InfraNestInfraNest

SSL certificates

About SSL certificates

InfraNest keeps a single inventory of all your SSL/TLS certificates — wherever they live and whoever issued them — tracks when they expire, checks they're…

SSL/TLS certificates keep the connections to your websites and services secure — this article explains how InfraNest helps you track and manage all of them, and is written for anyone responsible for keeping domains protected, not just technical specialists.

Overview

  • InfraNest keeps a single, deduplicated inventory of every certificate you have, no matter where it lives or who issued it.
  • It tracks expiry dates and warns you before something breaks — auto-renewing certificates stay quiet unless a renewal actually fails.
  • It checks that certificates are installed correctly, flags weak or misconfigured setups, and shows you which domains have no protection at all.
  • It can also catch certificates issued for your domains that you didn't request, which may be a sign of a security problem.

Find all your certificates

  1. Open Certificates from the sidebar.
  2. Use the Inventory tab to see every certificate InfraNest has found — through monitors, scans, pasted certificates and connected providers.
  3. Use Search subject, issuer or SAN… to find a specific certificate, or use Filter and Tags to narrow the list.
  4. Select View details on any certificate to see its full Certificate chain, Health and history.

NoteCertificates found in more than one place are automatically combined into a single entry, so you won't see duplicates.

Check domain coverage

  1. Open Certificates, then select the Coverage tab.
  2. Review the list to see which domains are covered, which are Approaching expiry, and which have No SSL monitor.
  3. Select Scan next to any domain to check it immediately, or use Scan an endpoint to check a specific address.
  4. Select Add SSL monitor to start tracking a domain that isn't monitored yet.

Review a certificate's health

  1. Open Certificates and select a certificate to view its Details.
  2. Select Show the security checks to see the full breakdown, including Chain trust, Key strength, Signature algorithm, Validity period and Hostname coverage.
  3. Look at the Security rating {letter} and {passed} of {total} passed summary to understand overall Security posture.
  4. If an issue is found, select How to fix this for plain-language guidance — for example, when the Chain is incomplete or untrusted or a certificate has a Weak key or signature.

TipIf a certificate shows Nothing will renew this certificate, set a reminder to replace it manually before it expires — InfraNest won't renew it for you.

Troubleshooting

  • Missing intermediate — the certificate chain is incomplete; select Download the issuing intermediate to fix it.
  • Untrusted root or Not trusted by browsers (self-signed) — visitors will see security warnings; check with your certificate provider.
  • Unexpected issuance (CAA) — a certificate was issued by an issuer not listed in your DNS CAA records; review your CAA policy and use Manage CAA if needed.
  • Discovered, not monitored — InfraNest found a certificate but isn't actively tracking it yet; select Add SSL monitor to start monitoring it.

About SSL certificates

Related articles

Start in seconds

Bring your whole infrastructure into one modern dashboard.

Free plan · No credit card required · Set up in minutes