| Weak algorithm |
Certificate uses cryptographic algorithms that are deprecated or considered weak by current security standards |
MD5, SHA-1, RSA < 2048 bits, DSA < 2048 bits, DES, 3DES, RC4 |
| Trusted CA risk |
Certificate is not issued by a trusted certificate authority or has CA-related trust issues |
Self-signed certificate, CA not in trusted root store, or CA not in organizational trust policy |
| No owner |
Certificate has no identified owner or responsible party |
Owner field is empty or not assigned |
| No environment |
Certificate lacks environment classification |
Environment field is empty or not specified |
| No renewal process |
Certificate has no defined renewal process or workflow |
No renewal process documented or automated workflow configured |