# KeyChest.net - a monitoring tool totally about keys and certificates

**URL:** <https://community.letsencrypt.org/t/keychest-net-a-monitoring-tool-totally-about-keys-and-certificates/37172>\
**Category:** Server\
**Created:** [June 30, 2017, 5:21pm UTC](https://community.letsencrypt.org/t/keychest-net-a-monitoring-tool-totally-about-keys-and-certificates/37172 "2017-06-30T17:21:57Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![DanCvrcek](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/dancvrcek/32/35672_2.png) [@DanCvrcek](https://community.letsencrypt.org/u/DanCvrcek)\
**Post date:** [June 30, 2017, 5:21pm UTC](https://community.letsencrypt.org/t/keychest-net-a-monitoring-tool-totally-about-keys-and-certificates/37172/1 "2017-06-30T17:21:57Z")

</div>

[https://keychest.net](https://keychest.net)

It’s in beta and we still need to shape it to give you most value free of charge.

The list of features will be quickly evolving over the next month or so. Currently, we show a 12 months’ plan, short-term 28 days list of task, info from direct connections to servers, as well as CT logs, some basic stats/information.

We have just now (10 July, 18 pm GMT) published a big upgrade of KeyChest. Two major new features improve automation and quick enrollment:

1. Bulk import of domains/servers - copy&paste of up to 100 servers; and
2. “Active Domains”, where KeyChest automatically registers new servers in a given domain. If you switch on the Watch Now feature, new servers will be automatically included in your Dashboard.
3. TLS handshake scanner now also supports servers with IPv6 only!

Note: we have temporarily limited the number of servers you can monitor to 4,000 to keep the service running.

[https://vimeo.com/228584972](https://vimeo.com/228584972)

 ![](https://global.discourse-cdn.com/letsencrypt/original/2X/5/592b42be09aba7f9e2a2f619b4264f878d0ec331.png)

 ![](https://global.discourse-cdn.com/letsencrypt/original/2X/7/76593926fb98d189835841edea0eb15d9e9ef675.png)

 ![](https://global.discourse-cdn.com/letsencrypt/original/2X/b/b38b9249cc3a432d33263266202e9d65da4409c6.png)

---

<div class="post-metadata">

**Author:** ![DanCvrcek](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/dancvrcek/32/35672_2.png) [@DanCvrcek](https://community.letsencrypt.org/u/DanCvrcek)\
**Post date:** [July 1, 2017, 9:18pm UTC](https://community.letsencrypt.org/t/keychest-net-a-monitoring-tool-totally-about-keys-and-certificates/37172/2 "2017-07-01T21:18:29Z")

</div>

Just a thought - would anyone be interested in an API for automation?

---

<div class="post-metadata">

**Author:** ![DanCvrcek](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/dancvrcek/32/35672_2.png) [@DanCvrcek](https://community.letsencrypt.org/u/DanCvrcek)\
**Post date:** [July 4, 2017, 8:30am UTC](https://community.letsencrypt.org/t/keychest-net-a-monitoring-tool-totally-about-keys-and-certificates/37172/3 "2017-07-04T08:30:20Z")

</div>

Just reached 200 registered users. Thank you all!

---

<div class="post-metadata">

**Author:** ![kuriot](https://avatars.discourse-cdn.com/v4/letter/k/e480ec/32.png) [@kuriot](https://community.letsencrypt.org/u/kuriot)\
**Post date:** [July 6, 2017, 11:22am UTC](https://community.letsencrypt.org/t/keychest-net-a-monitoring-tool-totally-about-keys-and-certificates/37172/4 "2017-07-06T11:22:49Z")

</div>

Very nice and clean design. It would be nice to also have an option to check for domain expiery and all this in the same cool design. Thanks for nice tool!

---

<div class="post-metadata">

**Author:** ![DanCvrcek](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/dancvrcek/32/35672_2.png) [@DanCvrcek](https://community.letsencrypt.org/u/DanCvrcek)\
**Post date:** [July 6, 2017, 11:36am UTC](https://community.letsencrypt.org/t/keychest-net-a-monitoring-tool-totally-about-keys-and-certificates/37172/5 "2017-07-06T11:36:55Z")

</div>

> [@kuriot](#):
>
> check for domain expiery

Thanks!

This feature is coming soon - probably next week. If there are certificates expiring within 28 days (or if there's a problem with a server), KeyChest will send an email once a week with an overview of all certificates that need attention.

The next upgrade (tomorrow) will include automatic discovery of servers within a given domain.

---

<div class="post-metadata">

**Author:** ![kuriot](https://avatars.discourse-cdn.com/v4/letter/k/e480ec/32.png) [@kuriot](https://community.letsencrypt.org/u/kuriot)\
**Post date:** [July 6, 2017, 11:40am UTC](https://community.letsencrypt.org/t/keychest-net-a-monitoring-tool-totally-about-keys-and-certificates/37172/6 "2017-07-06T11:40:10Z")

</div>

> KeyChest will send an email once a week with an overview of all certificates that need attention.

