The Certificate Report dashboard provides a consolidated view of certificate inventory, validity, cryptographic strength, issuer distribution, and post-quantum readiness. It combines certificate health indicators with algorithm, key-size, longevity, source, and detailed inventory information.
Operational guidance: Begin with the summary indicators to understand the size and immediate risk of the certificate population. Review Certificate Signature and Certificate Hygiene for readiness and lifecycle issues, then examine issuing authorities, algorithms, key sizes, longevity, and the detailed certificate records.
Panels
| Panel | Type | What It Shows |
|---|---|---|
| Total | Single value | Total certificate records in the filtered population. |
| Expired | Single value | Certificates whose expiration date has passed. |
| Exp 30D | Single value | Certificates scheduled to expire within 30 days. |
| Self-Signed | Single value | Certificates identified as self-signed. |
| Legacy | Single value | Certificates classified in the legacy signature tier. |
| PQC Vuln | Single value | Certificates identified as PQC-vulnerable or not classified as PQC ready. |
| Certificate Signature | Table | Signature readiness categories, representative algorithms, counts, and percentages. |
| Certificate Hygiene | Table | Expired, near-expiration, self-signed, and weak-key findings with severity and prevalence. |
| Top Issuing CAs | Bar chart | Most frequently observed issuing certificate authorities. |
| Key Algorithm | Table | Public-key algorithms with descriptions, counts, and percentages. |
| Key Size Distribution | Table | Public-key sizes with strength classifications, counts, and percentages. |
| Signature Algorithm | Table | Observed certificate signature algorithms and readiness tiers. |
| Certificate Longevity | Table | Certificate lifetime and expiration-window information. |
| Certificate Source | Table | Certificate records grouped by source type. |
| Certificate Detail | Table | Detailed certificate inventory for investigation and remediation planning. |
Key Data Fields
| Field | Description |
|---|---|
| observer.hostname | Host associated with the certificate record. |
| tychon.type | Certificate source category. |
| omb.sig_tier | Certificate-signature readiness tier. |
| certificate.key_algorithm / certificate.key_bit_size | Certificate public-key algorithm and key size. |
| certificate.chain[] / signature_algorithm | Chain and signature fields used for issuer and hygiene analysis. |
| x509.issuer.common_name | Issuing certificate authority. |
| certificate.not_before / certificate.not_after | Certificate validity start and expiration dates. |
| x509.subject.distinguished_name | Certificate subject distinguished name. |
Reading the Dashboard
Review the KPI row first
Use the summary metrics to gauge immediate certificate risk and scope.
Compare signature readiness and hygiene
These panels surface lifecycle issues alongside post-quantum concerns.
Review issuing CAs and key attributes
This helps identify concentration and weak cryptographic configurations.
Use longevity and detail for remediation
Plan renewals from the longevity views, then investigate individual records in Certificate Detail.
Filtering and Implementation Notes
Use the Time Range, Host, Certificate Source, Signature Tier, Key Algorithm, Key Size, Signature Algorithm, Issuing CA, and Self-signed controls. All category filters default to All.
These filters combine to narrow the certificate population for focused investigation and remediation planning.