Certificate intelligence
Expiry windows, SAN and hostname validation, issuer and fingerprint changes, chain checks, and TLS grading.
crt.watch monitors certificates, TLS posture, DNS drift, STARTTLS services, logins, public status pages, and notifications from one self-hosted operator interface.
The goal is a calm control room for certificate operations, not another noisy alert source.
Expiry windows, SAN and hostname validation, issuer and fingerprint changes, chain checks, and TLS grading.
HTTPS, TCP TLS, SMTP, IMAP, POP3, FTP, SSH, DNS, login checks, and STARTTLS/SSL transport modes.
Notification routing, deduplication, recovery messages, escalation timing, quiet hours, and maintenance windows.
Certificate Transparency watch, DNS resolver comparison, SSL Labs assessments, and change notifications.
Run it with Docker Compose, keep data in a local bind mount, and update with your existing Watchtower flow.
curl -fsSL https://raw.githubusercontent.com/brightcolor/crt.watch/main/scripts/quickstart.sh | sudo bash