Settings
Settings
Section titled “Settings”The Settings section provides platform-wide configuration for user management, access control, notifications, appearance, and licensing.
Navigation: Sidebar → Settings
Settings Sub-Sections
Section titled “Settings Sub-Sections”| Section | Description | Permission |
|---|---|---|
| License & Quota | View license details and managed certificate quota | settings:read |
| Users | Manage user accounts | user:read, user:create, user:delete |
| Roles | Define roles with granular permissions | role:read |
| Teams | Organize users into teams | team:read, team:create |
| Theme | Customize appearance (light/dark mode) | Any authenticated user |
| Alerts & Notifications | Configure alert rules and delivery | alert:read |
| Email Settings | SMTP configuration for outbound emails | settings:edit |
| Single Sign-On | OIDC/SAML SSO configuration | settings:edit |
License & Quota
Section titled “License & Quota”View your current license information:
| Field | Description |
|---|---|
| License Type | Plan tier (Starter, Professional, Enterprise) |
| Managed Certificate Quota | Maximum managed certificates allowed |
| Current Usage | How many managed certificates are in use |
| License Expiration | When the license expires |
| Features | Enabled feature flags for your plan |
The quota is enforced at the platform level — you cannot create new managed certificates beyond your limit. Monitored-tier certificates do not count against the quota.
Manage platform user accounts.
User Table
Section titled “User Table”| Column | Description |
|---|---|
| Username | Login identifier |
| Contact email | |
| Role | Assigned role |
| Team | Team membership |
| Status | Active / Disabled |
| Last Login | Most recent authentication |
Actions
Section titled “Actions”- Add User — Create a new local user account with username, email, password, role, and team
- Edit — Modify user details, change role assignment
- Disable — Deactivate the account (prevents login)
- Delete — Permanently remove the user
- Reset Password — Force password reset on next login
Permissions Required
Section titled “Permissions Required”user:read— View user listuser:create— Add new usersuser:delete— Remove usersuser:assign-role— Change role assignments
Define custom roles with granular permissions using the permission matrix.
Built-in Roles
Section titled “Built-in Roles”| Role | Description |
|---|---|
| Administrator | Full access to all platform features |
| PKI Manager | Manage CAs, policies, and certificate lifecycle |
| Deploy Engineer | Deploy certificates to stores, manage agents |
| Security Reviewer | Read-only access with audit and report capabilities |
| Read Only | View-only access to certificates and dashboard |
Built-in (system) roles cannot be deleted but can be viewed.
Custom Roles
Section titled “Custom Roles”Create custom roles by selecting specific permissions from the matrix.
Permission Matrix
Section titled “Permission Matrix”The role editor displays a checkbox matrix organized by resource:
| Resource | Available Permissions |
|---|---|
| Certificates | read, issue, revoke, deploy, renew, approve, export-key |
| Certificate Authorities | read, create, delete, discover |
| Certificate Stores | read, create, delete, deploy |
| Agents | read, register, disable |
| Discovery | read, run, configure |
| Policies | read, create, delete |
| Reports | read, create, run |
| Users | read, create, delete, assign-role |
| Teams | read, create, edit, delete |
| Alerts | read, acknowledge |
| Audit | read |
| Settings | read, edit |
| ACME | read, configure |
| DNS | read, configure |
| Jobs | read, manage |
Use “Select All” per resource row to grant all permissions for that resource. Custom combinations allow fine-grained control.
Creating a Role
Section titled “Creating a Role”- Click + Create Role
- Enter name and description
- Check the desired permissions in the matrix
- Click Save
Organize users into teams for ownership scoping and collaboration.
Team Fields
Section titled “Team Fields”| Field | Description |
|---|---|
| Name | Team display name |
| Slug | URL-safe identifier (auto-generated) |
| Description | Team purpose |
| Lead | Team lead user |
| Color | Visual identifier (hex color for UI badges) |
Use Cases
Section titled “Use Cases”- Assign certificate ownership by team
- Scope dashboard views by team
- Route approval requests to team leads
- Default team assignment for SSO-provisioned users
Actions
Section titled “Actions”- Create Team — Add a new team
- Edit — Modify team details
- Delete — Remove team (requires confirmation)
Customize the platform appearance:
- Light Mode — Default, light background
- Dark Mode — Dark background, easier on the eyes in low-light environments
- Brand Colors — Customize primary/accent colors (enterprise plans)
Theme preference is stored per-user.
