Here they are a pair of powershell scripts to keep track of certificate expiration and CRL expiration of your enterprise PKI. it uses certutil command to extract the information and saves the result in a SQLite database to manage the email notifications.
https://systemswin.blogspot.com/2020/10/powershell-wpf-pki-notify-v2.html