CyberArk Certificate Manager (Venafi) Integration with DefectDojo
CyberArk Certificate Manager (Venafi) Integration with DefectDojo
CyberArk Certificate Manager is the certificate and machine identity management product formerly sold as Venafi. It comes in two editions: Certificate Manager SaaS (formerly TLS Protect Cloud) and Certificate Manager Self-Hosted (formerly Trust Protection Platform). Both keep an inventory of the TLS certificates an organization issues and discovers, including subject names, issuer, key algorithm and size, signature algorithm, and expiry. DefectDojo reads that inventory as a JSON export or, in DefectDojo Pro, through an API connector.
CyberArk Certificate Manager (Venafi) Integration with DefectDojo
Certificate problems rarely look like vulnerabilities until one takes a service down. We already had CyberArk Certificate Manager keeping the inventory, but expiries and weak keys lived in a separate console that the application security team did not watch. Bringing the inventory into DefectDojo means an expiring certificate shows up next to the same Asset's scanner findings, with an owner and an SLA, and a certificate that is renewed drops off the list on the next import instead of lingering in a spreadsheet.
Why CyberArk Certificate Manager (Venafi) Matters
A certificate inventory is only useful if someone acts on what it shows. CyberArk Certificate Manager is where many organizations already track issuance, so it is the natural source for certificate risk.
- It covers certificates across teams and environments, including ones discovered rather than requested through a central process.
- Expired certificates break clients, and certificates close to expiry are the outages you can still prevent.
- Short RSA keys and SHA-1 or MD5 signatures are cryptographic debt that auditors and browsers flag.
- Self-signed certificates in places that should chain to a trusted issuer point to shortcuts that need a second look.
Advantages of This Integration
The export itself carries no verdicts. DefectDojo computes posture from each certificate's attributes, which gives you a few concrete gains:
- Findings only where something is wrong. A healthy certificate produces no finding at all. One certificate that breaks three rules produces three findings, each with its own remediation.
- Rules that skip rather than guess. If a certificate has no recorded key size, it is not reported as weak. If it has no expiry, it is not reported either way. That keeps false alarms out of the queue.
- Elliptic-curve keys are not punished. The 2048-bit floor is applied only to RSA keys, so EC certificates are not reported as weak because their keys are shorter by design.
- File and connector findings line up. The parser mirrors the DefectDojo Pro connector field for field and uses the same scan type, so a team that starts with file exports and later enables the connector gets deduplicated findings rather than two copies.
- Platform workflow applies to certificates. SLAs by severity, assignment, risk acceptance for a known internal self-signed certificate, Jira tickets, and reports all work the same way they do for scanner findings.
How This Integration Works
DefectDojo supports this tool with the CyberArk Certificate Manager Scan scan type. You can bring data in by file (UI Import, API Import, or Universal Importer in DefectDojo Pro) or through the DefectDojo Pro API connector.
1. Get a certificate inventory export. The parser reads JSON from either edition. A SaaS export is an object with a certificates list (fields such as fingerprint, subjectCN, issuerCN, keyStrength, encryptionType, signatureHashAlgorithm, validityEnd, selfSigned). A self-hosted export uses a Certificates list with capitalized field names (Thumbprint, CN, Subject, Issuer, KeySize, KeyAlgorithm, SignatureAlgorithm, ValidTo). A bare array of certificates also works. The file route exists for environments that cannot grant API credentials, such as air-gapped networks or a pending security review.