That's exactly how our scripts work now but having a nice GUI is nice so keep good work!

---

<div class="post-metadata">

**Author:** ![DanCvrcek](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/dancvrcek/32/35672_2.png) [@DanCvrcek](https://community.letsencrypt.org/u/DanCvrcek)\
**Post date:** [July 7, 2017, 7:43am UTC](https://community.letsencrypt.org/t/keychest-net-a-monitoring-tool-totally-about-keys-and-certificates/37172/8 "2017-07-07T07:43:37Z")

</div>

> [@gonace](#):
>
> the simple part is "user groups"

Hi, and thank you very much!

Well, this kind of user group management goes a wee bit beyond what we are able to offer as a free cloud service. But we had many requests like this since the launch a week ago and will offer "enterprise" version soon - cloud as well as on-premise. Send me a message here, or email us: (support at [enigmabridge.com](http://enigmabridge.com)) if you're interested in that.

---

<div class="post-metadata">

**Author:** ![andreipoe](https://avatars.discourse-cdn.com/v4/letter/a/ecd19e/32.png) [@andreipoe](https://community.letsencrypt.org/u/andreipoe)\
**Post date:** [July 7, 2017, 7:32pm UTC](https://community.letsencrypt.org/t/keychest-net-a-monitoring-tool-totally-about-keys-and-certificates/37172/9 "2017-07-07T19:32:07Z")

</div>

@DanCvrcek do you have any plans to open source any of this?

---

<div class="post-metadata">

**Author:** ![DanCvrcek](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/dancvrcek/32/35672_2.png) [@DanCvrcek](https://community.letsencrypt.org/u/DanCvrcek)\
**Post date:** [July 7, 2017, 9:07pm UTC](https://community.letsencrypt.org/t/keychest-net-a-monitoring-tool-totally-about-keys-and-certificates/37172/10 "2017-07-07T21:07:24Z")

</div>

> [@andreipoe](#):
>
> any plans to open source any of this?

Thanks for the note!

At the moment, we are quite amazed by the positive response - number of users, feedback. We will definitely keep [keepchest.net](http://keepchest.net) free for the community with some new exciting features coming. We need to discuss whether we can build a business model for it - enterprise features / on-premise / ... . Open-source option in some form is on the table but we need a bit of time to decide.

---

<div class="post-metadata">

**Author:** ![andreipoe](https://avatars.discourse-cdn.com/v4/letter/a/ecd19e/32.png) [@andreipoe](https://community.letsencrypt.org/u/andreipoe)\
**Post date:** [July 7, 2017, 9:21pm UTC](https://community.letsencrypt.org/t/keychest-net-a-monitoring-tool-totally-about-keys-and-certificates/37172/11 "2017-07-07T21:21:38Z")

</div>

Sounds good. Thanks for all your work!

---

<div class="post-metadata">

**Author:** ![just\_insane](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/just_insane/32/14668_2.png) [@just\_insane](https://community.letsencrypt.org/u/just_insane)\
**Post date:** [July 8, 2017, 2:56am UTC](https://community.letsencrypt.org/t/keychest-net-a-monitoring-tool-totally-about-keys-and-certificates/37172/12 "2017-07-08T02:56:54Z")

</div>

That would be awesome. Makes it easy to pull subdomains/servers from places like CloudFlare.

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [July 9, 2017, 8:47pm UTC](https://community.letsencrypt.org/t/keychest-net-a-monitoring-tool-totally-about-keys-and-certificates/37172/13 "2017-07-09T20:47:07Z")

</div>

Nice tool.  
I’m in 🙂

---

<div class="post-metadata">

**Author:** ![DanCvrcek](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/dancvrcek/32/35672_2.png) [@DanCvrcek](https://community.letsencrypt.org/u/DanCvrcek)\
**Post date:** [July 12, 2017, 9:18pm UTC](https://community.letsencrypt.org/t/keychest-net-a-monitoring-tool-totally-about-keys-and-certificates/37172/14 "2017-07-12T21:18:12Z")

</div>

Added a cool automation to [https://keychest.net](https://keychest.net) - “Active Domains”. You enter your domain name, e.g. [letsencrypt.com](http://letsencrypt.com), and it will automatically find all servers that exist and start regularly searching for new servers with certificates.

 ![](https://global.discourse-cdn.com/letsencrypt/original/2X/e/ec9cb7f965e93204f319fb01d59f07acbe6360ca.png)

---

<div class="post-metadata">

**Author:** ![barsh](https://avatars.discourse-cdn.com/v4/letter/b/278dde/32.png) [@barsh](https://community.letsencrypt.org/u/barsh)\
**Post date:** [July 13, 2017, 2:43am UTC](https://community.letsencrypt.org/t/keychest-net-a-monitoring-tool-totally-about-keys-and-certificates/37172/15 "2017-07-13T02:43:22Z")

</div>

This service is awesome, thank you for creating it!  
One question, some of my domains show a DNS error yet I can’t find a way to get any details on what the error was. All certs were successfully verified so DNS lookup must have worked.

