Keyfactor Command Service Automated Tasks

The Keyfactor Command Service runs several automated tasks for maintenance, alerting, reporting, and similar purposes. The below table provides details of these tasks. The schedules for some tasks are customizable.

Automated Tasks

Table 72: Keyfactor Command Jobs Services

Service

Description

Run Time

AgentNotificationAlert
Periodically check for orchestrators that have not checked in between job runs and send email notifications based on the Agents > General > Notification Alert Interval (minutes) and Agents > General > Notification Alert Email Recipients application settings (see Application Settings: Agents Tab). This is configurable in application settings (see Application Settings: Agents Tab).
ActionedCertificates
Periodically calculate certificates that should be considered actioned certificates. This job runs daily at 2:00 UTC.
BulkAuditProcessing
Periodically add audit log entries for large jobs. Most audit log entries are added immediately at the time the activity generating the audit log takes place. However, some large jobs that might generate heavy server load (for example, bulk revocation) save the audit log entries in a temporary location to reduce server load and then they are added to the audit log by this periodic job. This job runs every 10 minutes.
CAHealth
Periodically send email alerts when a CA is not responding. The schedule for this is user configurable (see Alert Recipients Tab).
CASync
Periodically synchronize certificates from certificate authorities. The schedules for this are user configurable (see Alert Recipients Tab).
CATemplateCache

Periodically retrieve certificate templates from CAs configured for enrollment (with the setting Use for Enrollment is turned on) and store the data in a cache in the database to reduce queries to the CA during enrollment requests. The cache lifetime is configurable using the Enrollment > General > CA Template Cache Expiration (minutes) application setting (see Application Settings: Enrollment Tab).

Important:  Turning off this job will cause enrollment to be unavailable once the cache expires.
This job runs every 5 minutes.
CAThreshold
Periodically send email alerts when a CA is issuing certificates or experiencing issuance failures outside of the established norms. The schedule for this is user configurable (seeAlert Recipients Tab).
CertificateCleanup

Periodically remove expired certificates from the Keyfactor Command database.

Some settings for this job are configurable in the Console > Certificate Cleanup application settings (see Application Settings: Console Tab). For more information, see Certificate Cleanup.

This job runs daily at 1:00 UTC.

CertificateStoreWorkflows
Periodically update the Keyfactor Command database cache of certificates entering or leaving a certificate store for use by the Certificate Entered Store and Certificate Left Store workflow types. This job runs every 10 minutes (see Workflow Definitions).
CertificateQueryAlert
Periodically process workflows for any certificates found in the database cache (see QueryItems) of certificates entering or leaving a certificate collection for use by the Certificate Entered Collection and Certificate Left Collection workflow types. This job runs every 10 minutes.
CRL
Periodically send email alerts for certificate revocation lists (CRLs) that are approaching expiration using the legacy alerting system. The schedule for this is user configurable (see Adding or Modifying a Revocation Monitoring Location).
CollectionQueryAlerts
Periodically update the temporary tables that store information on which certificates are in which certificate collections. These temporary tables (caches) are used to support faster processing of some systems. This job runs every 10 minutes.
EndpointHistory
Periodically remove any SSL endpoint history in the Keyfactor Command database that is eligible for deletion, based on the Agents > SSL > Retain SSL Endpoint History (days) application setting (see Application Settings: Agents Tab). This job runs daily at 1:00 UTC.
ExpirationAlerts

Periodically send email alerts for certificates approaching expiration using the legacy alerting system.

The schedules for these are user configurable. See Expiration Alerts.
ExpirationWorkflows
Periodically execute any Expiration workflows. This job runs every 10 minutes.
IssuedAlerts
Periodically send email alerts (typically to certificate requesters) for certificate requests made using a certificate template that requires manager approval that have been approved using the legacy alerting system. The schedule for this is user configurable (see Configuring an Issued Request Alert Schedule).
KeyRotationWorkflows
Periodically execute any Key Rotation workflows. This job runs every 10 minutes.
MetadataGeneration
Periodically generate and assign metadata to certificates when they are imported into Keyfactor Command using a custom metadata extension. This job runs every 15 minutes.
PendingAlerts

Periodically send email alerts (typically to certificate approvers) for certificate requests made using a certificate template that requires manager approval using the legacy alerting system.

The schedules for these are user configurable. See Configuring a Pending Request Alert Schedule.
PrivateKeyCleanup

Periodically remove any stored private keys in the Keyfactor Command database that have expired and are eligible for deletion.

For more information about stored private keys, see Certificate Details - Status Tab.

This job runs daily at 1:00 UTC.

PurgeAuditHistory

Periodically remove expired audit log history from the Keyfactor Command database. Audit log records are eligible for deletion when they are older than the retention period defined by the Auditing > General > Audit Entry Retention Period application setting. Records are deleted in batches, with the batch size defined by the Auditing > General > Purge Audit Log Batch Size application setting. Only audit logs that belong to unprotected categories are eligible for deletion. For more information, see Application Settings: Auditing Tab.