Alerts & Notifications
Section titled “Alerts & Notifications”Configure alert rules that trigger when conditions are met:
Alert Triggers
Section titled “Alert Triggers”| Trigger | Description |
|---|---|
| Certificate Expiring | Configurable thresholds: 90, 60, 30, 15, 7 days |
| Certificate Expired | Immediate alert when a certificate passes its validity |
| Renewal Failed | Auto-renewal or manual renewal job failed |
| Deployment Failed | Certificate deployment to a store failed |
| Agent Offline | An agent stopped reporting heartbeats |
| Discovery: New Certificates Found | Unmanaged certificates discovered |
| Policy Violation | Certificate request violated a policy |
| CA Unhealthy | A Certificate Authority became unreachable |
Delivery Channels
Section titled “Delivery Channels”| Channel | Configuration |
|---|---|
| In-App | Notifications bell in the top bar (always active) |
| Requires SMTP configuration (see Email Settings) | |
| Webhook | POST to a configured URL with JSON payload (future) |
Severity Levels
Section titled “Severity Levels”- Error (red) — Critical, requires immediate action
- Warning (orange) — Important, should be addressed soon
- Info (blue) — Informational, no immediate action needed
Email Settings
Section titled “Email Settings”Configure SMTP for outbound email notifications.
SMTP Configuration
Section titled “SMTP Configuration”| Field | Description | Example |
|---|---|---|
| SMTP Host | Mail server hostname | smtp.gmail.com |
| SMTP Port | Mail server port | 587 (TLS), 465 (SSL) |
| Username | SMTP authentication username | noreply@example.com |
| Password | SMTP authentication password | (stored encrypted) |
| From Address | Sender email address | ssl-clm@example.com |
| TLS Enabled | Use STARTTLS | Yes / No |
| Enabled | Master enable/disable toggle | Yes / No |
Testing
Section titled “Testing”Click Send Test Email to verify SMTP connectivity:
- Enter a recipient address
- Click Send
- Check inbox for the test email
- If it fails, review error messages and adjust SMTP settings
Single Sign-On (SSO)
Section titled “Single Sign-On (SSO)”Configure OIDC-based single sign-on for enterprise authentication.
Supported Identity Providers
Section titled “Supported Identity Providers”| Provider | Type | Key Configuration |
|---|---|---|
| Microsoft Entra ID (Azure AD) | OIDC | Tenant ID, Client ID, Client Secret |
| Google Workspace | OIDC | Issuer URI, Client ID, Client Secret |
| Okta | OIDC | Issuer URI, Client ID, Client Secret |
| Generic OIDC | OIDC | Custom Issuer URI, Client ID, Client Secret |
Configuration Fields
Section titled “Configuration Fields”| Field | Description |
|---|---|
| Enable SSO | Master toggle |
| Provider | Select from supported providers |
| Client ID | OAuth client ID from your IdP |
| Client Secret | OAuth client secret (stored encrypted) |
| Tenant ID | Azure AD tenant ID (Microsoft only) |
| Issuer URI | OIDC issuer URL (Google, Okta, Generic) |
| Display Name | Button label on login page (e.g., “Sign in with Okta”) |
| Scopes | OIDC scopes to request (default: openid profile email) |
| Redirect URI | Platform callback URL (displayed for configuration in your IdP) |
Just-In-Time (JIT) User Provisioning
Section titled “Just-In-Time (JIT) User Provisioning”When enabled, users authenticating via SSO for the first time are automatically created in SSL-CLM:
| Field | Description |
|---|---|
| JIT Provisioning | Toggle to enable auto-creation |
| Default Role | Role assigned to JIT-created users (e.g., Read Only) |
| Default Team | Team assigned to JIT-created users |
This eliminates the need to pre-create user accounts — users are created on first SSO login.
Testing SSO
Section titled “Testing SSO”Click Test Connection to validate your SSO configuration:
- Opens a popup to your IdP login
- Authenticates the test user
- Returns success/failure with diagnostic info
Platform Admin (Multi-Tenant)
Section titled “Platform Admin (Multi-Tenant)”For platform administrators managing multiple tenants:
Navigation: Sidebar → Platform (visible only to platform admins)
Tenant Management
Section titled “Tenant Management”- View all tenants
- Create new tenants
- Configure per-tenant quotas
- Manage tenant-level settings
This section is only visible to users with the Platform Admin role and is not part of the standard Settings section.
Related Pages
Section titled “Related Pages”- Dashboard — Reflects alert counts and health
- Audit Trail — Logs all settings changes
- Policies — Governance that works with roles and approvals