Version 2.0.5
Latest Release Minor Feature ReleaseRelease Date: October 2, 2026
Version 2.0.5 introduces the CAMP (Certificate Authority Management Platform) integration — a unified PKI platform connector framework that discovers CA and issued certificates from enterprise PKI platforms without touching the filesystem. Five production connectors ship in this release: Active Directory Certificate Services (ADCS) via LDAP with Kerberos/GSSAPI authentication, AWS Private Certificate Authority via a native SigV4 implementation (no AWS SDK), HashiCorp Vault PKI via token-authenticated REST, Venafi/CyberArk Certificate Manager in both VaaS and TPP modes, DigiCert ONE/CertCentral via separate service credentials with automatic rate-limit handling. All five connectors participate in full OMB M-23-02 quantum vulnerability assessment — every discovered certificate now carries the same 20+ OMB compliance fields that were previously only available for TLS port-scan certificates. PKI discoveries now appear in flat events, JSON, and HTML reports, with per-platform scan status. Certificate validity dates and cross-scanner PKI certificate IDs are corrected, along with later discovery, output, and assessment fixes described below.
Mandatory Prerequisite — BEFORE Installing 2.0.5 into Elastic
TQR-1573
Complete this Kibana dashboard cleanup before installing 2.0.5 into Elastic. Remove only the six dashboard saved objects listed below, after verifying that they are from version 2.0.2, 2.0.3, or 2.0.4.
- In Kibana, open Saved Objects.
- Filter by the tag Quantum Resilient.
- Filter the object type to Dashboard only.
- Validate that the dashboards selected for deletion are from version 2.0.2, 2.0.3, or 2.0.4.
- Select these six dashboards:
- [TYCHON Quantum Command] Inventory
- [TYCHON Quantum Command] Application Report
- [TYCHON Quantum Command] Application Detail
- [TYCHON Quantum Command] Certificate Operations Dashboard
- [TYCHON Quantum Command] Application Connections Topology
- [TYCHON Quantum Command] Cost Analysis
- Click Delete to remove the selected dashboard saved objects.
- Complete this cleanup before installing 2.0.5 into Elastic, then proceed with installation.
Customer data is preserved: Deleting these dashboard saved objects does not delete customer data.
Update browser bookmarks after installation: The new 2.0.5 dashboards have different IDs. Customers must update browser bookmarks to point to the new dashboards.
What's New at a Glance
pki-type mounts and deduplicates certs across mounts by SHA-256 fingerprint.tychon.pki.* and tychon.hsm.* Elasticsearch field mappings separate PKI platform metadata from cryptographic certificate data.PKI Platform — CAMP Integration
CAMP (Certificate Authority Management Platform) is a new connector framework that queries enterprise PKI platforms directly
via their native APIs — LDAP, REST, SigV4, or OAuth2 — and feeds discovered certificates into the same PQC assessment and OMB M-23-02
pipeline as all other certificate sources. PKI certificates appear as pki_ca_discovered
or pki_issued_cert_discovered events in the pki_certificate
dataset. The JSON report includes certificate details in filesystem_scan_results
and per-platform summaries in pki_platform_results. Each certificate has a
source_file_path that uniquely identifies the platform and source (e.g.
vault://addr/pki/cert/serial,
ldap+pki://dc/CN=...,
awspca://us-east-1/arn:aws:acm-pca:...,
venafi-cloud://...certificates/{id},
digicert://www.digicert.com/order/{id}).
PKI Platform Connector Framework
New pki_platform.go defines the PkiPlatformConnector
interface and shared types (PkiCertRecord, PkiScanResult)
used by all PKI connectors. Activates via the -scan-pki flag alongside any configured connector.
PKI Results Across Reports
- Flat events now include PKI platform and CA dashboard fields. A
pki_scan_healthevent reports each configured connector's success, partial result, or failure, including scans that found no certificates. - JSON reports now include
pki_platform_resultswith each platform's host, CA certificates, and issued-certificate count. Split JSON output retains this section even when a configured platform returned no certificates. - HTML reports now show discovered PKI platforms, scan status, CA and issued-certificate counts, and certificate details.
