Installation and setup

Requirements

Windows Server 2016 or newer, 64-bit, Desktop or Server Core (TLS 1.3 from Server 2022, otherwise TLS 1.2); member of an AD domain for "Sign in with Windows"; 2 vCPU, 4 GB RAM; no .NET installation needed (self-contained); install as local administrator.

Firewall matrix

DirectionFrom → ToPortPurposeRequired
inboundadmin workstations → certmon serverTCP 8443 (/PORT)dashboard (HTTPS)yes – the installer creates a rule for the domain profile
outboundcertmon server → api.polar.shTCP 443license activation and check (about every 30 days)no – offline activation with a license file
outboundcertmon server → domain controllersKerberos (88), LDAP (389)Windows sign-in and group name lookup onlyonly for Windows sign-in
outboundcertmon server → scan targets (network scan)the configured ports (default 443, 8443, 4443, 9443, 10443, 5001, 8006, 636, 3269, 5986, 993, 995, 465, 3389)TLS handshake to read the certificate; optionally one GET / for the page title; no sign-inonly when a network scan is set up
outboundcertmon server → domain controllersKerberos (88), LDAP (389, signed and sealed)PKI monitoring: read the configuration partition (Public Key Services)only with a PKI source
outboundcertmon server → certification authoritiesRPC (TCP 135) + dynamic RPC portscertutil -ping and reading the CA database (DCOM)only with a PKI source
outboundcertmon server → CDP/AIA web serversTCP 80/443 (the URLs in the certificates)download CRLs and CA certificates, revocation check of the CA chainsonly with a PKI source with network checks
outboundcertmon server → monitored Windows serversTCP 5985 (WinRM, Kerberos-encrypted) or 5986 (WinRM over HTTPS)reading over the JEA endpoint certmon.Readeronly with a server source
outboundcertmon server → monitored Windows serversthe ports of the bound services (443, 3389, 5986, 636 …)TLS cross-check of the bindings, LDAPS of domain controllersonly with a server source with TLS check
outboundcertmon server → SMTP serverTCP 587 or 25 (STARTTLS)e-mail notificationsonly with an SMTP channel
outboundcertmon server → login.microsoftonline.com, graph.microsoft.comTCP 443e-mail over Microsoft 365 (Graph)only with a Microsoft 365 channel
outboundcertmon server → Teams workflow, webhook receiverTCP 443 (HTTPS)Teams and webhook notificationsonly with the respective channel
outboundcertmon server → directory server (DC, OpenLDAP, FreeIPA)TCP 636 (LDAPS) or 389 (StartTLS)LDAP(S) sign-inonly when enabled

No telemetry. No other outgoing connections; new sources (PKI, Windows servers, notifications) extend this table when they are added.

Service account

Default: virtual account NT SERVICE\certmon (the computer account on the network), nothing to prepare. Optional gMSA: create and install it (New-ADServiceAccount, Install-ADServiceAccount), grant "Log on as a service", register the HTTP SPNs of the server on the gMSA for Windows sign-in (setspn -S HTTP/<fqdn> DOMAIN\gmsa$, same for the short name) and install with /SERVICEACCOUNT="DOMAIN\gmsa$".

Permission model

certmon needs no domain admin rights. The service account (network access as the computer account, or a gMSA): read AD (default); CA permission "Read" on each enterprise CA; membership in certmon-Reader, which only opens the JEA endpoint certmon.Reader on the servers; nothing on network devices (TLS handshake only); optional: Graph app with Application Mail.Send scoped to one mailbox, an LDAP search account with read access, write access to the backup folder. Dashboard roles: viewer, operator (acknowledge, mute, run), administrator (sources, channels, rules), system administrator (users, groups, sign-in, license, certificate, backup) – checked on the server, audited.

Preparing PKI monitoring

certmon only reads the PKI. It needs: read access to AD (any domain account; the virtual service account uses the computer account), the Certification Authority Management Tools on the certmon server for the CA databases (Install-WindowsFeature RSAT-ADCS-Mgmt; the setup points out when they are missing) and the CA permission "Read" for the service account on every enterprise CA (CA console > CA properties > Security, add the certmon computer account or gMSA with "Read" only). No further rights, no remoting to the CA. Then add a source under Settings > PKI (Active Directory).

Preparing Windows server monitoring

certmon reads Windows servers only over the JEA endpoint certmon.Reader; see JEA endpoint for Windows servers: create an AD group with the certmon service account, run jea\Install-CertmonJea.ps1 -Account <group> on every server (e.g. via GPO), restart the certmon service once and add a source under Settings > Windows servers. The certmon server must be a domain member (Kerberos); no passwords are stored.

Proxy (optional)

Outgoing HTTPS (Microsoft 365, Teams, webhooks, license check, CDP/AIA downloads) can use a proxy: Settings > Proxy (system administrators) – system proxy, direct, or a configured proxy with exceptions and sign-in as the service account (Kerberos/NTLM) or a separate account (encrypted password). Changes apply immediately; Test connection checks the way to an address. SMTP, LDAP, WinRM and the network scan never use a proxy; Windows chain checks use the WinHTTP proxy (netsh winhttp set proxy).

