Release Notes - Version 2.0.5

TYCHON Quantum Readiness Scanner

Version 2.0.5

Latest Release Minor Feature Release

Release Date: October 2, 2026

Version 2.0.5 introduces the CAMP (Certificate Authority Management Platform) integration — a unified PKI platform connector framework that discovers CA and issued certificates from enterprise PKI platforms without touching the filesystem. Five production connectors ship in this release: Active Directory Certificate Services (ADCS) via LDAP with Kerberos/GSSAPI authentication, AWS Private Certificate Authority via a native SigV4 implementation (no AWS SDK), HashiCorp Vault PKI via token-authenticated REST, Venafi/CyberArk Certificate Manager in both VaaS and TPP modes, DigiCert ONE/CertCentral via separate service credentials with automatic rate-limit handling. All five connectors participate in full OMB M-23-02 quantum vulnerability assessment — every discovered certificate now carries the same 20+ OMB compliance fields that were previously only available for TLS port-scan certificates. PKI discoveries now appear in flat events, JSON, and HTML reports, with per-platform scan status. Certificate validity dates and cross-scanner PKI certificate IDs are corrected, along with later discovery, output, and assessment fixes described below.

Mandatory Prerequisite — BEFORE Installing 2.0.5 into Elastic

TQR-1573

Complete this Kibana dashboard cleanup before installing 2.0.5 into Elastic. Remove only the six dashboard saved objects listed below, after verifying that they are from version 2.0.2, 2.0.3, or 2.0.4.

  1. In Kibana, open Saved Objects.
  2. Filter by the tag Quantum Resilient.
  3. Filter the object type to Dashboard only.
  4. Validate that the dashboards selected for deletion are from version 2.0.2, 2.0.3, or 2.0.4.
  5. Select these six dashboards:
    • [TYCHON Quantum Command] Inventory
    • [TYCHON Quantum Command] Application Report
    • [TYCHON Quantum Command] Application Detail
    • [TYCHON Quantum Command] Certificate Operations Dashboard
    • [TYCHON Quantum Command] Application Connections Topology
    • [TYCHON Quantum Command] Cost Analysis
  6. Click Delete to remove the selected dashboard saved objects.
  7. Complete this cleanup before installing 2.0.5 into Elastic, then proceed with installation.
Kibana Saved Objects list showing the six TYCHON Quantum Command dashboards tagged Quantum Resilient and version 2.0.3.
The six dashboard saved objects to remove. This example shows version 2.0.3; validate that your selected dashboards are from version 2.0.2, 2.0.3, or 2.0.4 before deleting them. Click the image to view it at full size.

Customer data is preserved: Deleting these dashboard saved objects does not delete customer data.

Update browser bookmarks after installation: The new 2.0.5 dashboards have different IDs. Customers must update browser bookmarks to point to the new dashboards.

What's New at a Glance

ADCS Connector
Enumerates CA and issued certificates from Active Directory Certificate Services via LDAP. Three-tier authentication: GSSAPI/Kerberos → simple bind → anonymous. Auto-discovers domain controller via DNS SRV.
AWS Private CA Connector
Discovers CA certificates from AWS Private Certificate Authority. Native SigV4 signing — no AWS SDK required. Supports standard regions, GovCloud, FIPS endpoints, and custom C2S/SC2S overrides for Federal/DoD.
HashiCorp Vault PKI Connector
Enumerates CA and issued certificates from Vault's PKI secrets engine via token-authenticated REST. Auto-discovers all pki-type mounts and deduplicates certs across mounts by SHA-256 fingerprint.
OMB M-23-02 Full Certificate Assessment
All 20+ OMB compliance fields now emitted for every discovered certificate — filesystem, ADCS, AWS PCA, and Vault PKI. Previously only TLS port-scan certs received the full OMB block.
PKI Platform Field Namespace
New tychon.pki.* and tychon.hsm.* Elasticsearch field mappings separate PKI platform metadata from cryptographic certificate data.
Bug Fixes
Certificate dates and IDs, on-disk key discovery, encrypted configuration permissions, Splunk events, and assessment accuracy have been corrected. Details appear below.
Config Scan Performance
Config scan is significantly faster on endpoints running large applications (Teams, Slack, VS Code). Five fixes eliminate redundant work across the scan pipeline, reducing scan times on affected hosts from minutes to seconds.
Venafi / CyberArk Connector
Dual-mode connector for Venafi VaaS (CyberArk Certificate Manager SaaS) via API key and Venafi TPP (on-premises) via OAuth2 bearer token. Auto-detects deployment mode from stored configuration. No Venafi SDK required.
DigiCert ONE Connector
Enumerates DigiCert ONE private CAs and CertCentral certificate orders with separate credentials. CertCentral order requests handle rate limits with exponential backoff. No DigiCert SDK required.

