CC · Core Concepts
Certificates
Tracking expiring certs, certifications and app credentials.
3 min read
Certificates is three related things under one section, split into tabs. Certificates covers digital certificates — TLS/SSL server certs, wildcard certs, SAN certs, code-signing and client certs — with issuer, common name, type and expiry. Certifications covers organisational compliance certifications like ISO 27001, SOC 2, or Cyber Essentials Plus, tracked with a certificate number, auditor, and scope rather than a technical issuer. App Credentials is a read-only tab holding the Entra app-registration secrets and certificates your Microsoft 365 sync discovered. Every record in all three tabs must have an expiry date — that date is the whole point of the record.
- 01
Certificates tab — digital certificates
Tracks TLS wildcard, server, SAN and intermediate CA certificates: issuer (e.g. DigiCert, Let's Encrypt), common name, type, status and expiry date.
- 02
Certifications tab — compliance certifications
Tracks audit-based certifications like ISO 27001, ISO 9001, SOC 2 Type II, or Cyber Essentials Plus: certificate number, auditor, scope, status and expiry.
- 03
App Credentials tab — Microsoft 365 app secrets
Read-only. Client secrets, X.509 key credentials and SAML token-signing certificates found on your tenant's app registrations and enterprise apps, so an expiring integration credential or SSO signing cert surfaces the same way a software renewal does. These appear only once Microsoft 365 is connected, and can't be created, edited or deleted by hand.
- 04
Add a certificate or certification
Use Add Certificate from the Certificates or Certifications tab. The fields adjust depending on which type you're adding. You don't set a status — AssetSort derives it from the expiry date: Valid, Expiring once the date falls inside your expiry lead time, and Expired once it's passed.