This job runs on the first day of the month at 2:00 UTC.

QueryItems
Periodically update the Keyfactor Command database cache of certificates entering or leaving a certificate collection for use by the Certificate Entered Collection and Certificate Left Collection workflow types. This job runs every 10 minutes (see Workflow Definitions).
Reporting
Deliver scheduled legacy reports via email or save to a file system. The schedules for these are user configurable.
ReportingCleanup
Periodically remove records from temporary files generated while running reports. This job runs daily at 00:00 UTC.
RevocationMonitoringWorkflows
Periodically execute any Revocation Monitoring workflows. This job runs every 10 minutes.
ScheduleSSLJobs

Periodically identify and schedule SSL discovery and monitoring jobs.

This job runs every 5 minutes.
SSHKeyRotationAlerts
Periodically send email notifications to SSH key users and/or administrators when a key is nearing the end of the key lifetime using the legacy alerting system. The schedule for this is user configurable (see Configuring a Key Rotation Alert Schedule).
StatsUpdate
Periodically run the Microsoft SQL update statistics function in the Keyfactor Command database.

This job runs monthly on the first day of the month at 1:00 UTC.

SuspendedWorkflows
Periodically attempt to continue all suspended workflows that may be eligible to continue but have not done so due to locking conflicts. A locking conflict may occur if two users attempt to provide input to a workflow instance (for example, approve a request) at exactly the same time. This job runs daily at 00:00 UTC.
SyncTemplates
Periodically synchronize certificate templates from the source (for example, Active Directory) to pick up new templates. This job runs every hour.
UndecryptableSecretsSearch
Periodically scan the database for any secrets that cannot be decrypted. If any are found, an error is logged to the orchestrator logs that indicate how many secrets were undecryptable. A Management Portal alert (see System Alerts) will also be triggered flagging the issue.

This job runs daily at 00:00 UTC.

WorkflowCleanup
Periodically remove any completed workflow instances (both successful and failed) in the Keyfactor Command database that have aged X number of days past the completion date (last modified date), where X is defined by the Workflow > General > Workflow Instance Cleanup Days application setting (see Application Settings: Console Tab). This job runs daily at 00:00 UTC.
CertStoreMirroring
Periodically scan the certificate store mirroring queue for certificate stores that require differencing. For each certificate store in the batch, Keyfactor Command determines the associated trust bundle, compares the certificates in the trust bundle with the certificates currently in the store, and creates jobs to add missing certificates or remove certificates that are not in the trust bundle. The number of certificate stores processed in each batch is defined by the Agents > General > Trust Bundle Mirroring Queue Batch Size application setting. This job runs every 10 minutes.
SyncTrustedRoots

Periodically synchronize trusted root certificates from the host trust store into the Publicly Trusted Roots trust bundle in Keyfactor Command. During synchronization, Keyfactor Command compares the thumbprints of certificates in the host trust store with certificates in the Keyfactor Command database. New trusted root certificates are imported into the Keyfactor Command database and added to the configured trust bundle. Certificates that are no longer present in the host trust store are removed from the trust bundle but are not deleted from the Keyfactor Command database.

The name of the trust bundle is configurable using the Console > General > Publicly Trusted Roots Bundle Name application setting. See Application Settings: Console Tab.

If the trust bundle named by the Publicly Trusted Roots Bundle Name application setting does not exist at the time the job runs, it will be created.

This job runs daily at 00:00 UTC.
OrchestratorPoolClean
Periodically clean up transient orchestrators that are no longer actively checking in to their orchestrator pools. For each pool with Remove Transient Orchestrators turned on, Keyfactor Command removes orchestrators from the pool when they have not checked in within the pool’s configured Last Seen Threshold (minutes). This job runs every 5 minutes.
BackfillBasicConstraints
Run once when the Keyfactor Command service starts to populate basic constraints data for existing certificates in the Keyfactor Command database. The job parses certificates in batches and sets the Is CA Certificate and Path Length Constraint values based on each certificate’s basic constraints extension. If a certificate cannot be parsed, a warning is logged and the values remain empty. If the job has already run, it exits without making changes.  
OrchestratorPoolJobTimeoutHandler
Periodically check pooled orchestrator jobs to determine whether any assigned or in-progress jobs have exceeded the job timeout configured for the orchestrator pool. When a job exceeds the pool’s Job Timeout (minutes) value, Keyfactor Command marks the current job instance as failed and places the job back into the pool. The job is made available again after the pool’s Retry Pause Interval (minutes) has elapsed. This timeout handling does not increase the job’s retry count and is not affected by the global retry limit. The check interval is defined by the Agents > General > Job Timeout Check Interval (minutes) application setting. This job runs every 15 minutes.

