4. Host Monitoring
Monitor TLS certificate expiry, deployment, and trust problems.
CertKit monitors TLS hosts to verify that each endpoint is reachable and serving a valid certificate that matches your configuration. Monitoring is independent of issuance, so you can monitor a host even if CertKit doesn’t manage its certificate.
Public hosts are checked from the CertKit cloud. Hosts that are only reachable on your private network can be checked by a CertKit agent; see Intranet Host Monitoring.
Monitored Hosts List
Use the grouping options to audit your endpoints:
- Grouped by Root Domain: If you have many subdomains, group by root domain to see related hosts together.
- Grouped by Certificate: See all hosts that use a given certificate and confirm that they are using the latest version.
- Grouped by Status: Prioritizes failing endpoints for troubleshooting.
Linked vs. Monitoring-Only (Unmanaged Certificates)
When you monitor a host, you can associate a specific CertKit certificate with it. In addition to monitoring expiry and certificate validity, CertKit ensures that the endpoint is presenting the latest issued leaf certificate. This catches cases where renewal succeeded but deployment failed or updated the wrong endpoint.
- Linked: Connected to a CertKit-managed certificate. An expired certificate, incorrect thumbprint, or missing SAN changes the host status to yellow or red.
- Monitoring-only: Use this for third-party or legacy endpoints. CertKit catches common certificate problems and watches expiry, but does not require the host to present a specific CertKit-issued certificate.
Host Detail
The detail page provides a 90-day chart of observed time-until-expiry. A marker is placed whenever a new certificate is detected.
Alerts
If a host’s certificate gets too close to expiry, CertKit starts sending emails to users configured to receive those alerts in the Certificate Collection. For 90-day certificates, alerts start at 25 days until expiry. Shorter-duration certificates alert closer to expiry.