Skip to content

Certificate Management

The Certificate Management page is the central hub for all SSL/TLS certificates in your organization. It provides unified inventory visibility, multi-mode enrollment, lifecycle tracking, and deployment management.

Navigation: Sidebar → Certificates

Certificate Inventory


The inventory displays all certificates in a searchable, filterable data table.

The top-right corner shows your license usage:

25 / 500 managed

This indicates how many certificates are in the Managed tier relative to your license limit.


Certificates are organized into tiers:

TabDescription
AllEvery certificate in the system regardless of tier
ManagedCertificates under active lifecycle management — counts against your license quota
MonitoredCertificates being tracked for visibility but not actively managed (e.g., discovered certificates)

Managed certificates receive full lifecycle automation (renewal, deployment, alerting). Monitored certificates are tracked for expiration awareness only.


Filter certificates by clicking status chips:

StatusMeaning
ActiveValid and within its validity window
ExpiringWithin the renewal threshold (approaching expiration)
ExpiredPast its validity period
Pending ApprovalAwaiting manual approval per policy
PendingIssuance in progress
IssuingCurrently being issued by the CA
ArchivedSuperseded by a newer certificate, retained for audit
RevokedExplicitly revoked
FailedIssuance or renewal failed
RejectedApproval request was rejected

The inventory table displays (configurable via the Columns button):

ColumnDescription
NameCertificate common name or friendly name
StatusCurrent lifecycle status with color-coded badge
TierManaged or Monitored
Days LeftDays until expiration (negative = expired)
CAIssuing Certificate Authority name
DeploymentsNumber of active store deployments
CreatedDate the certificate was added to inventory
Key PresentWhether the private key is stored in the platform
  • Search bar — Find certificates by common name, SAN, serial number, or fingerprint
  • Column sorting — Click any column header to sort ascending/descending
  • Pagination — Navigate through large inventories

Click any certificate row to open the full detail view.

Certificate Detail

  • Subject — Common Name, Organization, OU, Country, State, Locality, Email
  • Issuer — CA name, issuer DN
  • Validity — Valid From, Valid To, Days Remaining
  • Serial Number — Hex serial
  • Fingerprint — SHA-256 fingerprint
  • Status — Current lifecycle state
  • Algorithm — RSA or EC (ECDSA)
  • Key Size — 2048, 3072, 4096 (RSA) or 256, 384, 521 (EC)
  • Signature Algorithm — e.g., SHA256withRSA, SHA384withECDSA
  • Key Present — Whether private key is stored

Full list of DNS names and IP addresses covered by the certificate.

Certificate Deployments

Lists all stores where this certificate is deployed:

  • Store name and type
  • Deployment status
  • Last sync time
  • Actions: Remove deployment, re-deploy

Audit trail of all renewals for this certificate identity:

  • Renewal date
  • Previous certificate serial
  • New certificate serial
  • Trigger (manual / auto / policy)

From the detail view:

  • Renew — Trigger immediate renewal
  • Deploy — Add to a certificate store
  • Revoke — Revoke the certificate at the CA
  • Download — Download certificate (PEM, DER, PKCS#12)
  • Export Key — Export private key (requires certificate:export-key permission)
  • Archive — Move to archived state

Click + New Certificate to open the unified enrollment workflow.

SSL-CLM v2 supports 5 enrollment modes from a single page:


Full automated lifecycle: generate key pair + CSR on the server, submit to an integrated CA, receive the issued certificate.

Required fields:

  • Certificate Authority (select from configured CAs)
  • Common Name
  • Subject Alternative Names (optional)
  • Key Algorithm: RSA or EC (ECDSA)
  • Key Size: 2048 / 3072 / 4096 (RSA) or P-256 / P-384 / P-521 (EC)
  • Validity (days)
  • Template (if the CA supports templates)

Optional:

  • Auto-Renew: Enable + days-before-expiry threshold
  • Auto-Deploy: Select target stores
  • Generate PFX: Create PKCS#12 bundle with password

Flow:

  1. Platform generates key pair and CSR
  2. CSR submitted to selected CA
  3. CA issues certificate (may require approval if policy enforces it)
  4. Certificate stored in inventory
  5. Auto-deployed to configured stores (if enabled)

Submit a PEM-encoded CSR that was generated externally (e.g., by the application, openssl, or another tool).

Required fields:

  • Certificate Authority
  • CSR PEM (paste into text area)

CSR Preview: As you paste, the platform parses and displays:

  • Subject (CN, O, OU, etc.)
  • SANs detected
  • Key algorithm and size
  • Any parsing errors

Flow:

  1. CSR validated and parsed
  2. Submitted to selected CA
  3. Certificate issued and stored
  4. Private key is NOT stored (it remains with whoever generated the CSR)

Generate a key pair and CSR locally in the browser. Download the CSR for submission to an external CA. The certificate will not be issued by SSL-CLM.

Required fields:

  • Common Name
  • Key Algorithm and Size
  • SANs (optional)
  • Subject fields (optional)

Output:

  • .csr file (PEM-encoded)
  • .key file (PEM-encoded private key)
  • Optional: ZIP bundle of both files

Use case: When you need to submit a CSR to a CA that is not integrated with SSL-CLM.


Generate a self-signed certificate for development, testing, or internal services.

Required fields:

  • Common Name
  • Key Algorithm and Size
  • Validity (days)
  • SANs (optional)

Output:

  • Self-signed certificate stored in inventory
  • Private key stored
  • Marked as self-signed in metadata

Warning: Self-signed certificates are not trusted by browsers or clients without explicit trust configuration. Not recommended for production.


Reserve a managed certificate identity without immediate issuance. Useful for planning ahead — you define what certificate you need, and issue it when ready.

Required fields:

  • Certificate Authority
  • Common Name

Result:

  • Creates a certificate identity in “Pending” status
  • No CSR or certificate is generated
  • Can be issued later from the detail view

When you submit a certificate request, the Policy Engine evaluates all active issuance policies:

  • If the request violates a policy (e.g., key size too small, forbidden SAN pattern), the request is rejected with an error message.
  • If the policy has requireApproval enabled, the certificate enters Pending Approval status and must be approved by a user with the certificate:approve permission.
  • If no policies match or all pass, the certificate is issued immediately.

Click Import to upload existing certificates into inventory:

  • Supported formats: .pem, .crt, .cer, .der, .p12, .pfx
  • Optionally include private key
  • Imported certificates are added to the Monitored tier by default
  • Promote to Managed tier to enable lifecycle automation

From the inventory table, select multiple certificates to:

  • Bulk renew
  • Bulk deploy to a store
  • Bulk archive
  • Export as CSV

PLAN_FOR_LATER → PENDING → ISSUING → ACTIVE → EXPIRING → EXPIRED
↓ ↓
FAILED RENEWED → ACTIVE
↓
ARCHIVED
ACTIVE → REVOKED
PENDING → PENDING_APPROVAL → ACTIVE (approved) or REJECTED (denied)