- CBOM reports now include PKI platforms as CycloneDX service entries, alongside the discovered certificate components (TQR-1555).
Active Directory Certificate Services (ADCS) Connector
Discovers CA and issued certificates from Windows ADCS by querying Active Directory over LDAP. No WinRM, PowerShell, or CertUtil dependency — works from any platform that can reach the domain controller on port 636 (LDAPS) or 389 (StartTLS).
-
1
GSSAPI / Kerberos — attempted first when no username is configured on domain-joined Linux and macOS hosts. Uses the running process's Kerberos credential cache. Not available on Windows; use tier 2 (simple bind) by storing credentials with
-config-adcs-user. -
2
Simple bind over TLS — when username is configured. Accepts UPN (
user@domain) or DN format. RootDSE query auto-normalizes bare usernames to UPN. Refused if TLS mode isnone. -
3
Anonymous bind — last-resort fallback. Warning is logged. Returns empty set if AD denies anonymous reads of PKI containers.
- Certification Authorities container — root and policy CA certs
- NTAuthCertificates — enterprise CAs trusted for smart card / SSL auth
- AIA container — intermediate / cross-cert distribution points
- Enrollment Services — issuing CAs with enrollment URL metadata
- Domain-wide userCertificate — issued leaf certificates (paged, RFC 2696, page size 500)
- CertSrv\CertEnroll filesystem path (TQR-1187) — CA cert files on Windows CA servers, discovered automatically with
-scanfilesystem
_ldap._tcp.dc._msdcs.{domain}) and USERDNSDOMAIN env. SHA-256 deduplication prevents the same CA cert from appearing twice across containers.AWS Private Certificate Authority Connector
Discovers CA certificates from AWS Private CA (ACM PCA) using the ACM PCA REST API. Issued leaf certificates are not enumerated by this connector. No AWS SDK
dependency — all API calls are signed with a native SigV4 implementation using only Go standard library
(crypto/hmac, crypto/sha256).
Supports scanning multiple regions in a single run via comma-separated list.
- 1.
config.encstored access key + secret - 2.
AWS_ACCESS_KEY_ID/AWS_SECRET_ACCESS_KEYenv vars - 3.
~/.aws/credentialsfile (default profile) - 4. IMDSv2 PUT-then-GET (EC2 instance role) — IMDSv1 explicitly not used
- Standard:
acm-pca.{region}.amazonaws.com - GovCloud:
acm-pca.us-gov-{west|east}-1.amazonaws.com - FIPS (
-config-awspca-fips):acm-pca-fips.{region}.amazonaws.com - C2S/SC2S (
-config-awspca-endpoint): custom endpoint override for Federal/DoD isolated regions
HashiCorp Vault PKI Connector
Enumerates CA and issued certificates from Vault's PKI secrets engine via Vault's REST API. Uses token authentication
only — no Vault SDK dependency. Three API calls per mount: GET /v1/{mount}/ca/pem
(raw CA PEM), LIST /v1/{mount}/certs (issued serial numbers), and
GET /v1/{mount}/cert/{serial} per issued cert.
- 1.
config.encstored token (via-config-vault-token) - 2.
VAULT_TOKENenvironment variable - 3.
~/.vault-tokenfile
When no mount is configured, calls GET /v1/sys/mounts and scans every mount of type pki automatically. A Vault instance with pki/ and pki-int/ has both enumerated with no extra configuration.
- SHA-256 deduplication — a cert installed on multiple mounts (e.g. intermediate CA published to both its own mount and the root mount) is emitted exactly once per scan.
- Enterprise namespaces —
-config-vault-namespacesetsX-Vault-Namespaceheader. Leave empty for Vault OSS (Community Edition). - source_file_path uses
vault://addr/mount/cert/serialorvault://addr/mount/ca— queryable in Kibana and Splunk.
