We built this for our internal use, but decided to make it our community project. It is highly scalable, free, and will always be free. It is a globally distributed monitoring service that checks for missing, expiring or misconfigured certs and alerts multiple recipients via SMS or email. This is intended to be a third-party supplement to the email expiration notifications LetsEncrypt already sends out.
With 90 day expirations, it can get a little tricky validating all your certs are up to date and functioning.
Registered an account and put one of my sites on. For some reason it queried a subdomain and was constantly alerting me of connection issues due to a certificate mismatch.
Very odd. No matter what method I use, Iām getting a cert back with the alternate names āmailā and ācalendarā. Iāve looked at the raw data and it is a different certificate than the one I get from a browser. Iām still looking into itā¦
Fails on most of my domains, as it doesnāt appear to correctly find the domain ( it looks as if it just checks the main certificate on that IP, not for the specific domain name )
I support the āpush your own CAā idea, also maybe you could try DANE validation if not done yet (I dont have a DANE yet, coz CF doesnt do that yet, sadly.
Any update on getting it to correctly recognise certificates ? of the initial 7 hosts I put in, it only recognises 1 which is on itās own IP ( the others are all on shared IP, and it doesnāt correctly check the cert )