Audit every SSL/TLS certificate, SSH key, and secret operation

Every certificate, key, and secret in your environment goes through dozens of operations a week, including renewals, rotations, signings, deployments, and revocations. When these are managed across different tools, piecing together a complete audit record becomes a manual, error-prone task.

Key Manager Plus captures every operation as a detailed audit trail, covering SSL/TLS certificates, SSH keys, PGP keys, and secrets. Each entry records the user, timestamp, source IP, and description, giving your teams complete visibility into how these machine identities are being accessed and managed, and by whom.

Try Key Manager PlusSee how it works

Key Manager Plus can help with:

  • Unified audits of all operations
  • Session recording for remote SSH access
  • Role-based audit visibility
  • Exportable on-demand or on schedule

Capture every operation

Key Manager Plus captures every SSL/TLS certificate, SSH key, PGP key, and secret operation performed in the product, including creations, imports, discoveries, deployments, renewals, rotations, revocations, and exports. Scheduled tasks like automatic certificate renewals through public CAs, private CA, and Microsoft CA, SSH key rotations, and recurring discovery scans are tracked alongside on-demand operations.

Key Manager Plus audit trail capturing SSL/TLS certificate, SSH key, PGP key, and secret operation
Recorded privileged SSH session listed in the Key Manager Plus audit interfaceReplaying a recorded SSH session in Key Manager Plus for forensic analysis

Record and replay privileged SSH sessions

When users launch remote SSH sessions from Key Manager Plus, the session is recorded and stored for playback. Administrators can replay these recorded sessions directly from the audit interface for forensic analysis and compliance reviews. Each session is tied to the user, target server, and SSH key used.

Implement role-based audit visibility

Administrators have visibility across all users and operations, while SSL power users see only records tied to the certificates and templates in their scope. Operators only see records for the resources shared with them. This ensures teams access the audit data relevant to their responsibilities without exposing broader operational detail.

Role-based audit visibility controls in Key Manager Plus scoping records by user role
Exporting audit trails as PDF or CSV in Key Manager PlusScheduling periodic daily, weekly, or monthly audit report delivery in Key Manager Plus

Export audits on demand or on schedule

Audit trails can be exported as a PDF or CSV, or emailed directly to recipients. Periodic delivery can be scheduled on a daily, weekly, or monthly basis to keep auditors, stakeholders, and security teams on track without manual effort.