Venafi / CyberArk Certificate Manager Connector
Enumerates certificates from both Venafi deployment modes — VaaS (CyberArk Certificate Manager SaaS) and TPP (Trust Protection Platform, on-premises) — from a single connector. Mode is auto-detected from which configuration value is stored: a stored API key activates VaaS; a stored URL activates TPP. No Venafi SDK required.
-
VaaS
CyberArk Certificate Manager SaaS — API key via
tppl-api-keyheader. Paginated enumeration viaGET /outagedetection/v1/certificates. Source path:venafi-cloud://.../{id}. -
TPP
Trust Protection Platform (on-premises) — OAuth2 bearer token via
POST /vedauth/authorize. Paginated enumeration viaGET /vedsdk/certificates. Optional policy zone narrows scan scope. Source path:venafi-tpp://host/vedsdk/{dn}.
-config-venafi-apikey— VaaS API key (activates VaaS mode)-config-venafi-url— TPP base URL (activates TPP mode)-config-venafi-user— TPP bind username (UPN format)-config-venafi-pass— TPP bind password-config-venafi-zone— TPP policy folder (default:\VED\Policy)
config.enc — never passed on the command line at scan time. TPP mode requires the tychon-scanner OAuth client ID to be registered in Venafi before use.DigiCert ONE / CertCentral Connector
Enumerates private CAs from DigiCert ONE and certificate orders from CertCentral via separate REST APIs.
Each service needs its own credential. The CertCentral order API handles rate limiting with exponential backoff,
honoring the Retry-After header when present. No DigiCert SDK is required.
- Private CAs — DigiCert ONE
GET /certificate-authority/api/v1/calists CAs; PEM certificates are downloaded per CA. Source path:digicert://{one_host}/ca/{id}. - Certificate orders —
GET /order/certificatewith page size 1,000. Auth pre-validated viaGET /user/mebefore paginating. Source path:digicert://www.digicert.com/order/{id}.
- Rate-limit handling — 429 responses retried with exponential backoff (2s initial, 60s cap).
- Separate credentials —
TYCHON_DIGICERT_API_KEYsupplies the CertCentral order key;TYCHON_DIGICERT_ONE_API_KEYsupplies the DigiCert ONE Private CA token. A scan configured for only one service can still return its results. - DigiCert ONE host — defaults to
https://one.digicert.com;TYCHON_DIGICERT_ONE_URLor runtime-digicert-urlselects a regional or private-cloud host. See the DigiCert guide for configuration.
Expanded Dashboard Suite
The 2.0.5 dashboard packages for Elasticsearch/Kibana and Splunk each contain 13 dashboards. Seven additional dashboard subjects extend the existing Inventory, Application Report, Application Detail, Certificate Operations, Application Connections Topology, and Cost Analysis views:
| Dashboard | Purpose | Related tickets |
|---|---|---|
| Crypto Libraries | Library versions, PQC capability, and remediation exposure. | Splunk: TQR-1512 |
| Application Crypto Inventory | Application-level cryptographic inventory and quantum-readiness posture. | Splunk: TQR-1507 |
| IPSec & VPN Security | VPN and tunnel inventory, cryptographic settings, and risk. | Splunk: TQR-1515 |
| Keystores & Key Material | Keystore inventory, accessibility, certificates, and key material. | Splunk: TQR-1516 |
| Installed Applications | Software inventory, versions, vendors, and host coverage. | Splunk: TQR-1513 |
| PKI Platform and CA Intelligence | PKI platform coverage, CA hierarchy, certificate expiry, and CA risk. | Elastic: TQR-1529; Splunk: TQR-1541 |
| CAMP Integration Health | Platform scan freshness, event trends, errors, and CA counts. | Elastic: TQR-1521; Splunk: TQR-1539 |
See the Elasticsearch dashboard overview and Splunk dashboard overview for guides to the documented dashboards. In Splunk, Application Connections Topology is titled Application Topology Explorer, and Certificate Operations is titled Certificate Report.
