
PKI Spotlight
Overview
PKI Spotlight is a monitoring and posture management platform for enterprise Public Key Infrastructure, developed by PKI Solutions. It brings certificate authorities, revocation services, certificate inventory and hardware security modules into a single view, and alerts on the conditions that lead to outages and security findings.
Rather than a point-in-time audit, it maintains that picture continuously. For organisations running PKI across several teams, sites or business units, it answers the question most cannot answer confidently today: what do we actually have, and is any of it about to fail?
The Challenge
PKI tends to grow quietly. Certificate authorities are stood up for a specific project, ownership changes hands, documentation falls behind, and the estate ends up larger and less understood than the records suggest.
The consequences are familiar:
- Expiries discovered only when a service stops working
- Revocation infrastructure failing quietly until authentication breaks
- Misconfigured templates and weak settings sitting unnoticed for years
- Troubleshooting that depends on one or two people who understand the environment
- Migration and post-quantum planning stalled by an inventory nobody trusts
Most monitoring tools were not built for this. They watch servers and services, not the trust relationships between them.
What It Does
Continuous visibility
Centralised monitoring across certificate authorities, revocation infrastructure, certificate templates, validation locations and HSMs, with a topology view of how those components depend on one another. Supports Microsoft ADCS and EJBCA environments.
Inventory and expiry tracking
A maintained inventory of PKI certificates and certificate revocation lists, with validity tracking, renewal alerts and configurable expiry thresholds. Leaf certificate reporting extends this to certificates issued by your internal PKI.
Risk and misconfiguration detection
Detection of known ADCS risk conditions, insecure configuration changes, expired CAs and configuration drift, assessed continuously rather than at audit time.
HSM monitoring
Status and configuration monitoring for Luna and nShield HSMs, on-premises and cloud, covering the availability of the cryptographic services your PKI depends on.
Public certificate visibility
Integration with DigiCert CertCentral brings publicly issued certificates, domain validation status and organisation records into the same view as your internal PKI.
Alerting and integration
Native Splunk integration, a generic syslog API for other SIEM platforms, email alerts and digest reporting, plus SAML single sign-on through Entra ID or PingID.
Remediation guidance
Findings are correlated across components, prioritised by operational impact, and paired with guidance on how to resolve them. A PKI maturity self-assessment measures your estate against the PKI Consortium model to help prioritise improvement work.
The full feature set is documented on the PKI Solutions website.
How Unsung Helps
We provide the professional services around the platform.
- Implementation. Deployment and configuration, integration with your CA estate, HSMs and SIEM, and sensible alert thresholds so the platform is useful rather than noisy.
- Testing. Validation that monitoring covers what it should, and that alerts reach the right people through the right channels.
- Value extraction. Help interpreting findings, prioritising them against your risk appetite, and turning them into remediation work your teams can act on.
We are vendor-neutral. If PKI Spotlight is not the right fit for your requirements, we will say so.
