Skip to content

Settings

The Settings section provides platform-wide configuration for user management, access control, notifications, appearance, and licensing.

Navigation: Sidebar → Settings


SectionDescriptionPermission
License & QuotaView license details and managed certificate quotasettings:read
UsersManage user accountsuser:read, user:create, user:delete
RolesDefine roles with granular permissionsrole:read
TeamsOrganize users into teamsteam:read, team:create
ThemeCustomize appearance (light/dark mode)Any authenticated user
Alerts & NotificationsConfigure alert rules and deliveryalert:read
Email SettingsSMTP configuration for outbound emailssettings:edit
Single Sign-OnOIDC/SAML SSO configurationsettings:edit

View your current license information:

FieldDescription
License TypePlan tier (Starter, Professional, Enterprise)
Managed Certificate QuotaMaximum managed certificates allowed
Current UsageHow many managed certificates are in use
License ExpirationWhen the license expires
FeaturesEnabled feature flags for your plan

The quota is enforced at the platform level — you cannot create new managed certificates beyond your limit. Monitored-tier certificates do not count against the quota.


Manage platform user accounts.

ColumnDescription
UsernameLogin identifier
EmailContact email
RoleAssigned role
TeamTeam membership
StatusActive / Disabled
Last LoginMost recent authentication
  • Add User — Create a new local user account with username, email, password, role, and team
  • Edit — Modify user details, change role assignment
  • Disable — Deactivate the account (prevents login)
  • Delete — Permanently remove the user
  • Reset Password — Force password reset on next login
  • user:read — View user list
  • user:create — Add new users
  • user:delete — Remove users
  • user:assign-role — Change role assignments

Define custom roles with granular permissions using the permission matrix.

RoleDescription
AdministratorFull access to all platform features
PKI ManagerManage CAs, policies, and certificate lifecycle
Deploy EngineerDeploy certificates to stores, manage agents
Security ReviewerRead-only access with audit and report capabilities
Read OnlyView-only access to certificates and dashboard

Built-in (system) roles cannot be deleted but can be viewed.

Create custom roles by selecting specific permissions from the matrix.

The role editor displays a checkbox matrix organized by resource:

ResourceAvailable Permissions
Certificatesread, issue, revoke, deploy, renew, approve, export-key
Certificate Authoritiesread, create, delete, discover
Certificate Storesread, create, delete, deploy
Agentsread, register, disable
Discoveryread, run, configure
Policiesread, create, delete
Reportsread, create, run
Usersread, create, delete, assign-role
Teamsread, create, edit, delete
Alertsread, acknowledge
Auditread
Settingsread, edit
ACMEread, configure
DNSread, configure
Jobsread, manage

Use “Select All” per resource row to grant all permissions for that resource. Custom combinations allow fine-grained control.

  1. Click + Create Role
  2. Enter name and description
  3. Check the desired permissions in the matrix
  4. Click Save

Organize users into teams for ownership scoping and collaboration.

FieldDescription
NameTeam display name
SlugURL-safe identifier (auto-generated)
DescriptionTeam purpose
LeadTeam lead user
ColorVisual identifier (hex color for UI badges)
  • Assign certificate ownership by team
  • Scope dashboard views by team
  • Route approval requests to team leads
  • Default team assignment for SSO-provisioned users
  • Create Team — Add a new team
  • Edit — Modify team details
  • Delete — Remove team (requires confirmation)

Customize the platform appearance:

  • Light Mode — Default, light background
  • Dark Mode — Dark background, easier on the eyes in low-light environments
  • Brand Colors — Customize primary/accent colors (enterprise plans)

Theme preference is stored per-user.


Configure alert rules that trigger when conditions are met:

TriggerDescription
Certificate ExpiringConfigurable thresholds: 90, 60, 30, 15, 7 days
Certificate ExpiredImmediate alert when a certificate passes its validity
Renewal FailedAuto-renewal or manual renewal job failed
Deployment FailedCertificate deployment to a store failed
Agent OfflineAn agent stopped reporting heartbeats
Discovery: New Certificates FoundUnmanaged certificates discovered
Policy ViolationCertificate request violated a policy
CA UnhealthyA Certificate Authority became unreachable
ChannelConfiguration
In-AppNotifications bell in the top bar (always active)
EmailRequires SMTP configuration (see Email Settings)
WebhookPOST to a configured URL with JSON payload (future)
  • Error (red) — Critical, requires immediate action
  • Warning (orange) — Important, should be addressed soon
  • Info (blue) — Informational, no immediate action needed

Configure SMTP for outbound email notifications.

FieldDescriptionExample
SMTP HostMail server hostnamesmtp.gmail.com
SMTP PortMail server port587 (TLS), 465 (SSL)
UsernameSMTP authentication usernamenoreply@example.com
PasswordSMTP authentication password(stored encrypted)
From AddressSender email addressssl-clm@example.com
TLS EnabledUse STARTTLSYes / No
EnabledMaster enable/disable toggleYes / No

Click Send Test Email to verify SMTP connectivity:

  1. Enter a recipient address
  2. Click Send
  3. Check inbox for the test email
  4. If it fails, review error messages and adjust SMTP settings

Configure OIDC-based single sign-on for enterprise authentication.

ProviderTypeKey Configuration
Microsoft Entra ID (Azure AD)OIDCTenant ID, Client ID, Client Secret
Google WorkspaceOIDCIssuer URI, Client ID, Client Secret
OktaOIDCIssuer URI, Client ID, Client Secret
Generic OIDCOIDCCustom Issuer URI, Client ID, Client Secret
FieldDescription
Enable SSOMaster toggle
ProviderSelect from supported providers
Client IDOAuth client ID from your IdP
Client SecretOAuth client secret (stored encrypted)
Tenant IDAzure AD tenant ID (Microsoft only)
Issuer URIOIDC issuer URL (Google, Okta, Generic)
Display NameButton label on login page (e.g., “Sign in with Okta”)
ScopesOIDC scopes to request (default: openid profile email)
Redirect URIPlatform callback URL (displayed for configuration in your IdP)

When enabled, users authenticating via SSO for the first time are automatically created in SSL-CLM:

FieldDescription
JIT ProvisioningToggle to enable auto-creation
Default RoleRole assigned to JIT-created users (e.g., Read Only)
Default TeamTeam assigned to JIT-created users

This eliminates the need to pre-create user accounts — users are created on first SSO login.

Click Test Connection to validate your SSO configuration:

  1. Opens a popup to your IdP login
  2. Authenticates the test user
  3. Returns success/failure with diagnostic info

For platform administrators managing multiple tenants:

Navigation: Sidebar → Platform (visible only to platform admins)

  • View all tenants
  • Create new tenants
  • Configure per-tenant quotas
  • Manage tenant-level settings

This section is only visible to users with the Platform Admin role and is not part of the standard Settings section.


  • Dashboard — Reflects alert counts and health
  • Audit Trail — Logs all settings changes
  • Policies — Governance that works with roles and approvals