
Blackfort Certificate Intelligence
One certificate register across all your PKI worlds
Certificate Intelligence consolidates certificates from ADCS, EJBCA, Vault PKI, step-ca, Kubernetes, cloud vaults, TLS endpoints and CT logs in one audit-ready register. Read-only, operated in your environment, without access to private keys and without changes to your existing PKI. For DORA, information security and audit.
Microsoft ADCS · EJBCA · HashiCorp Vault PKI · smallstep step-ca · Kubernetes/cert-manager · Azure Key Vault · AWS Certificate Manager · Google Certificate Manager · TLS scan · CT logs · File import
DORA
DORA requires an up-to-date certificate register
“Financial entities shall create and maintain a register for all certificates and certificate-storing devices for at least ICT assets supporting critical or important functions. Financial entities shall keep that register up to date.”
“Financial entities shall ensure the prompt renewal of certificates in advance of their expiration.”
Para. 4: the register
Certificate Intelligence provides the technical basis: one register across all sources, mapping to critical or important functions, owners, expiry dates, revocation status and an audit-ready export. It stays current because the sources are re-read regularly.
Para. 5: timely renewal
Upcoming expiries appear staggered by criticality and go to your monitoring, to Jira and as a daily summary to Teams. Renewal continues with your existing tools; Certificate Intelligence shows whether it happened in time.
The register also supports the identification of ICT assets and the cryptography requirements of DORA Art. 8 and 9, as well as the inventory expectations of NIS2 and ISO 27001. It supports implementation and evidence; it does not replace a legal assessment, and which obligations apply to your organisation depends on your classification under DORA.
Grown PKI
Every source only knows its own slice
Certificates come from several CAs, cloud vaults and public orders and live on servers, devices and services. A shared governance model across them is usually missing, so audit questions get answered with Excel lists.
Today
- Microsoft ADCSknows what ADCS has issued
- EJBCA, Vault, step-caeach know their own inventory
- Azure Key Vaultknows the certificates in the vault
- Public CAsknow their orders
- Monitoringknows the endpoints it watches
No shared register, no shared ownership
With Certificate Intelligence
All sources flow into one register:
- one register across all sources
- owners and functions
- critical / important per certificate
- expiry by criticality
- revocation status via CRL and OCSP
- crypto findings
- audit trail
- Jira tickets, monitoring, Teams, auditor export
How it works
Collect, consolidate, assess
Collect
Small, openly readable export scripts at CAs and key stores, a built-in TLS scanner, Certificate Transparency logs and file import for isolated networks. Only public certificates are transferred.
Consolidate
One register across all sources, each certificate held once. Plus your governance data: owners, function or process, critical or important function.
Assess and report
Expiry by criticality, revocation status, weak cryptography, key reuse, orphans. Findings become Jira tickets with a due date and go to your monitoring, as a daily summary to Teams and as a complete export to auditors.
Show technical architecture
- All sources write into a stable, versioned JSON exchange format (exchange-v1). The logic lives in the register; the export scripts stay simple and individually reviewable.
- The primary key is the SHA-256 fingerprint; imports are merged, never replaced. Governance data survives every new import.
- Three field classes per certificate: technical fields from the certificate (immutable), governance fields (maintained, including custom columns) and provenance (last imported, last seen, source class internal / external / mixed).
- Two transfer paths per source: HTTPS push with a token, or file export for isolated segments. Tokens are created, revoked and rotated centrally.
- Findings: expiry by criticality, revocation status via CRL (CDP) and OCSP (AIA), weak cryptography (RSA below 2048, SHA-1), self-signed on a critical function, wildcard, key reuse (shared SPKI), orphans, chain and trust resolution via AKI/SKI.
The application
What Certificate Intelligence looks like today
The views are taken from the running application; its interface is in German.




All data shown is synthetic (example domains such as example.com / demo.internal). A public demo is available at certintel.demo.blackfort-tec.de (login demo / demo).
Findings
What Certificate Intelligence makes visible
Example finding types, illustrative and not taken from a specific customer inventory.
Certificate expires in 14 days
highCN=portal.intern.example • critical function
Critical certificate of an internal portal with no documented owner responsible for renewal.
Revoked but still in use
highOCSP: revoked • endpoint still serves the certificate
Revoked according to OCSP, yet still served by a reachable endpoint.
Weak cryptography
mediumRSA 1024 • SHA-1
Outdated key length and weak signature algorithm on an important function.
Unknown public certificate
mediumCT log • *.example.com
Discovered via Certificate Transparency, not part of the managed inventory.