Additional Scanning and Reporting Features
Multiple Report Formats from One Scan
Pass a comma-separated list to -outputformat to write several report formats from one scan. With the example below, the scanner writes scan.ndjson, scan.cbom.json, and scan.html. The ndjson alias selects flatndjson.
certscanner -mode local -outputformat flatndjson,cbom,html -output scan.json
See Output Features for format selection and file naming.
Native HCL BigFix QRA Report
The new -outputformat hcl option produces JSON in the HCL BigFix QRA web-report format for consumption by BigFix. When requested alongside other formats, its file uses the .hcl.json extension to distinguish it from the scanner's standard JSON report.
Certificate Risk Properties in CBOM
CBOM certificate components now include cert:pqc-vulnerable and, when available, cert:quantum-risk and cert:migration-priority. These properties let downstream consumers identify vulnerable certificates and prioritize migration from the CBOM itself.
Additional TLS PQC Group Recognition
TLS scanning now recognizes additional pre-IANA Kyber draft key-exchange group IDs, including X25519Kyber768Draft00. Servers advertising these older draft groups can be identified alongside standardized ML-KEM groups. Unknown cipher and group IDs are also retained in the output fields listed in the schema section below.
Improved Linux Cryptographic Library Detection
Linux scans can extract cryptographic library versions directly from ELF shared-library binaries instead of relying only on filenames. Version definitions, embedded version strings, and shared-object names provide additional evidence when package or filename information is incomplete. Library PQC capability assessments also use updated version thresholds.
OMB M-23-02 Full Certificate Assessment
Full OMB Fields on All Certificate Events
Prior to 2.0.5, only TLS port-scan certificate events carried the full OMB M-23-02 compliance block. Filesystem,
ADCS, AWS PCA, and Vault PKI certificate events emitted only omb.sig_tier.
This release adds applyCertOmbAssessments() which runs over all
discovered certificates before output, populating all 20+ OMB fields from the certificate's own public key and
issuer metadata.
| Field | Example (RSA-2048 leaf) | Notes |
|---|---|---|
| omb.vulnerability_status | Vulnerable | Vulnerable / Not Vulnerable |
| omb.sig_tier | CLASSICAL | CLASSICAL / MODERN / LEGACY / PQC READY |
| omb.dsa_algorithms | RSA | Key algorithm family (from cert's own public key) |
| omb.dsa_parameters | RSA: 2048 | Algorithm and key size |
| omb.dsa_hash_algorithms | SHA-256 | Hash used in the issuer's signature |
| omb.crqc_vulnerable_algos | RSA | Algorithms broken by a cryptographically relevant quantum computer |
| omb.vendor | TYCHON Inc | Issuer organization from cert Subject |
These fields are populated on PKI certificate events, filesystem_certificate_discovered,
keystore_certificate, and the JSON report's
filesystem_scan_results /
orphan_findings.filesystem_certificates blocks.
Elasticsearch Mappings — PKI & HSM Namespaces
tychon.pki.* and tychon.hsm.* Field Mappings
New Elasticsearch index mappings separate PKI platform metadata from cryptographic certificate data. PKI platform
metadata (source platform, CA type, enrollment URL) lives exclusively in tychon.pki.*;
certificate cryptographic data stays in certificate.* and
x509.*.
- tychon.pki.platform.type
- tychon.pki.platform.vendor
- tychon.pki.platform.host
- tychon.pki.ca.name
- tychon.pki.ca.type
- tychon.pki.ca.pqc_vulnerable
- tychon.pki.ca.migration_priority
- tychon.pki.ca.enrollment_url
- tychon.hsm.vendor
- tychon.hsm.product
- tychon.hsm.fips_level
- tychon.hsm.detection_method
- tychon.hsm.pkcs11_library
- tychon.hsm.serial
Bug Fixes
Fixes cover certificate output, on-disk discovery, configuration storage, Splunk reporting, assessment accuracy, SSH reporting, and dashboard visuals and filters.
