# Keychest.net - spot checks and get organized for cert renewals

**URL:** <https://community.letsencrypt.org/t/keychest-net-spot-checks-and-get-organized-for-cert-renewals/35865>\
**Category:** Server\
**Created:** [June 10, 2017, 11:37am UTC](https://community.letsencrypt.org/t/keychest-net-spot-checks-and-get-organized-for-cert-renewals/35865 "2017-06-10T11:37:44Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![DanCvrcek](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/dancvrcek/32/35672_2.png) [@DanCvrcek](https://community.letsencrypt.org/u/DanCvrcek)\
**Post date:** [June 10, 2017, 11:37am UTC](https://community.letsencrypt.org/t/keychest-net-spot-checks-and-get-organized-for-cert-renewals/35865/1 "2017-06-10T11:37:44Z")

</div>

A cert monitoring tool with a twist - we will send weekly emails showing all your cert renewals due in next 28 days. It is free and remain FREE as a cloud service!

[https://keychest.net](https://keychest.net)

We can already use Spot Checks, launch of dashboards is imminent. Once functional, it will start picking up all new certificates for you domains and subdomains. If you launch a new server, it will appear in your next dashboard.

We try to show as little as possible but not too little - any feedback here is welcome 🙂

What it does - server and CT (certificate transparency checks)

- direct checks against your server (default is port 443, but you can change it for email server, or custom web applications); and
- certificate transparency (CT) logs, which contain all legitimate issued certificates that cause your browser show a green or a gray padlock.

If there’s a problem, between those two, you will see it.

The list of Spot checks include:

- time validity
- completeness of the certificate chain
- hostname checks
- TLS version
- neighbors - a list of all domain names (i.e., servers) included in the certificate
- downtime - how many hours / days you didnt have a valid cert in the last 2 years
- HSTS - we check if your web server prevents downgrade from HTTPS/TLS (HTTP Strict Transport Security flag)

Any thoughts what struggle and a cloud service could help you with - get in touch!

Cheers  
Dan

PS: It’s not quite relevant (a different project), but I’m still so excited I have to mention it. We will present at BlackHat US as well as DEFCON in 7 weeks’ time! Come, see our demonstration of multi-party computation and say hallo!

---

<div class="post-metadata">

**Author:** ![DanCvrcek](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/dancvrcek/32/35672_2.png) [@DanCvrcek](https://community.letsencrypt.org/u/DanCvrcek)\
**Post date:** [June 10, 2017, 7:59pm UTC](https://community.letsencrypt.org/t/keychest-net-spot-checks-and-get-organized-for-cert-renewals/35865/7 "2017-06-10T19:59:09Z")

</div>

> [@rg305](#):
>
> Interesting...  
> But I'm unable to reach some of your work, as the website security in somewhat restrictive:

Thanks so much for taking your valuable time to review our beta version! We have improved the web server TLS config and it should pass SSLLabs test with A+ now.

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [June 10, 2017, 8:01pm UTC](https://community.letsencrypt.org/t/keychest-net-spot-checks-and-get-organized-for-cert-renewals/35865/8 "2017-06-10T20:01:19Z")

</div>

I look forward to it 🙂

---

<div class="post-metadata">

**Author:** ![DanCvrcek](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/dancvrcek/32/35672_2.png) [@DanCvrcek](https://community.letsencrypt.org/u/DanCvrcek)\
**Post date:** [June 11, 2017, 8:05pm UTC](https://community.letsencrypt.org/t/keychest-net-spot-checks-and-get-organized-for-cert-renewals/35865/13 "2017-06-11T20:05:27Z")

</div>

We had a few questions / comments over the last two days. The most interesting turned out to be caused by our approach to scanning.

We take the address you enter as an address of a server and the spot check (as well as info in dashboards we are working on) tests this server.

This is somewhat different from other SSL scanners - e.g., [SSLLabs](https://www.ssllabs.com/ssltest/) - which follow redirects.

We decided to stick with our way, although dashboards will automatically add redirect servers to the list of certificates/servers to track.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [July 11, 2017, 8:05pm UTC](https://community.letsencrypt.org/t/keychest-net-spot-checks-and-get-organized-for-cert-renewals/35865/14 "2017-07-11T20:05:34Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
