Reports
Reports
Section titled “Reports”SSL-CLM provides reporting capabilities for monitoring certificate risk, operational health, compliance posture, and audit activity.
Navigation: Sidebar → Governance → Reports
Available Report Types
Section titled “Available Report Types”| Report | Description |
|---|---|
| Certificate Expiration | Certificates approaching or past expiration, grouped by urgency |
| Certificate Inventory | Complete inventory snapshot with metadata |
| Compliance | Policy compliance status across all managed certificates |
| Discovery Summary | Results from recent discovery scans with correlation status |
| Audit Report | Filtered audit trail export for a date range |
Certificate Expiration Report
Section titled “Certificate Expiration Report”Purpose
Section titled “Purpose”Identify certificates approaching expiration to prevent service outages and plan renewal workload.
Risk Indicators
Section titled “Risk Indicators”| Days to Expiry | Risk Level | Recommended Action |
|---|---|---|
| 0 (expired) | Critical | Immediate renewal or replacement |
| 1–7 days | Critical | Immediate renewal |
| 8–14 days | High | Urgent renewal |
| 15–30 days | Medium | Schedule renewal this week |
| 31–60 days | Low | Plan renewal |
| 60+ days | Normal | No action needed |
Filters
Section titled “Filters”- Time-based: Expiring within 7, 14, 30, 60, 90 days; already expired; custom range
- Tier: Managed, Monitored, All
- CA: Filter by issuing Certificate Authority
- Status: Managed vs. Unmanaged, renewal scheduled vs. manual action required
Metrics Provided
Section titled “Metrics Provided”- Total certificates in scope
- Critical count (expired + <7 days)
- High-risk count
- Certificates with auto-renewal enabled vs. manual
- Overall risk score
Certificate Inventory Report
Section titled “Certificate Inventory Report”Purpose
Section titled “Purpose”Complete snapshot of your certificate estate for audit or inventory review.
Data Included
Section titled “Data Included”- Certificate name, subject, SANs
- Issuer and CA
- Validity dates
- Key algorithm and size
- Status and tier
- Deployment locations
- Auto-renewal status
Filters
Section titled “Filters”- Tier (Managed / Monitored)
- Status (Active / Expired / Revoked / All)
- CA
- Date range (created within)
Compliance Report
Section titled “Compliance Report”Purpose
Section titled “Purpose”Assess adherence to configured issuance and deployment policies.
Data Included
Section titled “Data Included”- Certificates violating key size policies
- Certificates using disallowed algorithms
- Certificates exceeding max validity
- Certificates with forbidden SAN patterns
- Certificates without auto-renewal enabled
- Orphan certificates (not deployed)
Grouping
Section titled “Grouping”- By policy (which policies are violated)
- By CA (which CAs produce non-compliant certificates)
- By severity (critical / warning / info)
Discovery Summary Report
Section titled “Discovery Summary Report”Purpose
Section titled “Purpose”Summarize discovery scan results and reconciliation status.
Data Included
Section titled “Data Included”- Total certificates discovered
- New (unmanaged) certificates found
- Ghost certificates (in CA but not deployed)
- Out-of-sync certificates (deployed vs. inventory mismatch)
- Scan success/failure rates
- Coverage by network segment
Audit Report
Section titled “Audit Report”Purpose
Section titled “Purpose”Export audit trail entries for a specific period for compliance review or incident investigation.
Filters
Section titled “Filters”- Date range (from / to)
- Actor (user, system, agent)
- Entity type
- Action type
Data Included
Section titled “Data Included”- All filtered audit entries with full metadata
- Actor information
- Entity references
- Structured event details
Generating a Report
Section titled “Generating a Report”- Navigate to Governance → Reports
- Select the report type
- Configure filters (date range, scope, etc.)
- Choose export format:
- PDF — Formatted document suitable for management review
- Excel — Spreadsheet with full data for analysis
- CSV — Raw data for integration with other tools
- Click Generate
- Download when ready
Scheduled Reports
Section titled “Scheduled Reports”Reports can be scheduled for periodic generation:
- Daily expiration summary (emailed to team)
- Weekly compliance report
- Monthly inventory snapshot
Configure via the report scheduling options or API.
Operational Usage
Section titled “Operational Usage”| Frequency | Report | Purpose |
|---|---|---|
| Daily | Certificate Expiration (7-day window) | Catch any certificates about to expire |
| Weekly | Compliance Report | Verify all certificates meet policy |
| Monthly | Certificate Inventory | Full estate snapshot for management |
| After Discovery | Discovery Summary | Review newly found certificates |
| As Needed | Audit Report | Incident investigation, compliance audit |
Permissions
Section titled “Permissions”Report generation requires the report:read permission. Creating scheduled reports requires report:create. Running ad-hoc reports requires report:run.
Related Pages
Section titled “Related Pages”- Dashboard — Real-time metrics (reports provide historical analysis)
- Policies — Policies that drive compliance reporting
- Audit Trail — Detailed event log (reports provide summarized exports)