PKI Platform — CAMP Integration

CAMP (Certificate Authority Management Platform) is a new connector framework that queries enterprise PKI platforms directly via their native APIs — LDAP, REST, SigV4, or OAuth2 — and feeds discovered certificates into the same PQC assessment and OMB M-23-02 pipeline as all other certificate sources. PKI certificates appear as pki_ca_discovered or pki_issued_cert_discovered events in the pki_certificate dataset. The JSON report includes certificate details in filesystem_scan_results and per-platform summaries in pki_platform_results. Each certificate has a source_file_path that uniquely identifies the platform and source (e.g. vault://addr/pki/cert/serial, ldap+pki://dc/CN=..., awspca://us-east-1/arn:aws:acm-pca:..., venafi-cloud://...certificates/{id}, digicert://www.digicert.com/order/{id}).

TQR-1192 NEW FEATURE

PKI Platform Connector Framework

New pki_platform.go defines the PkiPlatformConnector interface and shared types (PkiCertRecord, PkiScanResult) used by all PKI connectors. Activates via the -scan-pki flag alongside any configured connector.

# Activate all configured PKI platform connectors
certscanner -scan-pki -outputformat flatndjson
TQR-1506 TQR-1554 TQR-1555 TQR-1556 OUTPUT

PKI Results Across Reports

  • Flat events now include PKI platform and CA dashboard fields. A pki_scan_health event reports each configured connector's success, partial result, or failure, including scans that found no certificates.
  • JSON reports now include pki_platform_results with each platform's host, CA certificates, and issued-certificate count. Split JSON output retains this section even when a configured platform returned no certificates.
  • HTML reports now show discovered PKI platforms, scan status, CA and issued-certificate counts, and certificate details.
  • CBOM reports now include PKI platforms as CycloneDX service entries, alongside the discovered certificate components (TQR-1555).
TQR-1186 TQR-1187 TQR-1188 TQR-1189 TQR-1190 TQR-1191 NEW FEATURE

Active Directory Certificate Services (ADCS) Connector

Discovers CA and issued certificates from Windows ADCS by querying Active Directory over LDAP. No WinRM, PowerShell, or CertUtil dependency — works from any platform that can reach the domain controller on port 636 (LDAPS) or 389 (StartTLS).

Authentication (3-tier, auto-fallback)
  • 1
    GSSAPI / Kerberos — attempted first when no username is configured on domain-joined Linux and macOS hosts. Uses the running process's Kerberos credential cache. Not available on Windows; use tier 2 (simple bind) by storing credentials with -config-adcs-user.
  • 2
    Simple bind over TLS — when username is configured. Accepts UPN (user@domain) or DN format. RootDSE query auto-normalizes bare usernames to UPN. Refused if TLS mode is none.
  • 3
    Anonymous bind — last-resort fallback. Warning is logged. Returns empty set if AD denies anonymous reads of PKI containers.
Discovery Sources
  • Certification Authorities container — root and policy CA certs
  • NTAuthCertificates — enterprise CAs trusted for smart card / SSL auth
  • AIA container — intermediate / cross-cert distribution points
  • Enrollment Services — issuing CAs with enrollment URL metadata
  • Domain-wide userCertificate — issued leaf certificates (paged, RFC 2696, page size 500)
  • CertSrv\CertEnroll filesystem path (TQR-1187) — CA cert files on Windows CA servers, discovered automatically with -scanfilesystem
# Store ADCS credentials (one-time)
certscanner -config -config-adcs-host dc01.corp.com -config-adcs-user svc-scanner@corp.com -config-adcs-pass ••••••
# Scan (GSSAPI on domain-joined host — no credentials needed)
certscanner -scan-pki -outputformat flatndjson
DC auto-detection via DNS SRV (_ldap._tcp.dc._msdcs.{domain}) and USERDNSDOMAIN env. SHA-256 deduplication prevents the same CA cert from appearing twice across containers.
TQR-1195 TQR-1196 TQR-1197 TQR-1198 TQR-1199 TQR-1200 TQR-1201 NEW FEATURE

AWS Private Certificate Authority Connector

Discovers CA certificates from AWS Private CA (ACM PCA) using the ACM PCA REST API. Issued leaf certificates are not enumerated by this connector. No AWS SDK dependency — all API calls are signed with a native SigV4 implementation using only Go standard library (crypto/hmac, crypto/sha256). Supports scanning multiple regions in a single run via comma-separated list.