---

<div class="post-metadata">

**Author:** ![DanCvrcek](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/dancvrcek/32/35672_2.png) [@DanCvrcek](https://community.letsencrypt.org/u/DanCvrcek)\
**Post date:** [July 13, 2017, 6:28am UTC](https://community.letsencrypt.org/t/keychest-net-a-monitoring-tool-totally-about-keys-and-certificates/37172/16 "2017-07-13T06:28:59Z")

</div>

> [@barsh](#):
>
> some of my domains show a DNS error

DNS error should show when we can't resolve the server name. What may have happened was an IPv6 error. We have enabled IPv6 on KeyChest servers and didn't get round proper resolution that would check both - IPv6 and IPv4 - yet. I hope the next version will show more details.

But we also may have a bug in converting error codes into screen messages. Can you please drop me a message with a domain in question? I'd get back to you asap.

Thanks, we're glad you like it! Tell your friends 🙂

---

<div class="post-metadata">

**Author:** ![DanCvrcek](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/dancvrcek/32/35672_2.png) [@DanCvrcek](https://community.letsencrypt.org/u/DanCvrcek)\
**Post date:** [July 17, 2017, 10:21pm UTC](https://community.letsencrypt.org/t/keychest-net-a-monitoring-tool-totally-about-keys-and-certificates/37172/17 "2017-07-17T22:21:56Z")

</div>

We have now reached 8,000 monitoring targets, i.e., [KeyChest](https://keychest.net) now monitors 8,000+ servers.

We have optimized the backend and database, doubled CPU cores (again), and made some small improvements. We have now also agreed how to differentiate from and enterprise versions:

- on premise instances
- user/role management
- server/target subsets - for separate views of certificates relevant to different user roles/business units
- independent scanning agents
- …

Other than that, you get exactly the same information about your servers, and certificates, easiness of adding new servers and self-discovery of new ones, etc.

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [August 13, 2017, 8:54pm UTC](https://community.letsencrypt.org/t/keychest-net-a-monitoring-tool-totally-about-keys-and-certificates/37172/18 "2017-08-13T20:54:31Z")

</div>

How are this going with this project?

---

<div class="post-metadata">

**Author:** ![DanCvrcek](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/dancvrcek/32/35672_2.png) [@DanCvrcek](https://community.letsencrypt.org/u/DanCvrcek)\
**Post date:** [August 13, 2017, 9:12pm UTC](https://community.letsencrypt.org/t/keychest-net-a-monitoring-tool-totally-about-keys-and-certificates/37172/19 "2017-08-13T21:12:32Z")

</div>

A break due to DEFCON/BlackHat presentations. But we stabilized the performance and reliability. We have a couple of large customers with 3,000+ servers monitored - great for ironing out UI. Overall, KeyChest now monitors 15,000 servers and analyses 85,000 certificates for over 600 users.

The latest update was on Thursday and we expect weekly updates for a month now or so. Interestingly, with active domains, the problem is not to add servers, but to remove them 🙂

The current priority is a couple of enterprise features - user/role management for teams, and IP-based scanning.

The free version will start showing results for all detected IP addresses and allow entry of custom IP address for servers behind CDN.

oh yeah - [a 49 second video of what it looks like using KeyChest is at Vimeo](https://player.vimeo.com/video/228584972?autoplay=1).

---

<div class="post-metadata">

**Author:** ![DanCvrcek](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/dancvrcek/32/35672_2.png) [@DanCvrcek](https://community.letsencrypt.org/u/DanCvrcek)\
**Post date:** [August 18, 2017, 9:52pm UTC](https://community.letsencrypt.org/t/keychest-net-a-monitoring-tool-totally-about-keys-and-certificates/37172/20 "2017-08-18T21:52:38Z")

</div>

Today, we have complete another upgrade at [https://keychest.net](https://keychest.net) . This one is not so visible from user interface but we completed weekly status emailing facility. Also:

1. It now works on IE10 and 11;
2. supports work with large hundreds/thousands of certificates - bulk actions, paging back and forward by 5 pages, …
3. a background video at [KeyChest Registration with video of inside](https://keychest.net/register) - so you can see what it looks like inside, before you “give us” your email address

Next update again in a week’s time or so.

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [August 18, 2017, 9:56pm UTC](https://community.letsencrypt.org/t/keychest-net-a-monitoring-tool-totally-about-keys-and-certificates/37172/21 "2017-08-18T21:56:18Z")

</div>

Excellent. Keep up the great work!

[Next page](https://community.letsencrypt.org/t/keychest-net-a-monitoring-tool-totally-about-keys-and-certificates/37172.md?page=2)
