Discovery
The Discovery screen lets you find SSL/TLS certificates across public domains and cloud environments. It's split into two tabs: Domain Scan for one-off checks and Scans for automated routines.
Summary cards
At the top of the page you get a quick overview of the current state:
| Card | Description |
|---|---|
| Total Certificates | Total certificates discovered and imported into the CLM |
| Expiring Soon | Certificates expiring in the next 30 days |
| Certificate Authorities | Number of distinct CAs identified across the certificates |
Domain Scan tab
Use Domain Scan to find certificates for a domain or IP immediately, without configuring any integration.
How to use it
- In the search field, enter the domain or IP address (e.g.
pkiless.comor192.168.1.1) - Click Scan
- The CLM scans the domain and lists all certificates found under Discovery Results
- When it finishes, the message "Discovery completed — Found X certificates" appears
Results
The results table shows:
| Column | Description |
|---|---|
| Certificate Name | Name/CN of the certificate found |
| Domain | Domain where the certificate was found |
| Issuer | Issuing certificate authority |
| Expires | Expiration date |
| Status | Certificate status (Valid, Warning, Critical, Expired) |
| Actions | Import individually or view details |
Importing certificates
- Import individually — click + Import on the certificate row
- Import all — click Import All to import all results at once
- Multiple selection — use the checkboxes to select specific certificates and import them in bulk
The CLM uses SHA-256 fingerprints to avoid duplicates — certificates already in the inventory won't be imported again.
Where to start
Domain Scan is the recommended first step for new users. Scan your main domain to discover all active certificates before setting up integrations.
Scans tab
For continuous, automated discovery, use the Scans tab to create scheduled Discovery Jobs. See the Configure Discovery guide for detailed per-provider instructions.