Certificate inventoryDiscover certificates continuously and connect each one to a service owner.
Inventory public and private TLS certificates across web servers, load balancers, reverse proxies, API gateways, network appliances, inspection systems, cloud services, containers, service meshes, application servers, databases, internal PKI, client authentication, and device-management platforms. Include certificates issued outside the central PKI team.
Record subject names, SANs, issuer, serial number, algorithm, key size or curve, validity dates, deployment location, environment, business service, technical owner, renewal mechanism, private-key location, trust chain, and whether the certificate is externally or internally trusted. Discovery without ownership only creates another dashboard.
Reconcile active network discovery with CA and certificate-management records. Certificates observed on the network but absent from the inventory may represent unmanaged services; inventory records that are no longer observed may be retired, moved, or broken.