Credential Chain (4-tier)
  • 1. config.enc stored access key + secret
  • 2. AWS_ACCESS_KEY_ID / AWS_SECRET_ACCESS_KEY env vars
  • 3. ~/.aws/credentials file (default profile)
  • 4. IMDSv2 PUT-then-GET (EC2 instance role) — IMDSv1 explicitly not used
Endpoint Support
  • Standard: acm-pca.{region}.amazonaws.com
  • GovCloud: acm-pca.us-gov-{west|east}-1.amazonaws.com
  • FIPS (-config-awspca-fips): acm-pca-fips.{region}.amazonaws.com
  • C2S/SC2S (-config-awspca-endpoint): custom endpoint override for Federal/DoD isolated regions
# Store AWS PCA credentials and enable FIPS (one-time)
certscanner -config -config-awspca-region us-east-1,us-gov-west-1 -config-awspca-fips
# Scan
certscanner -scan-pki -outputformat flatndjson
TQR-1203 TQR-1204 TQR-1205 TQR-1206 TQR-1207 TQR-1208 NEW FEATURE

HashiCorp Vault PKI Connector

Enumerates CA and issued certificates from Vault's PKI secrets engine via Vault's REST API. Uses token authentication only — no Vault SDK dependency. Three API calls per mount: GET /v1/{mount}/ca/pem (raw CA PEM), LIST /v1/{mount}/certs (issued serial numbers), and GET /v1/{mount}/cert/{serial} per issued cert.

Token Credential Chain (3-tier)
  • 1. config.enc stored token (via -config-vault-token)
  • 2. VAULT_TOKEN environment variable
  • 3. ~/.vault-token file
Mount Discovery

When no mount is configured, calls GET /v1/sys/mounts and scans every mount of type pki automatically. A Vault instance with pki/ and pki-int/ has both enumerated with no extra configuration.

Key Behaviors
  • SHA-256 deduplication — a cert installed on multiple mounts (e.g. intermediate CA published to both its own mount and the root mount) is emitted exactly once per scan.
  • Enterprise namespaces — -config-vault-namespace sets X-Vault-Namespace header. Leave empty for Vault OSS (Community Edition).
  • source_file_path uses vault://addr/mount/cert/serial or vault://addr/mount/ca — queryable in Kibana and Splunk.
# Store Vault token (one-time)
certscanner -config -config-vault-addr https://vault.corp.com:8200 -config-vault-token hvs.XXXX
# Scan — auto-discovers all pki mounts
certscanner -scan-pki -outputformat flatndjson
TQR-1240 TQR-1242 TQR-1243 TQR-1244 TQR-1248 NEW FEATURE

Venafi / CyberArk Certificate Manager Connector

Enumerates certificates from both Venafi deployment modes — VaaS (CyberArk Certificate Manager SaaS) and TPP (Trust Protection Platform, on-premises) — from a single connector. Mode is auto-detected from which configuration value is stored: a stored API key activates VaaS; a stored URL activates TPP. No Venafi SDK required.

Deployment Modes
  • VaaS
    CyberArk Certificate Manager SaaS — API key via tppl-api-key header. Paginated enumeration via GET /outagedetection/v1/certificates. Source path: venafi-cloud://.../{id}.
  • TPP
    Trust Protection Platform (on-premises) — OAuth2 bearer token via POST /vedauth/authorize. Paginated enumeration via GET /vedsdk/certificates. Optional policy zone narrows scan scope. Source path: venafi-tpp://host/vedsdk/{dn}.
Configuration Flags
  • -config-venafi-apikey — VaaS API key (activates VaaS mode)
  • -config-venafi-url — TPP base URL (activates TPP mode)
  • -config-venafi-user — TPP bind username (UPN format)
  • -config-venafi-pass — TPP bind password
  • -config-venafi-zone — TPP policy folder (default: \VED\Policy)
# VaaS — store API key (one-time)
certscanner -config -config-venafi-apikey XXXXXXXXXX
# TPP — store credentials (one-time)
certscanner -config -config-venafi-url https://tpp.corp.com -config-venafi-user svc-scanner@corp.com -config-venafi-pass ••••••
# Scan (same flag for both modes)
certscanner -scan-pki -outputformat flatndjson
SHA-256 deduplication across pages. Credentials stored in config.enc — never passed on the command line at scan time. TPP mode requires the tychon-scanner OAuth client ID to be registered in Venafi before use.
TQR-1250 TQR-1251 TQR-1252 TQR-1253 TQR-1254 TQR-1255 NEW FEATURE

DigiCert ONE / CertCentral Connector

Enumerates private CAs from DigiCert ONE and certificate orders from CertCentral via separate REST APIs. Each service needs its own credential. The CertCentral order API handles rate limiting with exponential backoff, honoring the Retry-After header when present. No DigiCert SDK is required.

