Skip to main content

12 Certificates

Certificates centralizes accessible standard/anonymous PSEs, STRUSTSSL entries, and supported SSF applications.

Anonymized SAP certificate inventory
The inventory prioritizes expired and expiring certificates without exposing private keys.

What it shows

  • A current-only expiry runway, ordered by expiry and split into Expired, 0–7 days Critical, 8–30 Warning, and 31–365 Healthy. More distant certificates display as 365+ while retaining their exact value in detail.
  • Total, expired, and expiring certificates.
  • Filters by severity, PSE/application, host, and text.
  • Subject, issuer, serial number, fingerprint, and validity range.
  • Certificate details with identity, validity, and fingerprint.
  • Lifecycle contains only discovery, renewal, removal, or a 30/7-day threshold crossing; unchanged daily snapshots are not repeated.
  • Links from Events only when a certificate changes or crosses a severity boundary.

Thresholds are deterministic: warning at 30 days, critical at 7 days or when expired. The runway is not a time series: the agent collects the inventory daily and SPOT presents the current state. Certificates do not use ML forecasting.

Privacy and states

SPOT never collects private keys. Unsupported capability is unavailable, missing RFC permission is unauthorized, and an older producer reports Agent upgrade required rather than an empty inventory.

Investigation

Prioritize expired certificates, then critical certificates and PSEs shared by several applications. Confirm renewal in SAP and use the history to verify that SPOT observed the new fingerprint. No lifecycle change was recorded in this range means the inventory is valid but did not change during the window.