Finding Certificates in the Certificate Inventory
Table of Contents
Expand all | Collapse all
-
- Activate Next-Generation Trust Security
-
-
- Configure Akamai Connection
- Configure AWS Connection
- Configure Azure Key Vault Connection
-
- Workload Identity Federation Authentication
- Workload Identity Federation - Azure Identity Provider Authentication
- Next-Gen Trust Security Generated Key Authentication
- User Permissions
- Workload Identity Federation Authentication
- Next-Gen Trust Security Generated Key Authentication
- User Permissions
- Supported OIDC Claims
-
-
-
- Working with the Built-in CA
- Add AWS Public CA
- Add AWS Private CA
- Add DigiCert One Certificate Authority
- Add Entrust
- Add GlobalSign Atlas
- Add GlobalSign MSSL
- Add GoDaddy
- Add Google Cloud Private CA
- Add a HID PKIaaS CA
- Add Certificate Manager - Self-Hosted
- Set Up an OpenSSL Certificate Authority Connector
- Create a Sectigo Certificate Manager Certificate Authority
- Add Zero Touch PKI
- Set Up Certificate Expiration Notifications
- Using a Custom DNS Provider
-
-
-
-
- Create an F5 BIG-IP LTM Machine
- Create a Microsoft Azure Private Key Vault Machine
- Create a Microsoft Azure Application Registration Machine
- Create a Microsoft IIS Machine
- Create a Microsoft Windows (PowerShell) Machine
- Create a Microsoft SQL Server Machine
- Create a Common KeyStore Machine
- Create a Citrix ADC Machine
- Create an Imperva WAF Machine
- Create a VMware NSX Advanced Load Balancer (AVI) Machine
- Create an A10 Thunder ADC Machine
- Create a Cloudflare Machine
- Create Kemp Virtual LoadMaster Machine
- Create a Palo Alto Panorama Machine
- Create a Radware Alteon Machine
-
- Provision to an F5 BIG-IP LTM
- Provision to a Microsoft Azure Private Key Vault
- Provision to Microsoft IIS
- Provision to Microsoft Windows (PowerShell)
- Provision to Microsoft SQL Server
- Provision to a Common KeyStore
- Provision to a Citrix ADC
- Provision to an Imperva WAF
- Provision to VMware NSX Advanced Load Balancer (AVI)
- Provision to an A10 Thunder ADC
- Provision to Cloudflare
- Provision to a Kemp Virtual LoadMaster
- Provision to Palo Alto Panorama
- Provision Certificates to Radware Alteon
-
-
- 47-Day Validity Readiness TLS Certificates dashboard
- About the Certificate Inventory
- Managing Certificate Lifecycle Settings
- Reissuing Certificates in Next-Gen Trust Security
- Downloading Certificates, Certificate Chains, and Keystores
- Retiring, Recovering, and Deleting Certificates
- Finding Certificates in the Certificate Inventory
- Importing Certificates from a CA Using EJBCA
- Domain-Based Validation for External Emails
-
- Create a Workload Identity Management or Discovery Agent Built-in Account
- Create an OCI Registry Built-in Account
- Create a Certificate Manager - Self-Hosted Built-in Account
- Create a Scanafi Built-in Account
- Toggling a Built-in Account on or Off
- Editing Built-in Accounts
- Deleting Existing Built-in Accounts
- Renew Existing Built-in Accounts
- Troubleshooting
Finding Certificates in the Certificate Inventory
As your environment grows, the certificate inventory can contain thousands of certificates. To help you locate specific certificates, Next-Gen Trust Security provides search, filtering, and summary tools.
Open the certificate inventory by going to Inventory > Certificates. At the top of the page, you can access the Summary View dashboard. You can also use search, predefined filters, or custom filters to find certificates.
Using the Summary View Dashboard
The Summary View dashboard provides an overview of certificate metrics based on your access level. All users can view the dashboard, but the data displayed is limited by role-based access controls (RBAC).
Users with the Superuser role in the parent TSG see metrics across the full inventory (parent TSG and all child TSGs), while users in child TSGs see only certificates within their assigned TSG.
Select any of the following tiles to filter the inventory:
- Total certificates
- Expired certificates
- Revoked certificates
- Expiring in 15 days
Note: You can select more than one tile at a time to further refine the results.
Using Search and Filter Options
Use the free-text search box or filters to locate certificates in the inventory. You can search by certificate name, domain, issuing certificate authority, and other attributes. Filters allow you to narrow results by criteria such as expiration date, revocation status, or assignment.
Using the Free-Text Search Box
When you enter text in the search box at the top of the inventory, Next-Gen Trust Security searches across all visible columns. This is useful when you know a specific value, such as a domain name or certificate identifier.
Using Predefined Filters
Next-Gen Trust Security includes several predefined filters. The default view is All certificates. To apply a predefined filter, open the filter dropdown and select one of the available options.
Examples include:
- My certificates: Displays only certificates you own.
- Retired certificates: Displays only retired certificates, which can help you locate certificates that may need to be recovered.
Using Custom Filters
Select Filters to create more targeted queries using one or more criteria.
Use the Column, Operator, and Value fields to define each filter. You can select Add Filter to apply multiple filters at the same time.
Filtering for Wildcard Certificates
A wildcard certificate secures multiple subdomains under a single primary domain. The wildcard character (*) appears in the certificate’s domain name.
For example, *.example.com secures:
- payment.example.com
- contact.example.com
- login-secure.example.com
- www.example.com
To filter for wildcard certificates:
- Select Certificate Name as the column.
- Choose contains as the operator.
- Enter an asterisk (*) as the value.