> ## Documentation Index
> Fetch the complete documentation index at: https://docs.snapsec.co/llms.txt
> Use this file to discover all available pages before exploring further.

# Certificates

> Monitor SSL/TLS certificates, track expiry risks, and manage certificate lifecycle across your asset inventory.

## Overview

The **Certificates** section provides complete visibility into all SSL/TLS certificates discovered across your environment.\
It helps teams monitor certificate health, prevent expirations, and understand how certificates are connected to assets like subdomains and services.

<Frame caption="Certificates inventory showing status, issuer, validity period, and ownership">
  <img src="https://mintcdn.com/snapsec-23724fa2/YbhK-0qW9OFeSopg/images/aim/certs1.png?fit=max&auto=format&n=YbhK-0qW9OFeSopg&q=85&s=4c2b24467dd95491a7238ddbc6ba883a" alt="Certificates Inventory Table" width="1896" height="916" data-path="images/aim/certs1.png" />
</Frame>

***

## Dashboard View

The dashboard provides a high-level overview of certificate posture and expiry risks.

<Frame caption="Certificates dashboard showing validity, expiry timeline, and certificate authority distribution">
  <img src="https://mintcdn.com/snapsec-23724fa2/YbhK-0qW9OFeSopg/images/aim/certs2.png?fit=max&auto=format&n=YbhK-0qW9OFeSopg&q=85&s=1be3e300181c23e761b79418a14878de" alt="Certificates Dashboard View" width="1626" height="842" data-path="images/aim/certs2.png" />
</Frame>

### Key Metrics

* **Total Certificates** — All discovered certificates
* **Expired Certificates** — Certificates no longer valid
* **Expiring Soon** — Certificates nearing expiration
* **Valid Certificates** — Currently active and trusted certificates

***

## Key Insights

### Valid vs Expired

Quickly identify:

* Active certificates
* Expired certificates

Helps prevent downtime caused by missed renewals.

***

### Certificate Authority Distribution

Shows which providers are issuing certificates:

* Let’s Encrypt
* Google Trust Services
* GlobalSign
* Others

Useful for trust analysis and compliance tracking.

***

### Issuer Country

Breakdown of certificate issuers by country:

* Helps detect unusual or unexpected issuance sources

***

### Expiration Timeline

Visualizes when certificates will expire:

* Immediate (\< 1 month)
* Short-term (1–3 months)
* Mid-term (3–6 months)
* Long-term (> 6 months)

Critical for proactive renewal planning.

***

## Inventory Table

The certificates table is the primary view for managing certificate assets.

### Key Columns

| Column          | Description                               |
| --------------- | ----------------------------------------- |
| **Asset Value** | Domain or hostname using the certificate  |
| **Status**      | Certificate status (Valid, Expired, etc.) |
| **Issued By**   | Certificate authority                     |
| **Valid From**  | Certificate start date                    |
| **Valid Till**  | Expiration date                           |
| **Owner**       | Assigned owner                            |
| **Detected On** | First and last detection timestamps       |

***

## Certificate Detail View

Selecting a certificate opens a detailed asset view with full context.

<Frame caption="Certificate detail view showing metadata, ownership, and lifecycle status">
  <img src="https://mintcdn.com/snapsec-23724fa2/YbhK-0qW9OFeSopg/images/aim/inside-cert1.png?fit=max&auto=format&n=YbhK-0qW9OFeSopg&q=85&s=b51e24bc8184e8ee20ef58116b88fcb6" width="1656" height="866" data-path="images/aim/inside-cert1.png" />
</Frame>

***

## General Information

This section includes:

* **Asset ID**
* **Type (Certificate)**
* **Certificate Value (Fingerprint / Hash)**
* **Issuer Details** (CN, Organization, Country)
* **Last Checked Timestamp**
* **Certificate Status (Valid/Invalid)**
* **Associated Assets**
* **First Detected / Last Detected**

***

## Lifecycle Management

Each certificate can be assigned a lifecycle state:

* **Active** — Currently in use
* **Pending** — Newly discovered or under review
* **Staged** — Prepared but not fully active
* **Decommissioned** — No longer in use

This helps teams track operational status beyond technical validity.

***

## Ownership & Accountability

<Frame caption="Owner details including user, team, and department">
  <img src="https://mintcdn.com/snapsec-23724fa2/YbhK-0qW9OFeSopg/images/aim/inside-cert3.png?fit=max&auto=format&n=YbhK-0qW9OFeSopg&q=85&s=918ff0adc59d58022fcbd1f28dbe2220" width="1655" height="692" data-path="images/aim/inside-cert3.png" />
</Frame>

Certificates can be mapped to:

* **User**
* **Team**
* **Department**

Ensuring clear accountability for renewal and management.

***

## Security Insights

<Frame caption="Security panel showing vulnerability counts and severity distribution">
  <img src="https://mintcdn.com/snapsec-23724fa2/YbhK-0qW9OFeSopg/images/aim/inside-cert2.png?fit=max&auto=format&n=YbhK-0qW9OFeSopg&q=85&s=1c6972cd65741bf5c0577a10aea8131f" width="1646" height="863" data-path="images/aim/inside-cert2.png" />
</Frame>

The security section provides:

* Total vulnerabilities linked to the certificate
* Severity breakdown (Critical, High, Medium, Low, Info)
* Open vs closed vulnerabilities
* Aggregate CVSS score
* Remediation progress

***

## Asset Relationships

Certificates are linked to other assets such as:

* Subdomains
* Domains
* Applications

This helps understand **impact before rotation or removal**.

***

## Data Sources

Shows which adapter discovered the certificate (e.g., SSL cert scanner), helping validate data origin and reliability.

***

## Why This Matters

The Certificates module helps teams:

* Prevent outages caused by expired certificates
* Identify weak or misconfigured certificates
* Maintain trust and compliance standards
* Track ownership and accountability
* Understand certificate dependencies across assets

***

## Explore Live Demo

<Card title="Explore AIM Live — No Signup Needed" icon="wand-magic-sparkles" href="https://suite.snapsec.co/demo">
  Instantly explore how Snapsec AIM discovers, enriches, and tracks certificates and other assets in real time — all without creating an account.
</Card>
