST calls, and AWS PCA API calls run regardless of which mode the port scanner is in. This means you can use -mode remote -scan-pki to enumerate a PKI platform without running a full local scan:
# Fast PKI-only scan — skip local filesystem/process overhead
./build/certscanner -mode remote -host dc01.corp.com -ports 636,443 -scan-pki -insecure \
-outputformat flatndjson -posttoelastic
This runs in seconds and emits only the PKI platform events — useful for validation and scheduled PKI-only inventory jobs.
PKI platform certificate IDs are anchored to the certificate, not to the scanner host. Scanning the same ADCS domain, Vault instance, or AWS PCA CA from two different machines produces the same event.id for the same certificate. Subsequent scans upsert the existing Elasticsearch document rather than creating duplicates.
This differs from filesystem certificate events, which include the observer host ID so the same file on two different endpoints produces distinct records.
Every PKI platform certificate event receives a quantum readiness grade using a cert-intrinsic 100-point formula. Two fields are emitted on all pki_certificate events:
| Field | Type | Example | Description |
|---|---|---|---|
| tychon.crypto.grade | keyword | C | Letter grade A+/A/B/C/D/F |
| tychon.crypto.grade_score | integer | 57 | Numeric score 0–100 |
An A grade is unreachable without a PQC key. RSA-2048 + SHA-256 + valid ≈ 57 → C. See Quantum Readiness Scoring — PKI Certificate Grade for the full formula and examples.
All certificate event types emit a common set of date fields so Kibana / Splunk queries work consistently across TLS port-scan, filesystem, PKI, keystore, and app cert events:
| Field | Format | Status | Present On |
|---|---|---|---|
| x509.not_before | RFC 3339 | Primary | All cert event types |
| x509.not_after | RFC 3339 | Primary | All cert event types |
| certificate.not_before | RFC 3339 | Primary | All cert event types |
| certificate.not_after | RFC 3339 | Primary | All cert event types |
| x509.validity.not_before | RFC 3339 | Deprecated | TLS port-scan certs only |
| x509.validity.not_after | RFC 3339 | Deprecated | TLS port-scan certs only |
| tls.certificate.not_after | RFC 3339 | Deprecated | Keystore certs only |
Deprecated fields are retained for backwards compatibility with existing dashboards and will not be removed. Build new Kibana / Splunk queries using x509.not_after and certificate.not_after.
On Windows, ADCS auto-detects via DNS SRV but GSSAPI/Kerberos is not available — store credentials once with -config-adcs-user, then scan with no extra flags:
# One-time credential setup
tychon-certscanner.exe -config -config-adcs-user "user@DOMAIN.COM" -config-adcs-pass "password"
# Subsequent scans (credentials loaded from config.enc)
tychon-certscanner.exe -scan-pki -outputformat flatndjson
On a domain-joined Linux or macOS host with an active Kerberos credential cache, ADCS auto-detects via DNS SRV and authenticates via GSSAPI — no credentials required:
./tychon-certscanner -scan-pki -outputformat flatndjson
First, store credentials once (this writes to config.enc):
tychon-certscanner -config \
-config-adcs-host dc01.corp.example.com \
-config-adcs-user scanner@corp.example.com \
-config-adcs-pass "secure-password"
Then scan — credentials loaded automatically:
tychon-certscanner -scan-pki -outputformat flatndjson
Scan filesystem, port scan, enumerate ADCS CAs, and enrich all cert discoveries with PKI provenance:
tychon-certscanner \
-scanfilesystem \
-scan-pki \
-outputformat flatndjson \
-output /tmp/scan-results.ndjson
When the DC's TLS certificate is signed by an internal CA not in the OS trust store:
tychon-certscanner -scan-pki \
-adcs-cacert /etc/ssl/certs/corp-root-ca.pem \
-outputformat flatndjson