Certificate Validity Dates Inconsistent Across Event Types
Certificate validity dates were emitted under different field names depending on where the cert was found:
x509.validity.not_before/after (TLS port scan),
tls.certificate.not_after (keystores), or no date fields at all
(app, config, archive certs). There was no common field set that worked across all event types in a single Kibana query.
All certificate event types now emit x509.not_before,
x509.not_after, certificate.not_before,
and certificate.not_after in RFC 3339 format.
Legacy fields (x509.validity.*, tls.certificate.not_after)
are retained but marked deprecated in code comments. No existing dashboards break.
output_flat_ndjson.go (6 cert-event blocks),
splunk_connector.go, kafka_connector.go,
output_detail_level.go.
PKI Certificate IDs Scanner-Anchored Instead of Cert-Anchored
GenerateFilesystemCertID() was used for all PKI connector certs.
That function always runs in ScanModeLocal, which includes the
observer's host ID in the hash. Scanning the same ADCS domain or Vault instance from two different scanner hosts
produced two different event.id values for the same physical certificate —
doubling every PKI record in Elasticsearch.
New GeneratePKICertID() function in
unique_id_generator.go runs in
ScanModeRemote, excluding the observer ID.
The ID is keyed on sha256_fingerprint | serial_number | source_path.
The source path encodes the PKI server address, preventing cross-server collisions.
Repeated scans of the same PKI platform now upsert, not duplicate.
Existing Encrypted Configuration File Permissions
config.enc did not correct permissions that had become too broad. The save path now
restricts the file to owner access before writing and trims any bytes left from a longer previous value.
On-Disk Key and Certificate Discovery
Splunk Application and Inventory Events Restored
Output and Assessment Corrections
-outputformatvalidation now accepts comma-separated formats andhcl, matching the scanner's supported output options (TQR-1544).- EC P-384 and P-521 certificates no longer fall through to P-256 grading, and PQC certificate signatures receive the correct signature tier (TQR-1545, TQR-1448).
- DigiCert order SHA-1 thumbprints are preserved; Vault CA classification no longer depends on mount order; ADCS RSA-2048 root CAs receive the intended critical migration priority (TQR-1547, TQR-1551, TQR-1559).
SSH Protocol and Host-Key Reporting Restored
Application Report Dashboard Visual Restored
x509.public_key_curve.
The Curve grouping now includes documents without that field, allowing the visual to display results
even when curve information is unavailable.
Certificate Inventory Single-Click Filtering
Splunk Inventory Routing and Linked Events
tychon:pqc_inventory, and linked application and source inventory
records are consolidated while preserving application fields.
Application Discovery Event Actions
event.action. Flat NDJSON, Elasticsearch, and Splunk
records built through the shared flat event path now include event.action=application_discovered,
including applications without ports.
Elasticsearch Index Template Mappings
quantum_readiness mappings could prevent dashboard fields from being interpreted correctly.
The scanner's index template and the documented Flat NDJSON deployment template now include the required
mappings and use consistent field definitions.
Splunk Certificate Count Normalization
event.dataset so repeated records are counted
consistently for the same certificate dataset.
Additional Discovery Corrections
VPN Detection and Assessment Improvements
strongSwan installations using swanctl configuration can now be discovered alongside legacy ipsec.conf installations. VPN client PQC assessments use corrected version comparisons and readiness rules, including proper numeric version ordering for FortiClient. Client detection and capability assessment help identify candidates for migration; they do not prove that a connection negotiated PQC.
Elastic Agent Version Detection on Linux
Linux scans now identify Elastic Agent versions that previously could be omitted from application inventory, improving software-version reporting for these installations.
Performance Improvements
Five improvements to the config scan pipeline significantly reduce scan time on endpoints running large modern applications. Hosts with Microsoft Teams, Slack, VS Code, or similar apps see the largest gains — these applications include large dependency trees that the scanner previously had to traverse in full. Scan times on affected hosts drop from several minutes to seconds.
