How is this different from a free online SSL checker?
An online checker tests one host, once, from the public internet, when you remember to go there. CertWatch keeps the list, rechecks it on a schedule, tells you when something changes, and can reach hosts that are not on the public internet at all — the appliance on your management VLAN, the internal API, the staging box behind the VPN. If you have three public domains and a good memory, the free checkers are genuinely fine.
Does it need anything installed on my servers?
No. It connects the way any client would, reads the certificate the server presents, and disconnects. Nothing is installed on the host, and no credentials are needed — a TLS certificate is public by design.
Can it renew certificates for me?
No, and that is deliberate. Renewal means holding credentials for your certificate authority and your DNS provider, and writing files onto production servers. CertWatch is a monitor: it tells you what needs attention and leaves the doing to you and to whatever already issues your certificates.
What does "untrusted" actually mean?
That the chain the server presented could not be validated against the system trust store. Usually a missing intermediate certificate — the leaf is fine, but the server was configured without the rest of the chain, so browsers that have cached the intermediate succeed and everything else fails. It can also mean a self-signed certificate, or an authority that has since been distrusted. CertWatch says which.
How does subnet scanning behave?
It walks the range you give it with a limit on how many connections run at once, so it does not look like a port scan to your own network gear and does not saturate a link. Hosts that do not answer on a TLS port are simply not listed.
Where do alerts go?
To a webhook URL you provide. Slack and Microsoft Teams incoming webhooks are supported directly; anything else receives a JSON body you can shape to your own endpoint. There is no MeshWatch relay in the middle — the request goes from your computer to your endpoint.
Does anything leave my computer?
Only the TLS connections to the hosts you added, the DNS lookups behind them, and alert webhooks if you configure one. The host list and results are stored in your home directory. There is no telemetry and no licensing callback.
How does Pro activation work?
After checkout you receive a licence key by email. It is sent from license@meshwatch.app, usually within a minute — if it is not in your inbox, check your Junk or Spam folder before writing to support. Paste it into the app and Pro unlocks on that computer. The key carries its own expiry date and is checked locally against a public key built into the app, so activation works offline. When you renew, a fresh key is emailed to you.
Does it work with MeshWatch Central?
Optionally. Connect CertWatch to your own MeshWatch Central server and its alerts join whatever ConfigWatch, DeviceWatch, TrafficWatch, SyslogWatch and TrapWatch are reporting into one shared inbox — a certificate expiring on the same host ConfigWatch just saw change shows up as one incident, not two unrelated alerts in two unrelated apps. CertWatch sends Central a one-line summary like “certificate expires in 4 days” — never the certificate itself, never a private key. Central is a separate product you run on your own server; CertWatch works exactly the same with or without it.