Certificate Cleanup

The Certificate Cleanup Task runs daily at 1:00 UTC and removes expired certificates from the database based on configured cleanup settings. Cleanup eligibility can be defined at the system-wide, templateClosed A certificate template defines the policies and rules that a CA uses when a request for a certificate is received., or CAClosed A certificate authority (CA) is an entity that issues digital certificates. Within Keyfactor Command, a CA may be a Microsoft CA or a Keyfactor gateway to a cloud-based or remote CA. level.

When a certificate is removed by the cleanup task, it is excluded from subsequent standard CA synchronization unless cleanup is later turned off for that scope. CA synchronization tasks reference the cleanup settings to determine whether a certificate is eligible for removal and whether it should be excluded from import.

First Execution

When certificate cleanup is activated for the first time, the task evaluates all existing certificates that meet the configured cleanup criteria. As a result, the initial execution may take longer than subsequent daily runs.

To limit the scope of the first execution, you can configure cleanup at the template or CA level before applying it globally. This approach allows you to stage cleanup in controlled increments.

Processing Behavior

During execution, the cleanup task processes certificates according to scope. System-wide cleanup settings are evaluated first, followed by template-level settings, and then CA-level settings.

Certificates are deleted in batches of up to 1,000 records per cycle. Batch processing helps manage processing volume during execution and supports predictable task completion.

Certificates stored in the database are not removed by the cleanup task if they are associated with a certificate store or were imported through an SSLClosed TLS (Transport Layer Security) and its predecessor SSL (Secure Sockets Layer) are protocols for establishing authenticated and encrypted links between networked computers. scan.

Logging and Auditing

The cleanup task writes informational log entries when execution begins and when processing completes. In environments where many certificates are eligible for removal, additional log entries may appear as batches are processed.

For example (including a debug level message):

Copy
2026-02-26 10:00:01.1941 2ADABE80-9B8F-4F43-B48C-16536FA22F11 CSS.CMS.Service.Jobs.Maintenance.Tasks.CertificateCleanup [Info] - Beginning 'CertificateCleanup' execution.

2026-02-26 10:00:01.2124 2ADABE80-9B8F-4F43-B48C-16536FA22F11 CSS.CMS.Service.Jobs.Maintenance.Tasks.CertificateCleanup [Debug] - Context:
JobExecutionContext: trigger: 'DEFAULT.CertificateCleanup' job: 'DEFAULT.CertificateCleanup' fireTimeUtc: 'Thu, 26 Feb 2026 01:00:00 GMT' scheduledFireTimeUtc: 'Thu, 26 Feb 2026 01:00:00 GMT' previousFireTimeUtc: 'Wed, 25 Feb 2026 01:00:00 GMT' nextFireTimeUtc: 'Fri, 27 Feb 2026 01:00:00 GMT' recovering: False refireCount: 0

2026-02-26 10:00:01.2124 2ADABE80-9B8F-4F43-B48C-16536FA22F11 CSS.CMS.Service.Jobs.Maintenance.Tasks.CertificateCleanup [Info] - Beginning certificate cleanup at 2/26/2026 10:00:01 AM.

All log messages generated during a single cleanup execution share the same correlation ID. This identifier can be used to trace all log messages associated with a specific execution of the task.

Additional execution detail is available when Debug or Trace logging levels are turned on for the service. At these levels, log entries may include batch discovery, deletion counts, SQL interactions, and reasons certificates are skipped.

For example:

Copy
2026-02-26 10:00:01.3354 2ADABE80-9B8F-4F43-B48C-16536FA22F11 CSS.CMS.Service.Jobs.Maintenance.Tasks.CertificateCleanup [Debug] - Beginning cleanup of certificates associated with templates.

2026-02-26 10:00:01.3354 2ADABE80-9B8F-4F43-B48C-16536FA22F11 CSS.CMS.Service.Jobs.Maintenance.Tasks.CertificateCleanup [Trace] - Cleaning up certificates associated with template 58 that expired more than 12 Months ago.

2026-02-26 10:00:01.6950 2ADABE80-9B8F-4F43-B48C-16536FA22F11 CSS.CMS.Service.Jobs.Maintenance.Tasks.CertificateCleanup [Trace] - Found batch of 726 certificates to delete.

2026-02-26 10:00:02.8047 2ADABE80-9B8F-4F43-B48C-16536FA22F11 Keyfactor.Command.Sql.DataStores.CertificateDataStore [Debug] - deleted 726 certificates

2026-02-26 10:00:35.8333 2ADABE80-9B8F-4F43-B48C-16536FA22F11 CSS.CMS.Service.Jobs.Maintenance.Tasks.CertificateCleanup [Debug] - Skipping cleanup of certificate with ID 2193089 because it is associated with a certificate store or SSL network.

Debug and Trace levels can generate a higher volume of log output and are typically used for troubleshooting.

Each certificate deletion performed by the cleanup task generates a corresponding audit log entry.