2. Import the file. In the UI, open an Engagement, choose Import Scan Results, select CyberArk Certificate Manager Scan, and upload the JSON. With the API, available in Community Edition and DefectDojo Pro:
curl "https://YOUR_INSTANCE/api/v2/import-scan/"
-H "Authorization: Token $DD_API_TOKEN"
-F "scan_type=CyberArk Certificate Manager Scan"
-F "file=@certificates.json"
-F "product_name=pki-inventory"
-F "engagement_name=Certificate Posture"
-F "auto_create_context=true"
With Universal Importer in DefectDojo Pro:
universal-importer import
--defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/"
--scan-type "CyberArk Certificate Manager Scan"
--report-path "./certificates.json"
--product-name "pki-inventory"
--engagement-name "Certificate Posture"
--auto-create-context
3. Or connect over the API (DefectDojo Pro). The CyberArk Certificate Manager connector is configured in the DefectDojo Pro UI. Enter the Certificate Manager URL in Location and set Edition to cloud or tpp. The cloud edition needs a SaaS API key. The self-hosted edition needs an OAuth client ID registered on the server plus a service account username and password. Only the credential fields for the chosen edition are filled in. You can set a Minimum Severity. The connector creates a Record for each certificate's owning application (SaaS) or policy folder (self-hosted) and syncs on a schedule.
Expiry is judged at import time. The same file imported a week later can report more expiries, because certificates that have since lapsed really have lapsed. The connector judges expiry against sync time in the same way.
Data Granularity: What Gets Imported
| DefectDojo Field | Source in Certificate Manager Export | Notes |
|---|---|---|
| Title | Posture rule plus common name | For example "Certificate has expired" with the common name in brackets |
| Severity | Fixed per rule | Expired is Critical; expiring within 30 days, weak RSA key, weak hash are High; self-signed is Medium |
| Description | Certificate attributes | Rule detail, common name, sorted SANs, issuer, key, signature algorithm, expiry, fingerprint |
| Mitigation | Per rule | Renew, rekey to 2048 bits or more, reissue with SHA-256 or stronger, or replace with a CA-issued certificate |
| Component Name | Common name | Falls back to fingerprint, so the same problem on two certificates stays two findings |
| Unique ID from Tool | Fingerprint and rule | venafi-<fingerprint>-<rule>, preferring fingerprint or thumbprint over record ID |
| Vuln ID from Tool | Rule name | expired, expiring-soon, weak-key, weak-signature, self-signed |
| Tags | Rule and key algorithm | Useful for filtering by rule or by RSA versus EC |
| Self-signed (self-hosted) | Subject and Issuer | Inferred when subject equals issuer, since that edition has no flag |
| Finding type | Static | Posture is read from attributes; nothing is probed |
| Deduplication | Unique ID or hashcode | Unique ID from tool, falling back to title, severity, component_name |
Signature hashes are matched with hyphens removed, so SHA-1 and SHA1 are both caught. Timestamps are accepted as RFC 3339, with milliseconds, without a time zone (read as UTC), or as a bare date.
Use Cases
Preventing expiry outages: A platform team imports the inventory weekly. Anything expiring within 30 days arrives as High with a renewal mitigation, so the owning team gets a ticket while there is still time to act.
Cleaning up cryptographic debt: Weak RSA keys and SHA-1 signatures surface as High findings tagged by rule. A security lead can filter on weak-signature and track the reissue campaign to zero.
Air-gapped or restricted networks: Where DefectDojo cannot reach Certificate Manager, an administrator exports the inventory and uploads it. The findings match what the connector would produce, so moving to the connector later does not reset history.
Audit evidence: Certificate findings carry dates, SLA status, and closure history, which answers questions about how long expired or weak certificates stayed in service.
Operational Tips
- Reimport into the same Test on a fixed schedule. Because expiry is judged at import time, a regular cadence keeps the expiring-soon window accurate.
- If you combine file imports and the connector, send both to the same Asset. They share a scan type and identity so they can deduplicate, but DefectDojo only compares findings within the scope it deduplicates over.
- Risk-accept intentional self-signed certificates (internal test services, for example) with an expiration date rather than closing them as false positives.
- Configure your High SLA with the 30-day expiry window in mind. A High SLA longer than 30 days lets a certificate expire before the SLA is breached.
- A certificate with missing attributes produces fewer findings, not more. If an export looks quiet, check that it includes key size and expiry fields.
- Use the connector's Minimum Severity, or
minimum_severityon file import, if you only want to track Critical and High certificate issues.