Show HN: Automatic Discovery for Let's Encrypt Certificate Monitoring
keychest.net
keychest.net
Still working on this - it's incredibly hard to reach out to people who need this kind of tool.
BTW: if you signup and want to remove your account later, just drop us a line at support@enigmabridge.com .
Demo video: https://vimeo.com/228584972
It is a cert expiry monitoring tool (but it does more thorough checks in regular intervals as well). In terms of main features:
Spot Checks (no sign-up needed - you can test it at https://keychest.net - an instant feedback to get the configuration of a new server right as quickly as possible. It will tell you if your server uses the correct certificate, whether it sends a complete trust chain, the HSTS configuration, or whether IPv6 works as expected (9-10 basic tests to verify your config).
Server/domain enrolment - a) a server at a time (URL & port), b) bulk enrol (50 servers at a time, one per line) c) "active domain" - you set your domain name, KeyChest will automatically discover and keep discovering all servers/certs in all sub-domains.
Scanning & monitoring - DNS resolve, discovery of new certificates, direct tests of servers (TLS handshakes) - intervals are described in the User Manual inside your account.
Enterprise features (user management, internal networks, custom root certs, independent scanners) are not available here.