Config Scan Performance Overhaul
Config scan now skips known non-cryptographic dependency and build directories (such as package caches, version control metadata, and compiler output folders) that can contain tens of thousands of files with no certificate or key material. On a host with VS Code or Teams installed, this alone reduces the number of files inspected by an order of magnitude. Results are also shared across scan phases so the same directory is never traversed more than once per scan run.
Config scan previously processed one application at a time. Multiple applications are now scanned concurrently, so a host running many processes no longer waits for each application to complete before starting the next. Total scan time scales with the slowest individual application rather than the sum of all applications.
The scanner previously made multiple passes over the file list for each application directory — one to locate configuration files and a separate one to locate certificate files. These passes have been merged into a single traversal, halving the file-inspection work per application root. Oversized files are also skipped earlier, before any disk I/O is attempted.
Certificate and key files discovered during the config scan were previously read from disk twice — once to identify the file type and once to extract its contents. Each file is now read once, with the contents passed directly to the extraction step. On endpoints with many bundled certificate files, this reduces disk I/O proportionally to the number of files found.
The config scan and the filesystem certificate scan previously processed the same certificate files independently, performing redundant parsing work. Certificate files handled by the config scan are now tracked and automatically skipped by the filesystem scan, ensuring each file is parsed exactly once per scan run regardless of how many scan phases reference the same application directory.
Additional Security Hardening
Bounded Network Responses and HTTPS S3 Uploads
- SSH scanning rejects oversized packets before allocating their payload and reads packet contents completely (TQR-1347).
- HTTP response-size limits also apply to chunked responses, bounding response consumption when no content length is supplied (TQR-1350).
- S3 uploads reject non-HTTPS custom endpoint URLs to protect the upload transport (TQR-1349).
PKI Credential Redaction in Reports
PKI platform host and URL fields strip embedded credentials before being written to CBOM and flat-event reports. Platform URLs also omit query strings and fragments, reducing the risk of exposing sensitive configuration through report metadata.
Library Updates
New and Updated Third-Party Dependencies
| Package | Change | Purpose |
|---|---|---|
| github.com/go-ldap/ldap/v3 | New — v3.4.14 | ADCS LDAP connector. US-origin; used by HashiCorp Vault, Grafana, Kubernetes. |
| github.com/jcmturner/gokrb5/v8 | Promoted to direct — v8.4.4 | Kerberos/GSSAPI authentication for ADCS LDAP. US-origin; used by AWS SDK, Grafana. |
| github.com/cloudflare/circl | Updated — v1.6.5 (TQR-1403) | Refreshes the scanner's post-quantum cryptography dependency. |
| golang.org/x/crypto | Updated — v0.56.0 (TQR-1425, TQR-1435) | Includes security updates addressing SSH denial-of-service advisories. |
All third-party dependencies are US-origin and widely adopted. CGO_ENABLED=0 is maintained —
no CGO required. Kerberos/GSSAPI authentication is supported on Linux and macOS. On Windows, use simple bind by storing ADCS credentials with -config-adcs-user.
Go 1.26.7 Upgrade
CGO_ENABLED=0 support
for Linux amd64/arm64, Windows amd64, and macOS amd64/arm64.
