Certificate expiry monitoring and alerting
aethercert watches every certificate in the inventory, every job and every agent, records what happened in one event log, and sends the events that need a person to the monitoring you already run.
The event log and expiry detection are included in every plan. Push integrations and the Prometheus endpoint require Pro, MSP or MSP Plus. See plans and limits
certificate.issuedapp.example.com · EC-256 · 90 daysagent web-012m agojob.succeededdeploy to nginx :443, reloadedagent web-012m agocertificate.renewed*.internal.corp via Corp Issuing CAagent adcs-011h agojob.retry_scheduledvpn.example.com deploy failed, retry 2/3agent ns-adc3h agocertificate.discoveredportal.example.com found on ns-adcscan6h agoWhat it does
A scanner checks continuously for certificates that are within 14 days of expiry or already expired - managed and discovered alike - and for agents that stopped checking in. Each condition becomes an event, and a matching resolved event follows when it clears.
Events land in the organization's event log with the actor that caused them. On Pro and MSP plans, the alert-worthy ones are pushed to a webhook, a syslog/CEF collector or an SNMP trap receiver, and fleet metrics are available as a Prometheus endpoint for CheckMK, Prometheus, Grafana or Zabbix.
How it works
- 01
Detect
Expiry and agent health are scanned on a fixed cadence; job, deployment and configuration changes are recorded as they happen.
- 02
Classify
A curated catalog decides each event's severity and whether it is pushed. Routine bookkeeping stays in the log only.
- 03
Deliver
Push integrations receive the event as JSON, CEF or an SNMP trap. Webhooks are HMAC-signed when you set a secret.
- 04
Resolve
When a certificate is renewed or an agent returns, a resolved event closes the condition.
Key capabilities
Expiry alerts
Expiring soon (14 days), expired and resolved, for every non-revoked certificate in the inventory.
Failure alerts
Failed jobs and failed deployments, after retries are exhausted, plus deployment rollbacks.
Agent health
Offline and back-online events for every agent.
Event log with actor
Who created, changed or deleted what - certificates, deploy targets, CAs, members - kept for 7, 30 or 90 days by plan.
Push integrations
Webhooks, syslog with CEF and SNMP traps for SIEM and NOC tooling.
Prometheus metrics
Certificates by status and expiry bucket, agents by status, job outcomes and heartbeat age - with no per-certificate labels.
Compared with checking by hand
| By hand | With aethercert |
|---|---|
| Calendar reminders for each expiry date. | Expiry is checked continuously and resolved automatically after renewal. |
| A failed renewal script fails silently. | A failed job produces a critical event and a push notification. |
| No record of who changed a certificate or deployment. | Every change is in the event log with its actor. |
Works with your monitoring
Anything that accepts a webhook, syslog/CEF or SNMP traps, and anything that scrapes Prometheus metrics.
Security considerations
Signed webhooks
With a shared secret set, every webhook delivery is HMAC-signed, so the receiver can verify it came from aethercert.
Scoped metrics keys
The metrics endpoint uses its own API key, separate from user sessions, created by an admin.
Low-cardinality metrics
Metrics carry no certificate names, agent IDs or email addresses - per-entity detail stays in the dashboard.
Example: an expiring certificate reaches your SIEM
A discovered certificate on a server nobody remembered.
scanportal.example.com is found 13 days before expiry.eventcertificate.expiring_soon (warning) is written to the event log.pushThe event is sent to your syslog collector in CEF format.resolveAfter a managed replacement is deployed, certificate.expiry_resolved follows.
Frequently asked questions
Monitoring and alerting
Do I get an email when a certificate is about to expire?
Expiry events are recorded in the event log on every plan and pushed to your webhook, syslog/CEF or SNMP receiver on Pro and MSP plans. aethercert does not send expiry warnings to users by email.
Can I use CheckMK, Zabbix or Grafana?
Yes. Point them at the Prometheus-format metrics endpoint with an API key; the documentation has examples for each.
How long is the event log kept?
7 days on Community, 30 days on Standard and 90 days on Pro and MSP plans.
Know before a certificate lapses
Every certificate in the inventory is watched from the first scan.
Community plan, no card required. Open registration - your account is ready in a few minutes.