Positioning
The governance layer over your PKI
Certificate Intelligence does not take over your PKI and migrates nothing. It looks across all sources and makes inventory, ownership and risks auditable, including where a CLM platform is already in place.
Your CA
Issues certificates and knows its own inventory. A view across several CAs, cloud vaults and public certificates is not its job.
Your monitoring
Warns about expiry on the endpoints it knows. It does not see owners, critical functions or certificates outside monitored endpoints.
A CLM platform
Issues, renews and deploys. For that it needs extensive privileges and becomes a privileged system itself, often with a migration of the existing PKI.
Certificate Intelligence
Reads from all of these sources, consolidates them in one register and makes governance auditable. Your CAs and your CLM stay as they are.
Deliberately not included: issuance, automated renewal and deployment of certificates. If you want to build Certificate Lifecycle Management from scratch, you need a CLM platform for that; Certificate Intelligence checks its results.
Security architecture
No new privileged system
A system that issues and deploys certificates needs extensive privileges in your PKI. Certificate Intelligence does not. It is an inventory and only sees what is public on the certificate anyway.
Read-only
No changes to CAs, templates, vaults or services. No issuance, no revocation, no deployment.
No access to CA or keys
The register receives public certificates only, by push or as a file. It connects neither to your CA nor to key stores.
Openly readable export scripts
At the CA and key stores, small scripts of 72 to 220 lines run; for the Microsoft CA a PowerShell script with a SHA256 checksum. Your security team reads the source code beforehand.
Air-gap capable
Runs as containers in your environment, with an offline package and file import for isolated segments.
Roles
Web login with the roles admin (writes) and viewer (reads). Sign-in via OIDC/Entra ID is planned.
Audit trail
Append-only history of all changes; archiving instead of deletion, reversible and logged.
Integrations
Certificate status where your team already looks
Jira Cloud and Data Center · Prometheus + Grafana · PRTG · Nagios · Icinga · Checkmk · Zabbix · Elastic · Splunk · Datadog · Dynatrace · New Relic · SolarWinds Observability · ManageEngine OpManager
Findings become Jira tickets with a due date, and Certificate Intelligence keeps checking until they are resolved. Plus 13 monitoring integrations, tested in the Blackfort lab against the real software in October 2026, a daily summary card in a Microsoft Teams channel and the complete Excel/CSV export for auditors.
Show all integrations and connection methods
Jira Cloud and Data Center
Finding becomes a ticket with a due date, re-checked until resolved
Prometheus + Grafana
Metrics endpoint, dashboard, alert rules
PRTG
HTTP Data Advanced sensor
Nagios
Check plugin
Icinga
Check plugin
Checkmk
Check plugin as a classic check
Zabbix
Template with items and triggers
Elastic
Metricbeat, queries via ES|QL
Splunk
OpenTelemetry Collector to HEC
Datadog
Datadog Agent, OpenMetrics check
Dynatrace
OpenTelemetry (OTLP)
New Relic
OpenTelemetry (OTLP)
SolarWinds Observability
OpenTelemetry (OTLP)
ManageEngine OpManager
Script monitor via SSH
Jira is connected with an API token (Cloud) or personal access token (Data Center) that is stored only and never displayed again. Monitoring fetches the values from two read-only endpoints (Prometheus format and PRTG JSON) with a dedicated monitoring token that cannot submit or change anything. Product names mentioned are trademarks of their respective owners and describe compatibility; no partnership exists.
Benefits
Who gets what out of it
PKI operations
One inventory across all CAs instead of scattered Excel lists. Expiry by criticality, sources and data age in one view.
Information security
Weak cryptography, unknown public certificates, missing owners and revoked but active certificates visible in one place.
DORA and IT risk
Link certificates to critical or important functions and keep the register demonstrably up to date.
Internal and external audit
Receive the current inventory with governance fields and history as an Excel file, without an account in the system.
Offers and pricing
Try it, license it or have it introduced
Pilot
Certificate Inventory Pilot
free of charge
- 30 days
- up to 500 certificates
- full feature set
- self-install in your environment
- support by email
- price band and decision date agreed upfront
Licence
Annual licence
from €2,490 net
| Certificates | per year |
|---|---|
| up to 250 | €2,490 |
| up to 1,000 | €4,900 |
| up to 5,000 | €9,900 |
| up to 10,000 | €14,900 |
| up to 25,000 | €19,900 |
| over 25,000 | on request |
- twelve months, updates and standard product support included
- all released connectors and features in every tier
- no surcharges per user, source or feature
- 20 % growth tolerance until renewal
- self-install without an installation fee
We count unique end-entity certificates in the operational inventory; duplicate finds, chain CA certificates and archived certificates do not count. We confirm the inventory size and band in your environment before contract signature. Capacity measured up to 30,000 certificates on 4 vCPU and 8 GB RAM. Guided introduction on a time-and-material basis at €150 per remote hour with an agreed budget cap (typically €450 for one source, €1,200 for up to three sources).
