| ▲ | jcgl 4 hours ago | |||||||
Looks like it relies on certificate transparency logs. That means that it won’t be monitor endpoints using wildcard certs. Best thing it could do would be to alert when a wildcard cert is expiring without a renewed cert having been issued. | ||||||||
| ▲ | lousken 4 hours ago | parent [-] | |||||||
Is that enough though? You may have wildcards on domains that are not even on a public DNS and you may forget to replace it "somewhere". For that reason it is better to either dump list of domains from your local DNS or have e.g. zabbix or another agent on every host machine checking that file for you. | ||||||||
| ||||||||