Discovery Sources
  • Private CAs — DigiCert ONE GET /certificate-authority/api/v1/ca lists CAs; PEM certificates are downloaded per CA. Source path: digicert://{one_host}/ca/{id}.
  • Certificate orders — GET /order/certificate with page size 1,000. Auth pre-validated via GET /user/me before paginating. Source path: digicert://www.digicert.com/order/{id}.
Key Behaviors
  • Rate-limit handling — 429 responses retried with exponential backoff (2s initial, 60s cap).
  • Separate credentials — TYCHON_DIGICERT_API_KEY supplies the CertCentral order key; TYCHON_DIGICERT_ONE_API_KEY supplies the DigiCert ONE Private CA token. A scan configured for only one service can still return its results.
  • DigiCert ONE host — defaults to https://one.digicert.com; TYCHON_DIGICERT_ONE_URL or runtime -digicert-url selects a regional or private-cloud host. See the DigiCert guide for configuration.
# Have your secret manager provide both DigiCert key environment variables, then store them encrypted
certscanner -config
# Scan
certscanner -scan-pki -outputformat flatndjson

Expanded Dashboard Suite

The 2.0.5 dashboard packages for Elasticsearch/Kibana and Splunk each contain 13 dashboards. Seven additional dashboard subjects extend the existing Inventory, Application Report, Application Detail, Certificate Operations, Application Connections Topology, and Cost Analysis views:

DashboardPurposeRelated tickets
Crypto LibrariesLibrary versions, PQC capability, and remediation exposure.Splunk: TQR-1512
Application Crypto InventoryApplication-level cryptographic inventory and quantum-readiness posture.Splunk: TQR-1507
IPSec & VPN SecurityVPN and tunnel inventory, cryptographic settings, and risk.Splunk: TQR-1515
Keystores & Key MaterialKeystore inventory, accessibility, certificates, and key material.Splunk: TQR-1516
Installed ApplicationsSoftware inventory, versions, vendors, and host coverage.Splunk: TQR-1513
PKI Platform and CA IntelligencePKI platform coverage, CA hierarchy, certificate expiry, and CA risk.Elastic: TQR-1529; Splunk: TQR-1541
CAMP Integration HealthPlatform scan freshness, event trends, errors, and CA counts.Elastic: TQR-1521; Splunk: TQR-1539

See the Elasticsearch dashboard overview and Splunk dashboard overview for guides to the documented dashboards. In Splunk, Application Connections Topology is titled Application Topology Explorer, and Certificate Operations is titled Certificate Report.

Additional Scanning and Reporting Features

NEW FEATURE

Multiple Report Formats from One Scan

Pass a comma-separated list to -outputformat to write several report formats from one scan. With the example below, the scanner writes scan.ndjson, scan.cbom.json, and scan.html. The ndjson alias selects flatndjson.

certscanner -mode local -outputformat flatndjson,cbom,html -output scan.json

See Output Features for format selection and file naming.

TQR-1356 NEW FEATURE

Native HCL BigFix QRA Report

The new -outputformat hcl option produces JSON in the HCL BigFix QRA web-report format for consumption by BigFix. When requested alongside other formats, its file uses the .hcl.json extension to distinguish it from the scanner's standard JSON report.

TQR-1249 OUTPUT

Certificate Risk Properties in CBOM

CBOM certificate components now include cert:pqc-vulnerable and, when available, cert:quantum-risk and cert:migration-priority. These properties let downstream consumers identify vulnerable certificates and prioritize migration from the CBOM itself.

TQR-1354 TQR-1351 TQR-1352 TQR-1353 NEW FEATURE

Additional TLS PQC Group Recognition

TLS scanning now recognizes additional pre-IANA Kyber draft key-exchange group IDs, including X25519Kyber768Draft00. Servers advertising these older draft groups can be identified alongside standardized ML-KEM groups. Unknown cipher and group IDs are also retained in the output fields listed in the schema section below.

DISCOVERY

Improved Linux Cryptographic Library Detection

Linux scans can extract cryptographic library versions directly from ELF shared-library binaries instead of relying only on filenames. Version definitions, embedded version strings, and shared-object names provide additional evidence when package or filename information is incomplete. Library PQC capability assessments also use updated version thresholds.

OMB M-23-02 Full Certificate Assessment

TQR-1202 NEW FEATURE

Full OMB Fields on All Certificate Events

Prior to 2.0.5, only TLS port-scan certificate events carried the full OMB M-23-02 compliance block. Filesystem, ADCS, AWS PCA, and Vault PKI certificate events emitted only omb.sig_tier. This release adds applyCertOmbAssessments() which runs over all discovered certificates before output, populating all 20+ OMB fields from the certificate's own public key and issuer metadata.

