This dashboard identifies keystores and key material across hosts, including access state, authentication requirements, certificate counts, vulnerable certificates, and algorithm distribution.
Panels
| Panel | Purpose |
|---|---|
| Keystore Inventory | Locates stores, owners, paths, access state, and authentication requirements. |
| Certificate Counts | Prioritizes stores with expired, expiring, vulnerable, or PQC-vulnerable certificates. |
| Algorithm Distribution | Compares algorithm concentration and identifies stores requiring migration. |
| Key Material Detail | Investigates individual stores, access errors, and certificate-level evidence. |
Key Data Fields
tychon.type=keystore, keystore.type, keystore.path, keystore.accessible, keystore.requires_auth, keystore.cert_count, observer.hostname.
Reading the Dashboard
Keystore Inventory
Establishes the keystore population, locations, owners, access state, and certificate counts across the filtered events.
Certificate Counts
Shows total, vulnerable, PQC-vulnerable, expired, and soon-to-expire certificate counts to frame hygiene and migration workload.
Algorithm Distribution
Groups certificates and keys by algorithm, size, and curve where those values are emitted. Use the distribution to find concentration of weak material.
Key Material Detail
Provides the keystore path or owner, certificate identity, validity, usage, and algorithm evidence needed for targeted cleanup.
Filtering and Performance
Use the dashboard time range and global filters to narrow the population before interpreting counts. Preserve host, application, platform, algorithm, and risk filters when moving to related dashboards. Aggregations summarize the filtered events; missing optional fields mean that a value was not emitted or observed, not that the condition is false.
Related Dashboards
Use the overview page to move between this dashboard and the other dashboard definitions.