Notifications

certmon reports findings over channels (e-mail over SMTP or Microsoft 365, Microsoft Teams, webhook); rules decide which findings go where (Settings > Notifications, administrators). Tag and owner filters use the effective values: the source's tags plus those of the device or server, and its owner, otherwise the source's (set on the device or server page; thresholds there and per tag under Settings > Monitoring, effective from the next run).

  • Alert logic: state changes (new, worse, better, resolved) once per rule and change; reminders before expiry (30/14/7/3/1 days) and daily while critical; escalation after X hours for findings nobody acknowledged; daily or weekly digest; maintenance windows and quiet hours postpone; signed one-time links (7 days) open the dashboard, the action requires a signed-in operator. Up to 5 delivery attempts, then event 1600.
  • SMTP: STARTTLS (587 or 25) with a trusted server certificate; no implicit TLS (465). Plaintext only through the explicit switch "send without STARTTLS" for internal relays, and only without sign-in (credentials are rejected and never sent); the channel is flagged "unencrypted" and the choice is audited.
  • Microsoft Graph: app registration, certificate in LocalMachine\My (preferred) or client secret; grant Application Mail.Send scoped to the sending mailbox with RBAC for Applications in Exchange Online (commands above) and do not consent Mail.Send in Entra ID (it would apply to all mailboxes).
  • Teams: Workflows template "Post to a channel when a webhook request is received"; the URL is a secret.
  • Webhook: JSON schema 1 (example above), HMAC-SHA256 over "{timestamp}.{body}" in X-Certmon-Signature (sha256=<hex>), timestamp in X-Certmon-Timestamp, delivery id in X-Certmon-Delivery. Verify on the raw body, compare in constant time, reject timestamps older than 5 minutes.
  • All channel secrets are encrypted (DPAPI) and never shown, logged or exported; outgoing TLS 1.2/1.3 only, certificate validation, no redirects.

More documents

  • Installation and setup

    Requirements, firewall, service account, permissions, setup (also silent), initial setup, update, backup and troubleshooting.

  • JEA endpoint for Windows servers

    How certmon reads Windows servers only through a restricted PowerShell endpoint: setup, permissions, testing.

  • Findings

    Every finding id with its meaning and severity: network scan, PKI and Windows servers.

  • Windows event log

    Event ids of the certmon source for RMM and SIEM systems, with query examples.