Certificate Policies

Certificate Policies evaluate every certificate in your Inventory for lifecycle risk and cryptographic strength. When a certificate matches a policy's condition, it's surfaced as a finding in Dashboard and Inventory, with a severity that reflects how urgently it needs attention.

Available Certificate Policies

Identity & Secrets Intelligence currently ships the following built-in Certificate Policies:

PolicySeverityWhat It Flags
Certificate ExpiredHighThe certificate has already expired
Certificate About to ExpireHighThe certificate is due to expire within the next 30 days
Wildcard Certificate UsageHighThe certificate is a wildcard certificate
Weak AlgorithmHighThe certificate uses a weak or deprecated cryptographic algorithm, such as SHA-1, MD5, or a small RSA key size
Excessive Validity PeriodMediumThe certificate's validity period exceeds CA/Browser Forum guidance (more than 398 days)
Not Quantum ReadyLowThe certificate uses a classical algorithm (RSA, ECDSA, or ECC) that isn't resistant to quantum computing

What's Next


Did this page help you?
Footer Section