Does anyone have any recommendations of a product or tool to help keep track of certificate expiration dates? We have a lot of certificates across the enterprise and tracking them all has proven challenging.

2k views1 Upvote5 Comments
Sort By:
Oldest
Principal Information Security Officer in Educationa year ago
https://letsmonitor.org/

This is a free web-based service that will check your website certificates and notify you via email or text.  You can set up multiple contacts.

There are many other standalone web certificate monitoring tools -- but these one has the least amount of setup and configuration.

It still only checks and notifies you that a certificate is expiring, it doesn't automatically renew a certificate.
Director of IT in Softwarea year ago
Check if the CA you are buying the certs from has a tool for this (assuming you are talking about publicly signed certs). There are 3rd part tools that you can install agents on the environment that will scan the endpoints, detect and report certs and some will even allow you to renew the certs. I use a tool from the CA itself, some 3rd part tools allow you to manage certificates from various CAs.
Tanium has a way to report certificates on the endpoints. Depending if the certs are only SSL and are on the NLBs/Webservers or are installed on the endpoints and how many certs you need to manage, you might need to buy a Certificate Lifecycle manager. Some tools can only manage publicly signed certs, some can do public and private certificates (from your own CA). Check AppViewX and DigiCerts, both are good. 
1
CTO for Digital & IT in Healthcare and Biotecha year ago
If like many of us you use ServiceNow, it added a certificate management module about 3 years ago. It's not as powerful as some solutions on the market, but it seems to cover the basics in terms of automation (including integration with some common public cert providers) and of course ties into the CMDB, since certs really should be CIs, and into your ITSM processes.
1
lock icon

Please join or sign in to view more content.

By joining the Peer Community, you'll get:

  • Peer Discussions and Polls
  • One-Minute Insights
  • Connect with like-minded individuals
CIO in Healthcare and Biotecha year ago
https://sectigo.com/ Venafi and AppViewX are good options
VP of Engineering in Bankinga year ago
- In my workplace, we use Datadog synthetic monitoring. If you're not using Datadog, I think there should be other alternatives as long as they support health check with certificate expiry date.
- A simpler rudimentary approach: have a central calendar and create a reminder every time we create/renew the certificate
1

Content you might like

TCO19%

Pricing26%

Integrations21%

Alignment with Cloud Provider7%

Security10%

Alignment with Existing IT Skills4%

Product / Feature Set7%

Vendor Relationship / Reputation

Other (comment)

View Results
5.7k views3 Upvotes1 Comment
Head of Enterprise Architecture MERCK Group in Healthcare and Biotecha year ago
Strategy & Architecture
Read More Comments
39k views5 Upvotes34 Comments

Human Factors (fears, mental health, physical spacing)85%

Technical / IT Factors (on-premise tools, pivoting back away from remote)14%

3.7k views3 Upvotes2 Comments
1.8k views2 Upvotes