Skip to main content

Discovery

The Discovery screen lets you find SSL/TLS certificates across public domains and cloud environments. It's split into two tabs: Domain Scan for one-off checks and Scans for automated routines.


Summary cards

At the top of the page you get a quick overview of the current state:

CardDescription
Total CertificatesTotal certificates discovered and imported into the CLM
Expiring SoonCertificates expiring in the next 30 days
Certificate AuthoritiesNumber of distinct CAs identified across the certificates

Domain Scan tab

Use Domain Scan to find certificates for a domain or IP immediately, without configuring any integration.

How to use it

  1. In the search field, enter the domain or IP address (e.g. pkiless.com or 192.168.1.1)
  2. Click Scan
  3. The CLM scans the domain and lists all certificates found under Discovery Results
  4. When it finishes, the message "Discovery completed — Found X certificates" appears

Results

The results table shows:

ColumnDescription
Certificate NameName/CN of the certificate found
DomainDomain where the certificate was found
IssuerIssuing certificate authority
ExpiresExpiration date
StatusCertificate status (Valid, Warning, Critical, Expired)
ActionsImport individually or view details

Importing certificates

  • Import individually — click + Import on the certificate row
  • Import all — click Import All to import all results at once
  • Multiple selection — use the checkboxes to select specific certificates and import them in bulk

The CLM uses SHA-256 fingerprints to avoid duplicates — certificates already in the inventory won't be imported again.

Where to start
Domain Scan is the recommended first step for new users. Scan your main domain to discover all active certificates before setting up integrations.

Scans tab

For continuous, automated discovery, use the Scans tab to create scheduled Discovery Jobs. See the Configure Discovery guide for detailed per-provider instructions.