Field Example (RSA-2048 leaf) Notes
omb.vulnerability_statusVulnerableVulnerable / Not Vulnerable
omb.sig_tierCLASSICALCLASSICAL / MODERN / LEGACY / PQC READY
omb.dsa_algorithmsRSAKey algorithm family (from cert's own public key)
omb.dsa_parametersRSA: 2048Algorithm and key size
omb.dsa_hash_algorithmsSHA-256Hash used in the issuer's signature
omb.crqc_vulnerable_algosRSAAlgorithms broken by a cryptographically relevant quantum computer
omb.vendorTYCHON IncIssuer organization from cert Subject

These fields are populated on PKI certificate events, filesystem_certificate_discovered, keystore_certificate, and the JSON report's filesystem_scan_results / orphan_findings.filesystem_certificates blocks.

Elasticsearch Mappings — PKI & HSM Namespaces

TQR-1193 NEW FEATURE

tychon.pki.* and tychon.hsm.* Field Mappings

New Elasticsearch index mappings separate PKI platform metadata from cryptographic certificate data. PKI platform metadata (source platform, CA type, enrollment URL) lives exclusively in tychon.pki.*; certificate cryptographic data stays in certificate.* and x509.*.

Selected tychon.pki.* Fields
  • tychon.pki.platform.type
  • tychon.pki.platform.vendor
  • tychon.pki.platform.host
  • tychon.pki.ca.name
  • tychon.pki.ca.type
  • tychon.pki.ca.pqc_vulnerable
  • tychon.pki.ca.migration_priority
  • tychon.pki.ca.enrollment_url
Selected tychon.hsm.* Fields
  • tychon.hsm.vendor
  • tychon.hsm.product
  • tychon.hsm.fips_level
  • tychon.hsm.detection_method
  • tychon.hsm.pkcs11_library
  • tychon.hsm.serial

Bug Fixes

Fixes cover certificate output, on-disk discovery, configuration storage, Splunk reporting, assessment accuracy, SSH reporting, and dashboard visuals and filters.

TQR-1221 BUG FIX

Certificate Validity Dates Inconsistent Across Event Types

Root Cause

Certificate validity dates were emitted under different field names depending on where the cert was found: x509.validity.not_before/after (TLS port scan), tls.certificate.not_after (keystores), or no date fields at all (app, config, archive certs). There was no common field set that worked across all event types in a single Kibana query.

Fix

All certificate event types now emit x509.not_before, x509.not_after, certificate.not_before, and certificate.not_after in RFC 3339 format. Legacy fields (x509.validity.*, tls.certificate.not_after) are retained but marked deprecated in code comments. No existing dashboards break.

Affected output paths: output_flat_ndjson.go (6 cert-event blocks), splunk_connector.go, kafka_connector.go, output_detail_level.go.
TQR-1222 BUG FIX

PKI Certificate IDs Scanner-Anchored Instead of Cert-Anchored

Root Cause

GenerateFilesystemCertID() was used for all PKI connector certs. That function always runs in ScanModeLocal, which includes the observer's host ID in the hash. Scanning the same ADCS domain or Vault instance from two different scanner hosts produced two different event.id values for the same physical certificate — doubling every PKI record in Elasticsearch.

Fix

New GeneratePKICertID() function in unique_id_generator.go runs in ScanModeRemote, excluding the observer ID. The ID is keyed on sha256_fingerprint | serial_number | source_path. The source path encodes the PKI server address, preventing cross-server collisions. Repeated scans of the same PKI platform now upsert, not duplicate.

TQR-1494 SECURITY FIX

Existing Encrypted Configuration File Permissions

Saving an existing config.enc did not correct permissions that had become too broad. The save path now restricts the file to owner access before writing and trims any bytes left from a longer previous value.
TQR-1532 TQR-1533 TQR-1534 BUG FIX

On-Disk Key and Certificate Discovery

Scans could miss extensionless key or certificate files, OpenSSH private keys, and relevant files beneath user configuration directories. Discovery now checks likely filenames and file contents, including the filesystem scan path, so these findings can appear in scan results. Encrypted OpenSSH keys can be identified without exposing private key material.
TQR-1463 BUG FIX

Splunk Application and Inventory Events Restored

The Splunk connector again builds application events and per-port PQC inventory events from the application report, restoring those records for Splunk consumers.
TQR-1544 TQR-1545 TQR-1448 TQR-1547 TQR-1551 TQR-1559 ACCURACY

Output and Assessment Corrections

  • -outputformat validation now accepts comma-separated formats and hcl, matching the scanner's supported output options (TQR-1544).
  • EC P-384 and P-521 certificates no longer fall through to P-256 grading, and PQC certificate signatures receive the correct signature tier (TQR-1545, TQR-1448).
  • DigiCert order SHA-1 thumbprints are preserved; Vault CA classification no longer depends on mount order; ADCS RSA-2048 root CAs receive the intended critical migration priority (TQR-1547, TQR-1551, TQR-1559).
TQR-1565 BUG FIX

