Installation and setup
Requirements
Windows Server 2016 or newer, 64-bit, Desktop or Server Core (TLS 1.3 from Server 2022, otherwise TLS 1.2); member of an AD domain for "Sign in with Windows"; 2 vCPU, 4 GB RAM; no .NET installation needed (self-contained); install as local administrator.
Firewall matrix
| Direction | From → To | Port | Purpose | Required |
|---|---|---|---|---|
| inbound | admin workstations → certmon server | TCP 8443 (/PORT) | dashboard (HTTPS) | yes – the installer creates a rule for the domain profile |
| outbound | certmon server → api.polar.sh | TCP 443 | license activation and check (about every 30 days) | no – offline activation with a license file |
| outbound | certmon server → domain controllers | Kerberos (88), LDAP (389) | Windows sign-in and group name lookup only | only for Windows sign-in |
| outbound | certmon server → scan targets (network scan) | the configured ports (default 443, 8443, 4443, 9443, 10443, 5001, 8006, 636, 3269, 5986, 993, 995, 465, 3389) | TLS handshake to read the certificate; optionally one GET / for the page title; no sign-in | only when a network scan is set up |
| outbound | certmon server → domain controllers | Kerberos (88), LDAP (389, signed and sealed) | PKI monitoring: read the configuration partition (Public Key Services) | only with a PKI source |
| outbound | certmon server → certification authorities | RPC (TCP 135) + dynamic RPC ports | certutil -ping and reading the CA database (DCOM) | only with a PKI source |
| outbound | certmon server → CDP/AIA web servers | TCP 80/443 (the URLs in the certificates) | download CRLs and CA certificates, revocation check of the CA chains | only with a PKI source with network checks |
| outbound | certmon server → monitored Windows servers | TCP 5985 (WinRM, Kerberos-encrypted) or 5986 (WinRM over HTTPS) | reading over the JEA endpoint certmon.Reader | only with a server source |
| outbound | certmon server → monitored Windows servers | the ports of the bound services (443, 3389, 5986, 636 …) | TLS cross-check of the bindings, LDAPS of domain controllers | only with a server source with TLS check |
| outbound | certmon server → SMTP server | TCP 587 or 25 (STARTTLS) | e-mail notifications | only with an SMTP channel |
| outbound | certmon server → login.microsoftonline.com, graph.microsoft.com | TCP 443 | e-mail over Microsoft 365 (Graph) | only with a Microsoft 365 channel |
| outbound | certmon server → Teams workflow, webhook receiver | TCP 443 (HTTPS) | Teams and webhook notifications | only with the respective channel |
| outbound | certmon server → directory server (DC, OpenLDAP, FreeIPA) | TCP 636 (LDAPS) or 389 (StartTLS) | LDAP(S) sign-in | only when enabled |
No telemetry. No other outgoing connections; new sources (PKI, Windows servers, notifications) extend this table when they are added.
Service account
Default: virtual account NT SERVICE\certmon (the computer account on the network), nothing to prepare. Optional gMSA: create and install it (New-ADServiceAccount, Install-ADServiceAccount), grant "Log on as a service", register the HTTP SPNs of the server on the gMSA for Windows sign-in (setspn -S HTTP/<fqdn> DOMAIN\gmsa$, same for the short name) and install with /SERVICEACCOUNT="DOMAIN\gmsa$".
Permission model
certmon needs no domain admin rights. The service account (network access as the computer account, or a gMSA): read AD (default); CA permission "Read" on each enterprise CA; membership in certmon-Reader, which only opens the JEA endpoint certmon.Reader on the servers; nothing on network devices (TLS handshake only); optional: Graph app with Application Mail.Send scoped to one mailbox, an LDAP search account with read access, write access to the backup folder. Dashboard roles: viewer, operator (acknowledge, mute, run), administrator (sources, channels, rules), system administrator (users, groups, sign-in, license, certificate, backup) – checked on the server, audited.
Preparing PKI monitoring
certmon only reads the PKI. It needs: read access to AD (any domain account; the virtual service account uses the computer account), the Certification Authority Management Tools on the certmon server for the CA databases (Install-WindowsFeature RSAT-ADCS-Mgmt; the setup points out when they are missing) and the CA permission "Read" for the service account on every enterprise CA (CA console > CA properties > Security, add the certmon computer account or gMSA with "Read" only). No further rights, no remoting to the CA. Then add a source under Settings > PKI (Active Directory).
Preparing Windows server monitoring
certmon reads Windows servers only over the JEA endpoint certmon.Reader; see JEA endpoint for Windows servers: create an AD group with the certmon service account, run jea\Install-CertmonJea.ps1 -Account <group> on every server (e.g. via GPO), restart the certmon service once and add a source under Settings > Windows servers. The certmon server must be a domain member (Kerberos); no passwords are stored.
Proxy (optional)
Outgoing HTTPS (Microsoft 365, Teams, webhooks, license check, CDP/AIA downloads) can use a proxy: Settings > Proxy (system administrators) – system proxy, direct, or a configured proxy with exceptions and sign-in as the service account (Kerberos/NTLM) or a separate account (encrypted password). Changes apply immediately; Test connection checks the way to an address. SMTP, LDAP, WinRM and the network scan never use a proxy; Windows chain checks use the WinHTTP proxy (netsh winhttp set proxy).
