Skip to content

Reports

SSL-CLM provides reporting capabilities for monitoring certificate risk, operational health, compliance posture, and audit activity.

Navigation: Sidebar → Governance → Reports


ReportDescription
Certificate ExpirationCertificates approaching or past expiration, grouped by urgency
Certificate InventoryComplete inventory snapshot with metadata
CompliancePolicy compliance status across all managed certificates
Discovery SummaryResults from recent discovery scans with correlation status
Audit ReportFiltered audit trail export for a date range

Identify certificates approaching expiration to prevent service outages and plan renewal workload.

Days to ExpiryRisk LevelRecommended Action
0 (expired)CriticalImmediate renewal or replacement
1–7 daysCriticalImmediate renewal
8–14 daysHighUrgent renewal
15–30 daysMediumSchedule renewal this week
31–60 daysLowPlan renewal
60+ daysNormalNo action needed
  • Time-based: Expiring within 7, 14, 30, 60, 90 days; already expired; custom range
  • Tier: Managed, Monitored, All
  • CA: Filter by issuing Certificate Authority
  • Status: Managed vs. Unmanaged, renewal scheduled vs. manual action required
  • Total certificates in scope
  • Critical count (expired + <7 days)
  • High-risk count
  • Certificates with auto-renewal enabled vs. manual
  • Overall risk score

Complete snapshot of your certificate estate for audit or inventory review.

  • Certificate name, subject, SANs
  • Issuer and CA
  • Validity dates
  • Key algorithm and size
  • Status and tier
  • Deployment locations
  • Auto-renewal status
  • Tier (Managed / Monitored)
  • Status (Active / Expired / Revoked / All)
  • CA
  • Date range (created within)

Assess adherence to configured issuance and deployment policies.

  • Certificates violating key size policies
  • Certificates using disallowed algorithms
  • Certificates exceeding max validity
  • Certificates with forbidden SAN patterns
  • Certificates without auto-renewal enabled
  • Orphan certificates (not deployed)
  • By policy (which policies are violated)
  • By CA (which CAs produce non-compliant certificates)
  • By severity (critical / warning / info)

Summarize discovery scan results and reconciliation status.

  • Total certificates discovered
  • New (unmanaged) certificates found
  • Ghost certificates (in CA but not deployed)
  • Out-of-sync certificates (deployed vs. inventory mismatch)
  • Scan success/failure rates
  • Coverage by network segment

Export audit trail entries for a specific period for compliance review or incident investigation.

  • Date range (from / to)
  • Actor (user, system, agent)
  • Entity type
  • Action type
  • All filtered audit entries with full metadata
  • Actor information
  • Entity references
  • Structured event details

  1. Navigate to Governance → Reports
  2. Select the report type
  3. Configure filters (date range, scope, etc.)
  4. Choose export format:
    • PDF — Formatted document suitable for management review
    • Excel — Spreadsheet with full data for analysis
    • CSV — Raw data for integration with other tools
  5. Click Generate
  6. Download when ready

Reports can be scheduled for periodic generation:

  • Daily expiration summary (emailed to team)
  • Weekly compliance report
  • Monthly inventory snapshot

Configure via the report scheduling options or API.


FrequencyReportPurpose
DailyCertificate Expiration (7-day window)Catch any certificates about to expire
WeeklyCompliance ReportVerify all certificates meet policy
MonthlyCertificate InventoryFull estate snapshot for management
After DiscoveryDiscovery SummaryReview newly found certificates
As NeededAudit ReportIncident investigation, compliance audit

Report generation requires the report:read permission. Creating scheduled reports requires report:create. Running ad-hoc reports requires report:run.


  • Dashboard — Real-time metrics (reports provide historical analysis)
  • Policies — Policies that drive compliance reporting
  • Audit Trail — Detailed event log (reports provide summarized exports)