SSH Protocol and Host-Key Reporting Restored

Local scans could omit SSH listeners or report them without SSH protocol version and host-key information. SSH results are now retained in inventory and application output, with the protocol version, server banner, and host-key details reported when available.
TQR-1566 BUG FIX

Application Report Dashboard Visual Restored

The Application Report visual could appear blank when documents lacked x509.public_key_curve. The Curve grouping now includes documents without that field, allowing the visual to display results even when curve information is unavailable.
TQR-1562 BUG FIX

Certificate Inventory Single-Click Filtering

Clicking a Certificate Inventory cell previously highlighted it without applying the dashboard filter until a second click. The first click now highlights the cell and applies the filter together; clicking again removes the highlight and filter.
TQR-1291 BUG FIX

Splunk Inventory Routing and Linked Events

SSH inventory records could use the wrong Splunk sourcetype and disappear from inventory searches. Canonical inventory events now use tychon:pqc_inventory, and linked application and source inventory records are consolidated while preserving application fields.
TQR-1576 BUG FIX

Application Discovery Event Actions

Application discovery records could omit event.action. Flat NDJSON, Elasticsearch, and Splunk records built through the shared flat event path now include event.action=application_discovered, including applications without ports.
TQR-1564 BUG FIX

Elasticsearch Index Template Mappings

Missing quantum_readiness mappings could prevent dashboard fields from being interpreted correctly. The scanner's index template and the documented Flat NDJSON deployment template now include the required mappings and use consistent field definitions.
TQR-1182 BUG FIX

Splunk Certificate Count Normalization

Raw Splunk event totals could overcount certificates compared with Elasticsearch. Certificate reporting now normalizes counts by unique certificate ID and event.dataset so repeated records are counted consistently for the same certificate dataset.

Additional Discovery Corrections

TQR-1406 BUG FIX

VPN Detection and Assessment Improvements

strongSwan installations using swanctl configuration can now be discovered alongside legacy ipsec.conf installations. VPN client PQC assessments use corrected version comparisons and readiness rules, including proper numeric version ordering for FortiClient. Client detection and capability assessment help identify candidates for migration; they do not prove that a connection negotiated PQC.

TQR-1563 BUG FIX

Elastic Agent Version Detection on Linux

Linux scans now identify Elastic Agent versions that previously could be omitted from application inventory, improving software-version reporting for these installations.

Performance Improvements

Five improvements to the config scan pipeline significantly reduce scan time on endpoints running large modern applications. Hosts with Microsoft Teams, Slack, VS Code, or similar apps see the largest gains — these applications include large dependency trees that the scanner previously had to traverse in full. Scan times on affected hosts drop from several minutes to seconds.

TQR-1232 PERFORMANCE

Config Scan Performance Overhaul

TQR-1233 Smarter Directory Traversal

Config scan now skips known non-cryptographic dependency and build directories (such as package caches, version control metadata, and compiler output folders) that can contain tens of thousands of files with no certificate or key material. On a host with VS Code or Teams installed, this alone reduces the number of files inspected by an order of magnitude. Results are also shared across scan phases so the same directory is never traversed more than once per scan run.

TQR-1234 Parallel Application Scanning

Config scan previously processed one application at a time. Multiple applications are now scanned concurrently, so a host running many processes no longer waits for each application to complete before starting the next. Total scan time scales with the slowest individual application rather than the sum of all applications.

TQR-1235 Reduced File Inspection Overhead

The scanner previously made multiple passes over the file list for each application directory — one to locate configuration files and a separate one to locate certificate files. These passes have been merged into a single traversal, halving the file-inspection work per application root. Oversized files are also skipped earlier, before any disk I/O is attempted.

TQR-1236 Eliminated Redundant File Reads

Certificate and key files discovered during the config scan were previously read from disk twice — once to identify the file type and once to extract its contents. Each file is now read once, with the contents passed directly to the extraction step. On endpoints with many bundled certificate files, this reduces disk I/O proportionally to the number of files found.

TQR-1237 No Duplicate Certificate Processing

The config scan and the filesystem certificate scan previously processed the same certificate files independently, performing redundant parsing work. Certificate files handled by the config scan are now tracked and automatically skipped by the filesystem scan, ensuring each file is parsed exactly once per scan run regardless of how many scan phases reference the same application directory.

