Certificates by Key Strength

The Certificates by Key Strength report includes a bar graph showing the number of active certificates by key strength (e.g., sha-1, sha-256) for the selected CAClosed A certificate authority (CA) is an entity that issues digital certificates. Within Keyfactor Command, a CA may be a Microsoft CA or a Keyfactor gateway to a cloud-based or remote CA.(s), a bar graph showing the number of active certificates by key sizeClosed The key size or key length is the number of bits in a key used by a cryptographic algorithm. for the selected CA(s), and a pie chart for each selected CA showing the active certificates by key size (e.g., 1024 bit, 2048 bit).

Tip:  Where to find this in the Management Portal:
Reports → Report Manager or Reports → Certificates by Key Strength (if it has been added to the Navigator)
Note:  Post-quantum certificatesClosed A certificate with a single, primary post-quantum key. are not currently supported in this report but will be supported in a future release.
Tip:  Clicking on a bar on the graph, or a section of a pie chart or line graph, will open a new window as a drill down to the certificate search grid filtered for the exact criteria of that aspect of the graph. You can return to the original report by navigating to the original report window.

Figure 88: Certificates by Key Strength

The export options for the Certificates by Key Strength report are Excel and PDF.

This report takes as an input parameterClosed A parameter or argument is a value that is passed into a function in an application. the CA(s) on which to report and includes the option to report on certificates that have no associated CA. Typically, these would be certificates found via SSLClosed TLS (Transport Layer Security) and its predecessor SSL (Secure Sockets Layer) are protocols for establishing authenticated and encrypted links between networked computers. scanning or inventory on certificate stores.

Note:  By default, this report is configured not to appear on the top menu under Reports and can be found only in Report Manager. You can change this by modifying the Show in Navigator setting (see Report Manager Operations).
Note:  Other than the option of certificates with no associated CA, only CAs currently or previously configured for synchronization are available for reporting.