A number of server's partners implement public keys without our knowledge. When these certs need to be renewed their server can't connect to the app in the MVS LPAR. Is there is a report to list the usage of the public key from a remote server to app server connection?
Unfortunately, there is nothing in Top Secret that can track the use of a certificate.
If these are CA certificates they may have been used to sign several other certificates so that may be why the servers are using them.
ACF2 nor RACF has this type of ability either.
If you are looking for expiration dates of certificates stored in Top Secret then you can run the Certificate Utility SAFCRRPT. This can report on certificates that will expire in a specified amount of days.