Documentation
New and Updated Documentation Pages
- PKI Platform Overview — unified CAMP integration guide covering all connectors, CLI flags, field namespace rules, and auto-detection priority chain
- ADCS Connector Guide — prerequisites, authentication methods, credential storage, troubleshooting
- AWS Private CA Connector Guide — credential chain, GovCloud/FIPS/C2S setup, minimum IAM policy, output fields
- HashiCorp Vault PKI Connector Guide — token credential chain, lab setup (Docker + Homebrew), Enterprise namespaces, minimum Vault policy
- Venafi / CyberArk Connector Guide — VaaS API key setup, TPP OAuth client registration, policy zone scoping, troubleshooting
- DigiCert ONE Connector Guide — API key setup, rate limit behavior, output fields, PQC algorithm handling
- PKI Deployment Guide — Elasticsearch and Kibana setup for the PKI output (TQR-1552)
- Cryptographic Protocol Coverage — 24 new protocol sections: DTLS, QUIC/HTTP-3, RADIUS, TACACS+, NTP/NTS, WireGuard, mTLS, Plaintext Detector, NTLM, FIPS Mode, AirPlay, WiFi/WPA, OPC-UA, OT protocols, Noise Protocol, Signal/MLS, Tor, ZRTP, DTLS-SRTP/WebRTC, S/MIME, PGP, OpenVPN, IPSec, BigFix
- Documentation Index — new PKI Platform section with cards for all five connectors
- Output Features and TYCHON Format — supported formats clarified and retired format instructions removed (TQR-1504, TQR-1558)
⚠️ Known Issues
macOS EventLog truncation (TQR-1557)
Known limitation: macOS unified logging truncates messages at approximately 1 KB,
which can leave larger certificate and PKI events as incomplete JSON.
Workaround: Write flatndjson or json output to a file
for complete records. See EventLog Format
for details. Windows and Linux EventLog output are unaffected.
Kibana Vega panel rendering (TQR-1572)
Known limitation: Vega panels may not resize correctly after a dashboard panel is expanded or collapsed. Workaround : Click refresh button or reload the page and they will resize properly.
Upgrade Notes
Mandatory before installing 2.0.5 into Elastic: Complete the Kibana dashboard cleanup prerequisite. Customer data is preserved; update browser bookmarks after installation because the new dashboards have different IDs.
-
PKI scanning requires a valid license (TQR-1231), and connectors are disabled by default. Adding
-scan-pkiactivates all connectors with stored configuration. No credentials inconfig.encmeans only ADCS auto-detection via DNS SRV is attempted. -
Elasticsearch index mapping update required for
tychon.pki.*andtychon.hsm.*fields. Re-run the index template setup from the Elasticsearch deployment guide or update via the DevTools console. -
ADCS LDAP requires TLS 1.2 minimum. LDAP over port 636 (LDAPS) or StartTLS on 389 are supported. Plaintext LDAP on 389 is allowed only for anonymous reads — credentials are refused when
TLSMode = none. -
No fields removed from existing event types. All 2.0.4 scan flags and output fields remain present. New fields are additive — however,
tychon.crypto.gradenow also appears on filesystem and keystore cert events (previously port-scan only), and the newtychon.type = "pki_platform"event type requires dashboard filter updates. See the Schema Changes section above.
Output Schema Changes — 2.0.4 → 2.0.5
The original field comparison was confirmed by a Windows Server 2016 QA run; later PKI reporting additions below were checked against the source. Dashboards targeting these fields require review.
NEW EVENT TYPE
tychon.type = "pki_platform"
Certificates discovered via ADCS LDAP, HashiCorp Vault PKI, AWS Private CA, Venafi, and DigiCert connectors emit a new tychon.type = "pki_platform" event. These records have no counterpart in v2.0.4 — they appear as new IDs and carry PKI-specific fields absent from all prior event types.
| Field | Type | Notes |
|---|---|---|
| event.category | configuration | Previously would have been file |
| event.action | pki_ca_discovered or pki_issued_cert_discovered | CA vs. issued cert from PKI platform |
| event.dataset | pki_certificate | Previously would have been certificate |
| tychon.pki.platform.type | keyword | adcs | venafi_vaas | venafi_tpp | aws_pca | vault_pki | digicert |
| tychon.pki.platform.host | keyword | FQDN of PKI platform server |
| tychon.pki.ca.name | keyword | CA common name from PKI platform |
| tychon.pki.ca.type | keyword | root | intermediate | issuing |
| tychon.pki.ca.status | keyword | Native CA status when available; otherwise Unknown |
| tychon.pki.ca.quantum_ready / migration_priority | boolean / keyword | CA readiness and migration priority for dashboard filtering |
| tychon.pki.source_dn | keyword | LDAP DN or Vault path used to fetch cert (ADCS/Vault) |
Dashboard action: Any Kibana filter or aggregation on tychon.type, event.action, or event.category must add the new values above to include PKI-platform certificate records.
