Skip to main content

Certificates

The Certificates screen is the central inventory of all SSL/TLS certificates managed by the CLM, regardless of their origin — issued by the CLM, discovered on cloud providers, or manually imported.


Listing

Go to Certificates in the sidebar menu to see all of the tenant's certificates.

Available columns

Use the Toggle columns button to show or hide columns:

ColumnDescription
TypeCertificate type, e.g. SSL/TLS
SourceCertificate origin: CLM Issued, Azure · Key Vault, AWS ACM, etc.
Domain / CNCommon Name or full path of the certificate on the provider
VersionCertificate version in the CLM (increments on every renewal)
IssuerIssuing certificate authority
ExpiryExpiration date
Days RemainingVisual bar + number of days remaining
StatusCurrent certificate status
ActionsMenu of available actions

Possible statuses

StatusDescription
ValidCertificate is valid and within its validity period
WarningApproaching expiration — within the alert threshold
CriticalVery close to expiring — urgent action needed
ExpiredCertificate has expired
  • Text search — filter by domain, CN, or issuer
  • Status Filter — select one or more statuses (Valid, Warning, Critical, Expired)
  • Clear All — removes all active filters

Available actions

Click ⋮ Actions on the certificate row to access:

ActionDescription
View detailsOpens the certificate's full details
DownloadExports the certificate in PEM, including the chain
Renew certificateStarts manual renewal (disabled if no CA is linked)
Verify status (OCSP/CRL)Checks revocation status with the CA
Order StatusTracks the order status in DigiCert (DigiCert only)
Reprocess CertificateReprocesses the certificate's data
Delete certificateRemoves the certificate from the CLM inventory

Certificate Details

Click View details to open the details panel. The panel has five tabs:

Details tab

Full certificate information:

  • Common Name, SANs, type, and version
  • Issuer and root CA
  • Issuance and expiration dates
  • SHA-256 and SHA-1 fingerprints
  • Key algorithm and size
  • OCSP status

Chain tab

Displays the full certificate chain — from the leaf certificate to the root certificate — with details for each link in the chain (subject, issuer, validity).

Auto-Renewal tab

Configure automatic renewal for this certificate. See the Renew a certificate guide for full details on this tab.

Store tab

View and manage the Stores linked to the certificate — the destinations where it will be automatically installed after renewal. See the Configure Stores guide for more information.

Tags tab

Manage the tags associated with the certificate. Select the category (Key) and the value (Value), then click Add. Each certificate supports up to 20 tags. See the Tags guide for more information.