Certificates
The Certificates screen is the central inventory of all SSL/TLS certificates managed by the CLM, regardless of their origin — issued by the CLM, discovered on cloud providers, or manually imported.
Listing
Go to Certificates in the sidebar menu to see all of the tenant's certificates.
Available columns
Use the Toggle columns button to show or hide columns:
| Column | Description |
|---|---|
| Type | Certificate type, e.g. SSL/TLS |
| Source | Certificate origin: CLM Issued, Azure · Key Vault, AWS ACM, etc. |
| Domain / CN | Common Name or full path of the certificate on the provider |
| Version | Certificate version in the CLM (increments on every renewal) |
| Issuer | Issuing certificate authority |
| Expiry | Expiration date |
| Days Remaining | Visual bar + number of days remaining |
| Status | Current certificate status |
| Actions | Menu of available actions |
Possible statuses
| Status | Description |
|---|---|
| Valid | Certificate is valid and within its validity period |
| Warning | Approaching expiration — within the alert threshold |
| Critical | Very close to expiring — urgent action needed |
| Expired | Certificate has expired |
Filters and search
- Text search — filter by domain, CN, or issuer
- Status Filter — select one or more statuses (Valid, Warning, Critical, Expired)
- Clear All — removes all active filters
Available actions
Click ⋮ Actions on the certificate row to access:
| Action | Description |
|---|---|
| View details | Opens the certificate's full details |
| Download | Exports the certificate in PEM, including the chain |
| Renew certificate | Starts manual renewal (disabled if no CA is linked) |
| Verify status (OCSP/CRL) | Checks revocation status with the CA |
| Order Status | Tracks the order status in DigiCert (DigiCert only) |
| Reprocess Certificate | Reprocesses the certificate's data |
| Delete certificate | Removes the certificate from the CLM inventory |
Certificate Details
Click View details to open the details panel. The panel has five tabs:
Details tab
Full certificate information:
- Common Name, SANs, type, and version
- Issuer and root CA
- Issuance and expiration dates
- SHA-256 and SHA-1 fingerprints
- Key algorithm and size
- OCSP status
Chain tab
Displays the full certificate chain — from the leaf certificate to the root certificate — with details for each link in the chain (subject, issuer, validity).
Auto-Renewal tab
Configure automatic renewal for this certificate. See the Renew a certificate guide for full details on this tab.
Store tab
View and manage the Stores linked to the certificate — the destinations where it will be automatically installed after renewal. See the Configure Stores guide for more information.
Tags tab
Manage the tags associated with the certificate. Select the category (Key) and the value (Value), then click Add. Each certificate supports up to 20 tags. See the Tags guide for more information.