Setting up notifications

Channels (SMTP, Microsoft 365, Teams, webhook), rules and maintenance windows under Settings > Notifications; see Notifications for the Microsoft 365 app registration and the Teams workflow. Enter the dashboard address to get links in the messages.

LDAP(S) sign-in (optional)

For clients outside the domain, under Settings > LDAP sign-in (system administrators): LDAPS (636) or StartTLS (389) only, with a trusted server certificate. Active Directory uses the same SID group mappings as Windows sign-in; OpenLDAP/FreeIPA need a search account and group mappings by distinguished name. TOTP applies to the same roles as Windows sign-in. Test sign-in checks an account without signing in.

Backup and restore

Settings > Backup (system administrators): download after re-entering the TOTP code, or daily into a folder (local or UNC, write access for the service account). The .cmbackup file holds the database and the secrets, encrypted with the backup password (Argon2id, AES-256-GCM). Port and dashboard certificate stay with the machine. Restore with the service stopped: certmon.exe --restore <file> (asks for the password, keeps the previous database, re-protects the secrets with this machine's DPAPI, event 1304). Backups of a newer certmon version are refused.

Interactive installation

Run certmon-setup-<version>.exe (Inno Setup, one file for German and English). The setup copies the program, registers the service certmon (automatic delayed start, restart on failure) and the event source certmon, prepares C:\ProgramData\certmon with administrator rights (ACL: SYSTEM, Administrators, service account only), creates the installation entropy and – unless a certificate is given – a self-signed dashboard certificate (RSA 3072, 2 years, FQDN and short name), creates the firewall rule (domain profile) and starts the service. The last page shows the dashboard address and where the one-time token is stored. If one of these steps fails, the setup names it; the files stay installed and running the setup again is enough (details in the /LOG file and the event log).

Silent installation

certmon-setup-0.9.0.exe /VERYSILENT /SUPPRESSMSGBOXES /NORESTART /LOG="certmon-setup.log" /PORT=8443 /LANGUAGE=en
certmon-setup-0.9.0.exe /VERYSILENT /SUPPRESSMSGBOXES /NORESTART /SERVICEACCOUNT="CORP\gmsa-certmon$" /CERTTHUMBPRINT=0123456789ABCDEF0123456789ABCDEF01234567

Parameters: /PORT= (8443), /SERVICEACCOUNT= (NT SERVICE\certmon, gMSA as DOMAIN\name$), /CERTTHUMBPRINT= (certificate in LocalMachine\My with private key; the setup grants the service account read access to the key), /LANGUAGE= (de/en), /REMOVEDATA=1 (uninstaller only: also removes data and the self-signed certificate). An update without parameters keeps the previous values. Exit codes: 0 OK, 20 files installed but service, provisioning or firewall failed (see the log), other values are Inno Setup's codes.

Initial setup

  1. As local administrator read the one-time token: Get-Content C:\ProgramData\certmon\setup-token.txt (event 1200 names the file, never the token).
  2. Open https://<server>:8443/setup, enter token, user name and password (at least 12 characters).
  3. Set up the authenticator app (QR code, link or key) and confirm a code.
  4. Store the recovery codes safely – they are shown only once.

/setup is then locked for good and the token file deleted. The first user is system administrator and administrator.

Windows sign-in

Map groups to roles under Settings → AD group mapping (stored by SID; several domains/forests possible; without a mapping every Windows user is rejected). Administrators and system administrators additionally enter a TOTP code after Windows sign-in (configurable per role). Add the dashboard URL to the browser's intranet zone (AuthServerAllowlist policy for Edge/Chrome).

Replacing the dashboard certificate

Request a web server certificate from your CA (SAN: FQDN and short name), install it in LocalMachine\My, run "C:\Program Files\certmon\certmon.exe" --provision --certificate <thumbprint> as administrator (or select it under Settings → Dashboard certificate if the service can already read the key) and restart the service (Restart-Service certmon). No reinstallation needed.

Update, uninstall

Run the new setup (interactive or silent, no parameters needed): it stops the service, replaces the files and starts it again; data and settings are kept and certmon.db.bak-<version> is written before schema changes. Downgrades are refused. Uninstall via "Apps" or silently with "C:\Program Files\certmon\unins000.exe" /VERYSILENT /SUPPRESSMSGBOXES: removes program, service, event source and firewall rule; data is kept unless /REMOVEDATA=1.

Files, backup, troubleshooting

Program in C:\Program Files\certmon, data in C:\ProgramData\certmon (certmon.db, entropy.bin – secrets are lost without it, keys0, settings.json, logs` rotated daily, 30 days). Back up the whole data folder; secrets are bound to this server by DPAPI and must be re-entered after restoring on another server. Troubleshooting: event log source certmon (Windows event log), log files, /healthz (200 = OK, 503 = database not available), certmon.exe --console (stop the service first, run as administrator).

More documents

  • JEA endpoint for Windows servers

    How certmon reads Windows servers only through a restricted PowerShell endpoint: setup, permissions, testing.

  • Notifications

    Alert logic, email over SMTP or Microsoft 365, Microsoft Teams and webhooks with an HMAC signature.

  • Findings

    Every finding id with its meaning and severity: network scan, PKI and Windows servers.

  • Windows event log

    Event ids of the certmon source for RMM and SIEM systems, with query examples.