NEW EVENT TYPE
pki_scan_health
Each configured PKI connector now emits a pki_scan_completed event in the pki_scan_health dataset. It includes tychon.pki.platform.type, tychon.pki.scan.status (success, partial, or failed), and tychon.pki.scan.ca_count. A failed or partial scan is therefore visible even when it found no certificates.
JSON reports add pki_platform_results summaries with platform_type, platform_host, ca_certificates, and issued_cert_count. Consumers of JSON reports can use this section to distinguish an empty PKI inventory from a missing platform result.
ADDED FIELDS Existing event types — fields added in 2.0.5
| Field | ES type | Event types | Notes |
|---|---|---|---|
| tychon.crypto.certificate_grade | keyword | port, filesystem, keystore, app_cert, pki_platform | Cert-intrinsic letter grade — comparable across all event types. Use this for cross-type grade dashboards (TQR-1226, TQR-1228). |
| tychon.crypto.certificate_score | integer | port, filesystem, keystore, app_cert, pki_platform | Numeric score backing certificate_grade. |
| tychon.crypto.grade | keyword | filesystem, keystore (was port-only) | Now emitted on cert-only events; equals certificate_grade when no TLS composite grade is available. Dashboards that assumed grade implies a port-scan event are now incorrect. |
| tychon.crypto.grade_score | integer | filesystem, keystore (was port-only) | Numeric score accompanying tychon.crypto.grade. |
| x509.not_before / x509.not_after | date | port, filesystem | Canonical ECS validity dates. Prefer over x509.validity.not_before/after (deprecated aliases, kept for backwards compatibility). |
| x509.public_key_algorithm | keyword | pki_platform certificates | Now emitted for PKI certificate events when the algorithm is known (TQR-1546). |
| certificate.not_before / certificate.not_after | date | port (was filesystem-only) | Now also emitted on port-scan chain certs. |
| omb.vulnerability_status, omb.module_name, omb.crqc_vulnerable_algos, omb.pqc_algos, omb.dsa_*, omb.vendor, omb.operating_system, omb.software_package_name, omb.certifications | keyword | filesystem | Full OMB M-23-02 assessment fields now on filesystem certs. Previously only on port-scan events. |
| omb.system_name | keyword | pki_platform (ADCS) | CA common name used as display name (full LDAP DN is too verbose for dashboards). |
| quantum_readiness.network.wifi_present, wifi_ssid, wifi_protocol, wifi_cipher, wifi_key_mgmt, wifi_pqc_vulnerable, wifi_quantum_risk | keyword / boolean | quantum_readiness | Wi-Fi interface detection and PQC risk assessment. Conditional — only present when a Wi-Fi adapter is detected. |
| tls.unknown_cipher_ids, tls.unknown_cipher_count, tls.unknown_group_ids, tls.unknown_group_count | keyword / integer | port | Non-standard cipher suite / key exchange group IDs advertised by the server but not in the scanner's cipher universe (TQR-1351–1353). |
VALUE FORMAT Date format change — RFC3339Nano → RFC3339
The following date fields changed from nanosecond-precision (2026-08-11T12:00:00.123456789Z) to second-precision (2026-08-11T12:00:00Z). Elasticsearch date mappings accept both formats — no re-indexing required. Dashboards that display raw timestamp strings will show the shorter format.
tychon.crypto.certificate_grade, tychon.crypto.certificate_score, tychon.crypto.grade, tychon.crypto.grade_score, and omb.system_name are now explicitly mapped in artifact/elasticsearch_mappings.go. Re-apply the index template to ensure these fields map as keyword / integer rather than dynamic-text. Existing indices will need a field mapping update or reindex if dynamic mapping already mistyped them.