View Certificates
The Qualys Certificate View application covers every SSL/TLS certificate across your enterprise and cloud-hosted managed assets. ETM integrates with Certificate View, so you can read those certificates here. ETM also shows certificates for unmanaged assets.
Navigate to: Inventory > Certificates
The Certificates tab, added under the Inventory tab, lists certificates for managed and unmanaged assets discovered from Cloud Agent, IP, and EASM inventory sources.
Use this to
- Track certificates that have expired or are about to expire.
- Find certificates by algorithm, key size, or certificate authority.
- Open a certificate to see its hosts, path, and raw content.
What you can do from the Certificates tab
- Certificate summary — a detailed summary of each certificate, such as the organization, the issuer's name, algorithm, and sources.
- Count tiles — the number of Expired, Expiring, Low Grade, and Qualys Renewable certificates.
- QQL search — find certificates using a Qualys Query Language (QQL) query.
- Left pane search criteria — summarize certificates by Expiring Certificates, Algorithm, Unique Key Size, and Certificate Authority.
For example, find the certificates that expire in 90 days, 60 days, or 30 days, or those that have already expired. Or find certificates that use a specified algorithm, such as MD5withRSA or SHA256withRSA.
- Quick operations — download the certificate data, refresh the certificates, and toggle the graph to show or hide the count tiles.
Use the Expiring Certificates search criteria to plan renewals on a regular cycle. For example, review the certificates that expire in the next 30 days at the start of each month.
View certificate details
Open a single certificate to read its full details. Certificate instance details, such as certificate name, protocol, and service, are on the Certificates tab of the Asset Details page.
Click View Details from the Quick Actions menu of the certificate. The details open on five tabs.
| Tab | What you see |
|---|---|
| Information | Whether the certificate is valid or expired, who it was issued by and issued to, Fingerprints details, and Certificate Details — Serial Number, Certificate Type, Key, Signature Algorithm, First Found, and Last Found dates.
This tab also shows Subject Alternative Names, Key usage, and Validity. |
| Hosts | The host and instance breakdown: the name of the asset associated with the certificate, sources, port, protocol, service, last found, and certificate grade. |
| Certificate Path | The certificate path detected on assets. |
| Raw | The raw certificate with its format, such as PEM. Download or copy the raw certificate from here. |
| Activity Log | Activity logs, such as when the certificate was issued and when it was approved. |
Use the Hosts tab to find every asset that presents a certificate before you replace it, so that no instance is missed during the renewal.