I spent years working at DigiCert and got frustrated watching SMBs get priced out of cert management tooling. With 47-day validity cycles coming, the problem gets worse — shorter lifetimes means manual management breaks down fast, especially for teams who don't have full inventory of what they've deployed.
So I built CertHound. Single Go binary, scans filesystem and Windows cert store, finds every cert on the host, reports expiry/SANs/fingerprints. ACME auto-renewal built in. Free and open source.
There's an optional managed dashboard for centralized fleet monitoring if you want it, but the agent works completely standalone.
keelw•1h ago
So I built CertHound. Single Go binary, scans filesystem and Windows cert store, finds every cert on the host, reports expiry/SANs/fingerprints. ACME auto-renewal built in. Free and open source.
There's an optional managed dashboard for centralized fleet monitoring if you want it, but the agent works completely standalone.
https://github.com/deadbolthq/certhound-agent