Skip to content

Certificate Stores

Certificate Stores represent deployment targets where certificates and keys are installed, bound to services, validated, and monitored.

Navigation: Sidebar → Infrastructure → Certificate Stores

Certificate Stores


The main view displays all configured stores:

ColumnDescription
NameFriendly name assigned during creation
TypeStore integration type (e.g., NGINX, IIS, AWS ACM)
CategoryFile-Based, Application Server, or Cloud
AgentAgent name (for agent-based stores) or ”—” for agentless
CertificatesNumber of certificates deployed to this store
StatusConnected / Disconnected / Error
Last SyncLast time the store was inventoried

SSL-CLM v2 supports 7 certificate store types organized into 3 categories:

StoreType IDRuntimeAgentCertificate Format
NGINXstore-filebased-nginxAgentRequiredPEM (cert + key + chain as separate files)
JKSstore-filebased-jksAgentRequiredJava Keystore (JKS / PKCS#12)

NGINX stores deploy certificates as PEM files to configured paths and execute a reload command (nginx -t && systemctl reload nginx).

JKS stores import certificates into Java Keystores using keytool or direct PKCS#12 operations.


StoreType IDRuntimeAgentCertificate Format
Apachestore-applicationserver-apacheAgentRequiredPEM (cert + key + chain)
IISstore-applicationserver-iisAgentRequiredPFX / PKCS#12
F5 BIG-IPstore-applicationserver-f5bigipBackend—PEM or PKCS#12 via iControl REST

Apache stores deploy PEM files and reload Apache (apachectl configtest && systemctl reload apache2).

IIS stores import certificates into the Windows Certificate Store and bind them to IIS sites.

F5 BIG-IP stores use the iControl REST API to upload certificates and keys, then bind them to SSL profiles. No agent required.


StoreType IDRuntimeAgentCertificate Format
AWS ACMstore-cloud-aws-acmBackend—PEM (cert + chain + key)
Azure Key Vaultstore-cloud-azure-keyvault-secretBackend—PEM or PFX

AWS ACM stores use the AWS SDK to import certificates into AWS Certificate Manager for use with ELB, CloudFront, API Gateway, etc.

Azure Key Vault stores use the Azure SDK to import certificates as Key Vault secrets/certificates.


ModeHow It WorksWhen to Use
Agent-basedSSL-CLM Agent installed on the target host executes deployment locallyOn-premise servers, VMs, containers without API access
AgentlessPlatform connects directly via API (REST, SDK)Cloud services, load balancers with management APIs

For agent-based stores, the agent must be registered and ONLINE. The platform dispatches a DEPLOY_CERT job to the agent, which executes locally.

For agentless stores, the platform backend makes direct API calls to the target service.


  1. Click + Add Store
  2. Step 1 — Select Type: Store types are displayed as cards organized by category
    • Browse File-Based, Application Server, and Cloud categories
    • Click the desired store type card
  3. Step 2 — Configure: Fill in the configuration form
    • Name — Friendly identifier for this store instance
    • Agent — Select from registered agents (for agent-based stores)
    • Type-specific fields rendered dynamically from the integration schema
FieldDescriptionExample
certPathPath to write certificate PEM/etc/nginx/ssl/cert.pem
keyPathPath to write private key PEM/etc/nginx/ssl/key.pem
chainPathPath to write CA chain PEM/etc/nginx/ssl/chain.pem
reloadCommandCommand to reload NGINXnginx -t && systemctl reload nginx
FieldDescriptionExample
certPathPath to certificate file/etc/ssl/certs/server.pem
keyPathPath to private key file/etc/ssl/private/server.key
chainPathPath to chain file/etc/ssl/certs/chain.pem
reloadCommandCommand to reload Apacheapachectl configtest && systemctl reload apache2
FieldDescriptionExample
siteNameIIS site name to bindDefault Web Site
storeNameWindows certificate storeWebHosting
bindingIpIP for the binding*
bindingPortPort for the binding443
bindingHostnameSNI hostname (optional)example.com
FieldDescriptionExample
hostF5 management IP/hostnamef5.internal.corp
portManagement port443
usernameAPI usernameadmin
passwordAPI password(stored encrypted)
partitionBIG-IP partitionCommon
sslProfileSSL profile name/Common/clientssl
FieldDescriptionExample
keystorePathPath to the keystore file/opt/app/conf/keystore.jks
keystorePasswordKeystore password(stored encrypted)
aliasKey alias within the keystoreserver
keystoreTypeJKS or PKCS12JKS
FieldDescriptionExample
regionAWS regionus-east-1
accessKeyIdAWS access key IDAKIA...
secretAccessKeyAWS secret access key(stored encrypted)
certificateArnExisting ACM cert ARN (for updates)arn:aws:acm:...
FieldDescriptionExample
vaultUrlKey Vault URLhttps://myvault.vault.azure.net
tenantIdAzure AD tenant IDxxxxxxxx-xxxx-...
clientIdService principal client IDxxxxxxxx-xxxx-...
clientSecretService principal secret(stored encrypted)
certificateNameName in Key Vaultmy-ssl-cert
  1. Click Save

Click any store row to open its detail page:

  • Store name, type, category
  • Agent assignment
  • Certificate count
  • Connection status
  • Last sync time

List of all certificates currently deployed in this store, with:

  • Certificate name and status
  • Deployment date
  • Binding details (for application servers)
ActionDescription
Deploy CertificatePush a certificate to this store
DiscoverScan the store and import found certificates
ValidateRun validation checks (cert present, key matches, chain valid)
Sync to InventoryUpdate inventory metadata from actual store state
BindBind a certificate to a service endpoint
BackupCreate a backup of current certificate state
EditModify store configuration
DeleteRemove store (does not remove certificates from the actual target)

  1. Navigate to a certificate’s detail page
  2. Click Deploy
  3. Select target store(s)
  4. Confirm deployment
  1. Navigate to the store detail page
  2. Click Deploy Certificate
  3. Select the certificate to deploy
  4. Configure binding (for application servers)
  5. Confirm
  1. Platform creates a DEPLOY_CERT job
  2. For agent-based: job is dispatched to the assigned agent
  3. For agentless: platform executes directly via API
  4. Certificate and key are written/uploaded
  5. Post-deploy hook executes (reload command for web servers)
  6. Validation runs (certificate present, key matches, service responding)
  7. Job status updated (SUCCESS / FAILED)

After deployment, the platform automatically validates:

  • Certificate file exists at the configured path
  • Private key is present and matches the certificate
  • Certificate chain is complete and valid
  • Service is responding with the new certificate (for web servers)
  • Binding is correct (for IIS, F5)

Failed validation generates an alert and marks the deployment as requiring attention.


Scan a store to find what certificates are currently deployed:

  1. Click Discover on a store
  2. The agent (or backend) scans the store
  3. Found certificates are compared against inventory
  4. Unmanaged certificates can be imported

Useful for:

  • Initial store onboarding
  • Drift detection
  • Verifying deployment state