12 Certificates
Certificates centralizes accessible standard/anonymous PSEs, STRUSTSSL entries, and supported SSF applications.

What it shows
- A current-only expiry runway, ordered by expiry and split into Expired,
0–7 days Critical, 8–30 Warning, and 31–365 Healthy. More distant
certificates display as
365+while retaining their exact value in detail. - Total, expired, and expiring certificates.
- Filters by severity, PSE/application, host, and text.
- Subject, issuer, serial number, fingerprint, and validity range.
- Certificate details with identity, validity, and fingerprint.
- Lifecycle contains only discovery, renewal, removal, or a 30/7-day threshold crossing; unchanged daily snapshots are not repeated.
- Links from Events only when a certificate changes or crosses a severity boundary.
Thresholds are deterministic: warning at 30 days, critical at 7 days or when expired. The runway is not a time series: the agent collects the inventory daily and SPOT presents the current state. Certificates do not use ML forecasting.
Privacy and states
SPOT never collects private keys. Unsupported capability is unavailable,
missing RFC permission is unauthorized, and an older producer reports
Agent upgrade required rather than an empty inventory.
Investigation
Prioritize expired certificates, then critical certificates and PSEs shared by
several applications. Confirm renewal in SAP and use the history to verify that
SPOT observed the new fingerprint. No lifecycle change was recorded in this range means the inventory is valid but did not change during the window.