GUIDES › CertWatch

Other languages English · 日本語 · 한국어 · 简体中文

CertWatch

TLS certificate expiry and trust monitoring — 0.4.5

In this version

Full release notes

1. Install

Pick the build for the machine you are installing on. Every file below is the current release; older versions are listed on the release notes page.

Verify what you downloaded. The published checksums are at CertWatch-SHA256SUMS.txt

On macOS or Linux:

shasum -a 256 CertWatch-0.4.5-arm64.dmg

On Windows:

Get-FileHash -Algorithm SHA256 CertWatch-0.4.5-x64.exe

The macOS build is notarised by Apple, so it opens without a warning. The Windows installer is Authenticode-signed and timestamped. The certificate is new, so SmartScreen may still show a warning until it has built reputation — if it does, choose More info → Run anyway.

2. First run

  1. Add the hosts you want watched, by name or CIDR range.
  2. CertWatch connects out over TLS the way any client would. Nothing is installed on the servers themselves.
  3. Press Scan now. Results are sorted by a 0–100 risk score so you read from the top and stop when you stop caring.

Every install starts with a 30-day trial of the paid edition. Nothing is asked for up front — no card, no account, no email address.

3. Administration

What the score means

Risk is a number, not a label. It exists to put the list in the right order: expired weighs most, then chain and hostname problems, then time remaining. A host that could not be reached has no score and sorts to the bottom — it is not the same as a healthy one.

Free and Pro

Free shows 3 hosts. Hosts beyond the third are still scanned and still stored — they are hidden until you upgrade, not skipped. A monitor that silently skipped hosts while looking like it was working would be the worst thing this could be. Pro adds scheduled rechecks, subnet scanning and webhook alerts.

Scheduled rechecks

Pro only. Manual rechecks are available on every tier.

Webhook alerts

Pro only. Enter an https:// URL under Alerts in the sidebar — tick Slack format for a Slack incoming webhook — and press Save; Send test posts a test message. The alerts from a scan are posted together in one request. If delivery fails, the sidebar shows Alert failed — and the reason, and those alerts are not kept as sent, so the next scan — scheduled or Scan now — sends them again. Since 0.4.4 an alert counts as sent only once delivery has succeeded.

Language

Settings → Language. English and Japanese. Certificate subjects, issuers and host names are shown exactly as the server returned them and are never translated.

Where your data lives

Everything CertWatch records stays on the computer it runs on. None of it is sent to us, to an analytics company or to an advertising network.

Licence keys

The key arrives by email after purchase. It is checked on this computer, so CertWatch never contacts a licensing server. When the 30-day trial ends, or a subscription lapses, CertWatch keeps watching 3 hosts on Free; subnet scanning, alerts and audit export stop.

4. Firewall

5. Connect to MeshWatch Central

Optional. Central gathers alerts from several products into one inbox and correlates them by device. Only alert summaries are sent to Central. Certificates and private keys are never sent — CertWatch never sees a private key in the first place.

  1. In Central, open Agents, choose CertWatch, type any label you like — it is just a name to tell installations apart — and press Issue token. The token is shown once.
  2. Pick CertWatch in that dropdown. A token belongs to the product it was issued for, and Central files every report under that product rather than under the application that sent it. A CertWatch installation given another product’s token connects and reports successfully, and its data appears under the other product while the CertWatch view stays empty — with no error at either end.
  3. In CertWatch, open the MeshWatch Central settings and enter Central’s address as http://<central-server>:8443 and the token. Use the server’s address, not localhost, unless Central runs on this same machine.
  4. Tick the box that sends alerts to Central, save, then press Test connection. It should report success.

Alerts raised from then on appear in Central. Past alerts are not backfilled. The full walkthrough is in the MeshWatch Central guide.

6. Troubleshooting

Nothing is arriving

The firewall is the usual reason — see section 4. After that, check that the device is pointed at this computer’s current local IP address; a DHCP lease can move it.

Test connection to Central fails

bad-token means the token is wrong or was revoked — issue a new one. unreachable means the address is wrong or a firewall is in the way; port 8443 must be open on the Central server. Note it is http://, not https://, unless you put a reverse proxy in front of Central. wrong-product means the token was issued for a different product; the message names which one. Issue a token for CertWatch instead and revoke the other. If the address looks right but Central is still unreachable, check it for a typo: most mistyped addresses are still valid addresses — 127.0.0.01 is read as 127.0.0.1 and 192.168.001.5 as 192.168.1.5 — so the connection quietly goes somewhere else. In the current releases these results are shown as sentences — a token Central refuses is explained as possibly revoked or issued by a different Central — and the code itself appears when you hover over the message.

Central shows this agent as “connected”, but nothing arrives

That is not a failure. connected means the test succeeded and nothing has been sent yet; the row switches to reporting on the first real report, because a product sends only when something happens. CertWatch switches to reporting after the first scan that finds something worth reporting. A row still reading waiting has never reached Central.

Problems that affect every product

A blank window after upgrading, Ubuntu 24.04 refusing to start the app, credentials stored as plain text on Linux without a keyring, alert email not being delivered — these are the same on every product and are collected on the support page.

Still stuck

Write to support@meshwatch.app with the version number and what you expected to happen. First reply within two business days, Monday to Friday.