Overview
Stores (Certificate Repositories) are the destinations where the CLM automatically installs and manages certificates after issuance or renewal.
Store Types
| Store | How to create | Description |
|---|---|---|
| Azure Key Vault | Via the Stores screen or via Discovery | Publishes certificates to Azure Key Vaults |
| Unix Provider | Via the Stores screen | Deploys via SSH to Linux servers with an agent |
| F5 BIG-IP | Via Discovery | Manages Client/Server SSL profiles on F5 |
| Citrix NetScaler | Via Discovery | Manages SSL certkeys on NetScaler |
| Microsoft IIS | Via Discovery | Manages HTTPS bindings on IIS sites |
F5, NetScaler, and IIS can only be created via Discovery. See the [Discovery guide](/en/guias/discovery/visao-geral) to set up automatic discovery for these environments.
Create a Store manually
Go to Stores in the sidebar menu and click + New Certificate Repository.
The wizard has 4 steps: Provider → Integration/Agent → Configuration → Review.
Select the guide for the Store type:
Install a certificate in a Store
In any Store, open the details and click Install Certificate. Select the certificate from the inventory and confirm. The CLM performs the deploy automatically using the credentials from the linked integration or agent.
Sync a Store
Click Sync Now in the Store details to force an immediate sync with the destination. The CLM updates the inventory of installed certificates and the status of each binding.
Remove a Store
In the Danger Zone within the Store details, click Remove Repository from CLM. This undoes the link with the CLM but does not remove the certificates from the destination (Key Vault, NetScaler, etc.).
When you remove a Store, the automatic renewal settings linked to it will be lost.