Possible to discover and manage third-party certificates with Puppet?

I'm not referring to the CA and certificates Puppet itself uses. Has anyone used Puppet to discover or otherwise report on the state of certificates across their network (load balancers, web servers, etc)? Like maintaining info on them as facts and notifying when they're 60 days from expiring?

“Not my department.” This sounds like your're trying to use the wrong tool for a given scenario. I mean, it ain't impossible, but I tell you, you'd be rather … un-satisfied. Better head directly for appropriate solutions.

That's what I figured as well, but had to be sure.