Setting up notifications
Channels (SMTP, Microsoft 365, Teams, webhook), rules and maintenance windows under Settings > Notifications; see Notifications for the Microsoft 365 app registration and the Teams workflow. Enter the dashboard address to get links in the messages.
LDAP(S) sign-in (optional)
For clients outside the domain, under Settings > LDAP sign-in (system administrators): LDAPS (636) or StartTLS (389) only, with a trusted server certificate. Active Directory uses the same SID group mappings as Windows sign-in; OpenLDAP/FreeIPA need a search account and group mappings by distinguished name. TOTP applies to the same roles as Windows sign-in. Test sign-in checks an account without signing in.
Backup and restore
Settings > Backup (system administrators): download after re-entering the TOTP code, or daily into a folder (local or UNC, write access for the service account). The .cmbackup file holds the database and the secrets, encrypted with the backup password (Argon2id, AES-256-GCM). Port and dashboard certificate stay with the machine. Restore with the service stopped: certmon.exe --restore <file> (asks for the password, keeps the previous database, re-protects the secrets with this machine's DPAPI, event 1304). Backups of a newer certmon version are refused.
Interactive installation
Run certmon-setup-<version>.exe (Inno Setup, one file for German and English). The setup copies the program, registers the service certmon (automatic delayed start, restart on failure) and the event source certmon, prepares C:\ProgramData\certmon with administrator rights (ACL: SYSTEM, Administrators, service account only), creates the installation entropy and – unless a certificate is given – a self-signed dashboard certificate (RSA 3072, 2 years, FQDN and short name), creates the firewall rule (domain profile) and starts the service. The last page shows the dashboard address and where the one-time token is stored. If one of these steps fails, the setup names it; the files stay installed and running the setup again is enough (details in the /LOG file and the event log).
Silent installation
certmon-setup-0.9.0.exe /VERYSILENT /SUPPRESSMSGBOXES /NORESTART /LOG="certmon-setup.log" /PORT=8443 /LANGUAGE=en
certmon-setup-0.9.0.exe /VERYSILENT /SUPPRESSMSGBOXES /NORESTART /SERVICEACCOUNT="CORP\gmsa-certmon$" /CERTTHUMBPRINT=0123456789ABCDEF0123456789ABCDEF01234567Parameters: /PORT= (8443), /SERVICEACCOUNT= (NT SERVICE\certmon, gMSA as DOMAIN\name$), /CERTTHUMBPRINT= (certificate in LocalMachine\My with private key; the setup grants the service account read access to the key), /LANGUAGE= (de/en), /REMOVEDATA=1 (uninstaller only: also removes data and the self-signed certificate). An update without parameters keeps the previous values. Exit codes: 0 OK, 20 files installed but service, provisioning or firewall failed (see the log), other values are Inno Setup's codes.
Initial setup
- As local administrator read the one-time token:
Get-Content C:\ProgramData\certmon\setup-token.txt(event 1200 names the file, never the token). - Open
https://<server>:8443/setup, enter token, user name and password (at least 12 characters). - Set up the authenticator app (QR code, link or key) and confirm a code.
- Store the recovery codes safely – they are shown only once.
/setup is then locked for good and the token file deleted. The first user is system administrator and administrator.
Windows sign-in
Map groups to roles under Settings → AD group mapping (stored by SID; several domains/forests possible; without a mapping every Windows user is rejected). Administrators and system administrators additionally enter a TOTP code after Windows sign-in (configurable per role). Add the dashboard URL to the browser's intranet zone (AuthServerAllowlist policy for Edge/Chrome).
Replacing the dashboard certificate
Request a web server certificate from your CA (SAN: FQDN and short name), install it in LocalMachine\My, run "C:\Program Files\certmon\certmon.exe" --provision --certificate <thumbprint> as administrator (or select it under Settings → Dashboard certificate if the service can already read the key) and restart the service (Restart-Service certmon). No reinstallation needed.
Update, uninstall
Run the new setup (interactive or silent, no parameters needed): it stops the service, replaces the files and starts it again; data and settings are kept and certmon.db.bak-<version> is written before schema changes. Downgrades are refused. Uninstall via "Apps" or silently with "C:\Program Files\certmon\unins000.exe" /VERYSILENT /SUPPRESSMSGBOXES: removes program, service, event source and firewall rule; data is kept unless /REMOVEDATA=1.
Files, backup, troubleshooting
Program in C:\Program Files\certmon, data in C:\ProgramData\certmon (certmon.db, entropy.bin – secrets are lost without it, keys 0 , settings.json, logs` rotated daily, 30 days). Back up the whole data folder; secrets are bound to this server by DPAPI and must be re-entered after restoring on another server. Troubleshooting: event log source certmon (Windows event log), log files, /healthz (200 = OK, 503 = database not available), certmon.exe --console (stop the service first, run as administrator).
More documents
JEA endpoint for Windows servers
How certmon reads Windows servers only through a restricted PowerShell endpoint: setup, permissions, testing.
Notifications
Alert logic, email over SMTP or Microsoft 365, Microsoft Teams and webhooks with an HMAC signature.
Findings
Every finding id with its meaning and severity: network scan, PKI and Windows servers.
Windows event log
Event ids of the certmon source for RMM and SIEM systems, with query examples.