Additional Security Hardening

TQR-1347 TQR-1349 TQR-1350 SECURITY

Bounded Network Responses and HTTPS S3 Uploads

  • SSH scanning rejects oversized packets before allocating their payload and reads packet contents completely (TQR-1347).
  • HTTP response-size limits also apply to chunked responses, bounding response consumption when no content length is supplied (TQR-1350).
  • S3 uploads reject non-HTTPS custom endpoint URLs to protect the upload transport (TQR-1349).
SECURITY

PKI Credential Redaction in Reports

PKI platform host and URL fields strip embedded credentials before being written to CBOM and flat-event reports. Platform URLs also omit query strings and fragments, reducing the risk of exposing sensitive configuration through report metadata.

Library Updates

TQR-1166 DEPENDENCY

New and Updated Third-Party Dependencies

Package Change Purpose
github.com/go-ldap/ldap/v3 New — v3.4.14 ADCS LDAP connector. US-origin; used by HashiCorp Vault, Grafana, Kubernetes.
github.com/jcmturner/gokrb5/v8 Promoted to direct — v8.4.4 Kerberos/GSSAPI authentication for ADCS LDAP. US-origin; used by AWS SDK, Grafana.
github.com/cloudflare/circl Updated — v1.6.5 (TQR-1403) Refreshes the scanner's post-quantum cryptography dependency.
golang.org/x/crypto Updated — v0.56.0 (TQR-1425, TQR-1435) Includes security updates addressing SSH denial-of-service advisories.

All third-party dependencies are US-origin and widely adopted. CGO_ENABLED=0 is maintained — no CGO required. Kerberos/GSSAPI authentication is supported on Linux and macOS. On Windows, use simple bind by storing ADCS credentials with -config-adcs-user.

TQR-1574 TOOLCHAIN

Go 1.26.7 Upgrade

The scanner build toolchain is updated to Go 1.26.7. Builds retain CGO_ENABLED=0 support for Linux amd64/arm64, Windows amd64, and macOS amd64/arm64.

Documentation

TQR-1168 TQR-1194 DOCS

New and Updated Documentation Pages

New Pages
Updated Pages
  • Cryptographic Protocol Coverage — 24 new protocol sections: DTLS, QUIC/HTTP-3, RADIUS, TACACS+, NTP/NTS, WireGuard, mTLS, Plaintext Detector, NTLM, FIPS Mode, AirPlay, WiFi/WPA, OPC-UA, OT protocols, Noise Protocol, Signal/MLS, Tor, ZRTP, DTLS-SRTP/WebRTC, S/MIME, PGP, OpenVPN, IPSec, BigFix
  • Documentation Index — new PKI Platform section with cards for all five connectors
  • Output Features and TYCHON Format — supported formats clarified and retired format instructions removed (TQR-1504, TQR-1558)

⚠️ Known Issues

macOS EventLog truncation (TQR-1557)

Known limitation: macOS unified logging truncates messages at approximately 1 KB, which can leave larger certificate and PKI events as incomplete JSON. Workaround: Write flatndjson or json output to a file for complete records. See EventLog Format for details. Windows and Linux EventLog output are unaffected.

Kibana Vega panel rendering (TQR-1572)

Known limitation: Vega panels may not resize correctly after a dashboard panel is expanded or collapsed. Workaround : Click refresh button or reload the page and they will resize properly.

Upgrade Notes

Mandatory before installing 2.0.5 into Elastic: Complete the Kibana dashboard cleanup prerequisite. Customer data is preserved; update browser bookmarks after installation because the new dashboards have different IDs.

  • PKI scanning requires a valid license (TQR-1231), and connectors are disabled by default. Adding -scan-pki activates all connectors with stored configuration. No credentials in config.enc means only ADCS auto-detection via DNS SRV is attempted.
  • Elasticsearch index mapping update required for tychon.pki.* and tychon.hsm.* fields. Re-run the index template setup from the Elasticsearch deployment guide or update via the DevTools console.
  • ADCS LDAP requires TLS 1.2 minimum. LDAP over port 636 (LDAPS) or StartTLS on 389 are supported. Plaintext LDAP on 389 is allowed only for anonymous reads — credentials are refused when TLSMode = none.
  • No fields removed from existing event types. All 2.0.4 scan flags and output fields remain present. New fields are additive — however, tychon.crypto.grade now also appears on filesystem and keystore cert events (previously port-scan only), and the new tychon.type = "pki_platform" event type requires dashboard filter updates. See the Schema Changes section above.

Output Schema Changes — 2.0.4 → 2.0.5

The original field comparison was confirmed by a Windows Server 2016 QA run; later PKI reporting additions below were checked against the source. Dashboards targeting these fields require review.

NEW EVENT TYPE tychon.type = "pki_platform"

Certificates discovered via ADCS LDAP, HashiCorp Vault PKI, AWS Private CA, Venafi, and DigiCert connectors emit a new tychon.type = "pki_platform" event. These records have no counterpart in v2.0.4 — they appear as new IDs and carry PKI-specific fields absent from all prior event types.