Request a quoteGuided
Assessments
- Quick Assessment€4,900
PKI and certificate check
Orientation on one PKI or trust environment: interviews, documents, technical samples, risks and a prioritised action plan.
- PKI Assessment€9,900
Technology and governance
In-depth review of up to two PKI/trust environments, including software-supported analysis of up to five exports.
- Enterprise Intelligence Assessment€14,900 to €19,900
PKI and certificate register
Technical review plus introduction of the register at your site: source connection, governance mapping, critical functions, findings, management summary. Includes a 60-day project licence.
Fixed prices after scoping. Review and action plan; no remediation and no attestation. If you sign an annual licence within 60 days of the final report, we credit €1,000, at most 20 % of the first licence year.
Request an assessmentAll prices for business customers, net plus VAT.
Frequently asked questions
Is Certificate Intelligence a Certificate Lifecycle Management product?+
No. Certificate Intelligence does not issue, renew or deploy certificates. It consolidates the inventory from your CAs, cloud vaults, network scans and CT logs in one register, assesses it and makes governance auditable. An existing CLM stays in place; Certificate Intelligence reads its inventory as well.
Which sources are supported?+
The connectors for Microsoft ADCS, EJBCA, HashiCorp Vault PKI and smallstep step-ca are validated against real CA software in the Blackfort PKI test lab. Kubernetes with cert-manager is tested in the lab against a real cluster. There are also read-only connectors for Azure Key Vault, AWS Certificate Manager and Google Certificate Manager. In addition there is a built-in TLS scanner (read-only fetch per host:port, no cipher probing), Certificate Transparency logs for your domains and a file import for isolated segments.
Is the Microsoft CA changed, or does the software see private keys?+
No. No templates are changed, no certificates are issued or revoked and no settings are modified. The export runs as an openly readable PowerShell script on or next to the CA; in its default mode it writes a file, with no token on the CA and no outbound connection from the CA. Private keys are never read.
Does the DORA certificate register requirement apply to us?+
Art. 7(4) of Delegated Regulation (EU) 2024/1774 applies to financial entities within the scope of DORA that are not subject to the simplified ICT risk management framework. Small and medium-sized insurance intermediaries are exempt from DORA. The regulation requires an up-to-date register, not a particular product. Certificate Intelligence supports implementation and evidence; it does not replace a legal assessment and does not guarantee compliance.
Can Certificate Intelligence be integrated into our monitoring?+
Yes. The register provides two read-only endpoints, in Prometheus format and as JSON for PRTG, accessed with dedicated monitoring tokens that cannot submit or change anything. Tested in the lab against the real software: Prometheus and Grafana, PRTG, Nagios, Icinga, Checkmk, Zabbix, Elastic, Splunk, Datadog, Dynatrace, New Relic, SolarWinds Observability and ManageEngine OpManager. Each integration comes with a guide and a template.
Are tickets created in Jira or ServiceNow?+
In Jira, yes. A finding becomes a ticket with a due date based on your deadline and a link back to the register. On every run Certificate Intelligence keeps checking: once the finding is resolved, the ticket is commented and, if you wish, closed; the same finding never creates a second ticket. You decide which finding types raise tickets. Tested against Jira Cloud; Jira Data Center is supported with a personal access token. ServiceNow and generic webhooks will follow.
How do external auditors get access?+
The simplest way needs no account: you export the complete register with all fields as an Excel or CSV file. Without an active filter, the export contains all certificates of the current inventory; archived certificates are left out. Alternatively, auditors get an account with the viewer role, which can only read.
How is the product operated?+
In your environment as containers (Docker Compose); for isolated networks there is an offline package. The licence is a signed offline licence, no connection to Blackfort is required. If a licence expires, reading and the complete export remain available.
Does it support Kubernetes, AWS or Google Cloud?+
Yes. The Kubernetes connector reads TLS secrets and cert-manager certificates read-only and is tested in the lab against a real cluster with cert-manager; a separate mode works without read access to secrets. There are also read-only connectors for AWS Certificate Manager and Google Certificate Manager. The TLS scanner is platform-independent.
Kontakt aufnehmen
Do you know which certificates are in use across your organisation?
Try Certificate Intelligence free for 30 days in your environment, or have your inventory captured in an assessment.