This article introduces SSL certificate tracking in InfraNest, for anyone who needs to make sure their domains stay securely protected without digging through servers or providers.
Overview
- Keeps one inventory of every certificate you have, no matter where it lives or who issued it
- Tracks expiry dates and warns you in good time, so an alert really means something needs attention
- Checks certificates are installed correctly and explains any problems in plain language
- Flags weak, misconfigured or unexpected certificates
- Shows which domains aren't covered so you can fix gaps quickly
See every certificate in one place
InfraNest automatically finds certificates from your monitors, scans, pasted certificates and connected providers, then combines them into a single, deduplicated list. You don't need to add anything yourself for certificates that are already being watched or scanned — they'll show up on their own.
Track expiry with confidence
- Open Certificates from the sidebar.
- Look at the Inventory tab to see all your certificates and their status.
- Certificates that renew automatically stay quiet until the very last moment — so if you get an alert about one of these, it means the renewal failed and needs your attention.
- Certificates with Nothing will renew this certificate are worth checking manually before they expire.
Check a certificate is installed correctly
- From the Certificates page, open the certificate you want to check.
- Review the Certificate chain section — InfraNest rebuilds it for you and shows Chain served, Missing intermediate, or similar labels.
- Look at Health and Security posture for a plain-language summary, including a Security rating {letter} and a {passed} of {total} passed count.
- Select Show the security checks to see the full breakdown, including Chain trust, Key strength, Signature algorithm, Validity period and Hostname coverage.
- If something's wrong, select How to fix this for guidance — for example, Download the issuing intermediate if the chain is missing one.
Find and fix coverage gaps
- Open Certificates and switch to the Coverage tab.
- Review the list of domains to see which are protected, expiring, or unprotected.
- Select Scan an endpoint on any domain to check its current certificate.
- Use Add SSL monitor if you want InfraNest to keep watching that domain going forward.
Understand what a certificate costs
- Open the certificate you're interested in.
- Check its Certificate price panel — it shows the Yearly price.
- Certificates from an issuer that doesn't sell them — Let's Encrypt, Cloudflare, Amazon and Google Trust Services — are automatically marked free from this issuer, so they won't appear in your Reports as an unfilled price.
- For anything else, select Add (or Edit) to enter what you actually pay.
NoteIssuers like ZeroSSL, Sectigo and DigiCert sell both free and paid certificates, so InfraNest won't guess a price for these — a blank price is a question, a wrong zero is a wrong answer.
TipA price you enter yourself always takes priority and will never be automatically overwritten.
Tips
- Use Search subject, issuer or SAN… on the Inventory tab to quickly find a specific certificate.
- Use Filter and Tags to narrow down long lists, and save your setup with Save view for next time.
- Select Issues only to see just the certificates that need attention.
Was this article helpful?