FieldTypeNotes
event.categoryconfigurationPreviously would have been file
event.actionpki_ca_discovered or pki_issued_cert_discoveredCA vs. issued cert from PKI platform
event.datasetpki_certificatePreviously would have been certificate
tychon.pki.platform.typekeywordadcs | venafi_vaas | venafi_tpp | aws_pca | vault_pki | digicert
tychon.pki.platform.hostkeywordFQDN of PKI platform server
tychon.pki.ca.namekeywordCA common name from PKI platform
tychon.pki.ca.typekeywordroot | intermediate | issuing
tychon.pki.ca.statuskeywordNative CA status when available; otherwise Unknown
tychon.pki.ca.quantum_ready / migration_priorityboolean / keywordCA readiness and migration priority for dashboard filtering
tychon.pki.source_dnkeywordLDAP DN or Vault path used to fetch cert (ADCS/Vault)

Dashboard action: Any Kibana filter or aggregation on tychon.type, event.action, or event.category must add the new values above to include PKI-platform certificate records.

NEW EVENT TYPE pki_scan_health

Each configured PKI connector now emits a pki_scan_completed event in the pki_scan_health dataset. It includes tychon.pki.platform.type, tychon.pki.scan.status (success, partial, or failed), and tychon.pki.scan.ca_count. A failed or partial scan is therefore visible even when it found no certificates.

JSON reports add pki_platform_results summaries with platform_type, platform_host, ca_certificates, and issued_cert_count. Consumers of JSON reports can use this section to distinguish an empty PKI inventory from a missing platform result.

ADDED FIELDS Existing event types — fields added in 2.0.5

FieldES typeEvent typesNotes
tychon.crypto.certificate_gradekeywordport, filesystem, keystore, app_cert, pki_platformCert-intrinsic letter grade — comparable across all event types. Use this for cross-type grade dashboards (TQR-1226, TQR-1228).
tychon.crypto.certificate_scoreintegerport, filesystem, keystore, app_cert, pki_platformNumeric score backing certificate_grade.
tychon.crypto.gradekeywordfilesystem, keystore (was port-only)Now emitted on cert-only events; equals certificate_grade when no TLS composite grade is available. Dashboards that assumed grade implies a port-scan event are now incorrect.
tychon.crypto.grade_scoreintegerfilesystem, keystore (was port-only)Numeric score accompanying tychon.crypto.grade.
x509.not_before / x509.not_afterdateport, filesystemCanonical ECS validity dates. Prefer over x509.validity.not_before/after (deprecated aliases, kept for backwards compatibility).
x509.public_key_algorithmkeywordpki_platform certificatesNow emitted for PKI certificate events when the algorithm is known (TQR-1546).
certificate.not_before / certificate.not_afterdateport (was filesystem-only)Now also emitted on port-scan chain certs.
omb.vulnerability_status, omb.module_name, omb.crqc_vulnerable_algos, omb.pqc_algos, omb.dsa_*, omb.vendor, omb.operating_system, omb.software_package_name, omb.certificationskeywordfilesystemFull OMB M-23-02 assessment fields now on filesystem certs. Previously only on port-scan events.
omb.system_namekeywordpki_platform (ADCS)CA common name used as display name (full LDAP DN is too verbose for dashboards).
quantum_readiness.network.wifi_present, wifi_ssid, wifi_protocol, wifi_cipher, wifi_key_mgmt, wifi_pqc_vulnerable, wifi_quantum_riskkeyword / booleanquantum_readinessWi-Fi interface detection and PQC risk assessment. Conditional — only present when a Wi-Fi adapter is detected.
tls.unknown_cipher_ids, tls.unknown_cipher_count, tls.unknown_group_ids, tls.unknown_group_countkeyword / integerportNon-standard cipher suite / key exchange group IDs advertised by the server but not in the scanner's cipher universe (TQR-1351–1353).

VALUE FORMAT Date format change — RFC3339Nano → RFC3339

The following date fields changed from nanosecond-precision (2026-08-11T12:00:00.123456789Z) to second-precision (2026-08-11T12:00:00Z). Elasticsearch date mappings accept both formats — no re-indexing required. Dashboards that display raw timestamp strings will show the shorter format.

x509.validity.not_before x509.validity.not_after tls.certificate.not_before tls.certificate.not_after tls.server.not_before tls.server.not_after
ES mapping update: tychon.crypto.certificate_grade, tychon.crypto.certificate_score, tychon.crypto.grade, tychon.crypto.grade_score, and omb.system_name are now explicitly mapped in artifact/elasticsearch_mappings.go. Re-apply the index template to ensure these fields map as keyword / integer rather than dynamic-text. Existing indices will need a field mapping update or reindex if dynamic mapping already mistyped them.