Skip to main content

CSR — Certificate Requests

The CSR screen centralizes all certificate issuance requests for the tenant, letting you track the status of each request and create new ones.


Request Listing

Go to CSR in the sidebar menu to see the history of all requests.

ColumnDescription
Certificate NameName of the request
TypeType: ssl_tls (new issuance), renew (renewal), reissue (reissue)
Domain / CNMain domain of the certificate
Requested ByUser who created the request
Requested OnDate and time of the request
StatusCurrent status of the request
ActionsActions available depending on the status

Possible statuses

StatusDescription
issuedCertificate successfully issued
rejectedRequest rejected by the CA or a validation error
Pending ValidationAwaiting domain validation (DCV)

Actions by status

ActionWhen it appears
View CertificateStatus issued — opens the issued certificate
View OrderDigiCert requests — opens the order status
👁 (icon)Views the request's details

New Request

Click + New Request to open the 3-step wizard.

Step 1 — Identification

FieldDescription
Certificate NameName to identify the certificate in the CLM
Certificate TypeSSL/TLS (filled automatically)
Domain / Common NameMain domain, e.g. app.yourcompany.com
Alternative Names / SANsAdditional domains separated by commas (optional)
Key SizeKey size — 2048, 3072, or 4096 bits

Step 2 — CA and Configuration

Select the Certificate Authority and configure its specific parameters:

Free, automated issuance via the ACME v2 protocol.

FieldDescription
Let's Encrypt AccountLet's Encrypt account registered in Integrations
Validation MethodDomain validation method (see options below)
AWS IntegrationRoute 53 integration — only for DNS Auto-Validation
Hosted ZoneDNS zone of the domain in Route 53
NotesOptional notes

Available validation methods:

MethodHow it works
HTTP ChallengeCreates a file at /.well-known/acme-challenge/ on the web server
DNS Challenge (Manual)You add a TXT record to the DNS zone manually
DNS Auto-Validation — ManualYou have a Route 53 integration, but create the record manually
DNS Auto-Validation — AutomaticThe CLM creates and removes the DNS record automatically in Route 53
Faster with Route 53

If the domain is on Route 53, use DNS Auto-Validation — Automatic. The CLM handles the entire process with no manual action.


Step 3 — Review

Check all the settings from the previous steps. Use Edit to go back and correct any section. Click Submit request to send the request to the CA.


Track the validation

For Let's Encrypt and DigiCert, after submitting you may need to complete domain validation. The screen shows the DNS record status and lets you Force validation to trigger an immediate check.

See the detailed guides per CA: