Skip to content

The inventory

Certificates in the sidebar is the single list of every certificate found across all your clients. The heading reads “Certificates at a glance”, with a count of certificates across all clients above it.

The inventory shows active certificates: ones you are still responsible for. A certificate drops out of it once a renewal supersedes it, once it is revoked, once someone marks it resolved, or once its track is set to Excluded. Expiry is deliberately not part of that test, so an expired certificate nobody has renewed stays on the list where you can see it.

Certificates that expired more than 90 days ago are not loaded, and the view holds up to 500 certificates.

Column What it shows
Hostname The certificate’s common name
Client The client it was matched to
Issuer The certificate authority, in readable form
Track Auto-renewing, Manual or Excluded
Expires The end of the validity period
Days Days remaining, negative once past
Status The status pill

Hostname, Client, Issuer, Expires and Days are sortable. Select a column heading to sort by it, and again to reverse the direction.

Status tabs across the top: Active, Critical ≤7d, Warning ≤30d, Healthy, Recently expired and Starred. Each carries its own count. The thresholds behind them are in certificate status.

Search covers hostname, client, issuer and serial number. The box is labelled “Search hostname, client, issuer, serial…”.

Track filters to All tracks, Auto-renewing, Manual or Excluded. What the tracks mean is in renewals and supersession.

Issuer is a multi-select dropdown listing every issuer in your inventory with a count beside each. The button reads “Issuer: any” until you pick one. Clear all resets it.

Group by client switches the table to sections, one per client, with the client carrying the most urgent certificate first.

Selecting a row opens a panel on the right headed Certificate. It shows a Lifecycle bar placing today between the issue and expiry dates, and a Subject block with the common name, issuer, serial, issued date, expiry date, track and client. Open full page takes you to the certificate’s own page, which adds its subject alternative names, its history and any PSA ticket raised for it.

The star at the end of each row adds that certificate to your personal watchlist. Starred certificates appear in the Watching panel on your dashboard and under the Starred tab here.

Export CSV downloads the inventory as a spreadsheet named certificates- plus today’s date. The file has one row per certificate with these columns:

Subject CN, Serial, Issuer CN, Source, Not Before, Not After,
Days Left, Client, Wildcard, Self-signed

The export covers your active certificates rather than whatever filter you happen to have on screen, so the file is the same whichever tab you are viewing.

With no certificates at all, the table reads “No certificates yet” and offers Add your first client. Under a filter that matches nothing you get “No certificates match”, except on the critical tab, which reads “Nothing on fire”.