Mondoo Docs

X.509 certificate resource

certificate MQL resource for querying Network infrastructure with cnquery and cnspec.

Network

X.509 certificate resource

Use MQL in cnspec shell or policy:

certificate
Min version: 5.15.0Defaults: serial subject.commonName subject.dn

Relationships

Mini Map
Network
4 resources · 5 relationshipsClick to select, expand fields to see properties.

Fields (25)

FieldTypeDescription
authorityKeyID
stringAuthority key identifier
crlDistributionPoints
[]stringCRL distribution points
expiresIn
timeExpiration duration
extendedKeyUsage
[]stringExtended key usage
extensions
[]pkix.extensionExtensions
fingerprints
map[string]stringCertificate fingerprints
isCA
intWhether the certificate is from a certificate authority
isRevoked
intWhether this certificate has been revoked
issuer
pkix.nameIssuer
issuingCertificateUrl
[]stringIssuing certificate URL
isVerified
intWhether the certificate is valid (based on its chain)
keyUsage
[]stringKey usage
notAfter
timeValidity period not after
notBefore
timeValidity period validity period
ocspServer
[]stringOCSP
pemrequired
stringPEM content
policyIdentifier
[]stringPolicy identifier
revokedAt
timeThe time at which this certificate was revoked
sanExtension
pkix.sanExtensionSAN extension value params
serial
stringSerial number
signature
stringSignature
signingAlgorithm
stringSignature algorithm ID
subject
pkix.nameSubject
subjectKeyID
stringSubject unique identifier
version
intVersion number