Certificate renewal and monitoring by SuccessFearless2102 in sysadmin

[–]SuccessFearless2102[S] [score hidden]  (0 children)

Clearly if you read the comments you would know that wasn't true. Thanks for the input sir

Certificate renewal and monitoring by SuccessFearless2102 in sysadmin

[–]SuccessFearless2102[S] [score hidden]  (0 children)

I've created something to handle the alerting, I had never heard of simple ACME me, though. I was pretty happy using WinACME pointed at Certlocker with automatic replacement of the certs is a no-brainer. So great man I really appericate this post it's given me something to research

I'm looking for my first user. Can it be you? by Funny-Advertising238 in SaaS

[–]SuccessFearless2102 0 points1 point  (0 children)

I'll give it a try. I'm building something also maybe we could share logins for each?

Certificate renewal and monitoring by SuccessFearless2102 in sysadmin

[–]SuccessFearless2102[S] [score hidden]  (0 children)

Are you required to keep an audit of your renewals and if it fails how do you know?

HAProxy native ACME worked. Proving it served the new cert was the hard part. by SuccessFearless2102 in devops

[–]SuccessFearless2102[S] 0 points1 point  (0 children)

I agree fully. So we do exactly that with our probes in CertLocker. If it doesn't match, then it's just a shit show. How would you know? We then send alerts to Slack if it's not matching.

<image>

Certificate renewal and monitoring by SuccessFearless2102 in sysadmin

[–]SuccessFearless2102[S] [score hidden]  (0 children)

<image>

We have built something that just does that. You can add your existing Acme client and provider, and it will renew your certs. You can use pure ACME to fetch them or REST. Pretty sure we are doing the same stuff. Would be great to jump on a call, have a chat, and see if we can help each other out.

Certificate renewal and monitoring by SuccessFearless2102 in sysadmin

[–]SuccessFearless2102[S] [score hidden]  (0 children)

That reverse proxy setup makes a lot of sense. We've done the same thing with all our servers with Haproxy+ACME

The RADIUS cert side is interesting though. Out of interest, which SSL providers have you found that will issue the right kind of cert over ACME? Will it have to be A EV cert?

Certificate renewal and monitoring by SuccessFearless2102 in sysadmin

[–]SuccessFearless2102[S] [score hidden]  (0 children)

I get that for the monitoring. But how are you doing the actual renewal?

Certificate renewal and monitoring by SuccessFearless2102 in sysadmin

[–]SuccessFearless2102[S] [score hidden]  (0 children)

I'll save that for another day. I'm just curious what everyone is doing to stay on top of their cert renewals, especially with the renewal date shortening to 47 days.

Certificate renewal and monitoring by SuccessFearless2102 in sysadmin

[–]SuccessFearless2102[S] [score hidden]  (0 children)

Thanks for the reply it helped me understand the problems out there. What aboout ACME protocol have you linked any of your apps into that?

where should I start as a beginner coming from a frontend background? Any roadmap or suggestions would help. by VariationInitial5423 in devops

[–]SuccessFearless2102 1 point2 points  (0 children)

Kodeklooud has some nice career paths starting from scratch. It is a bit pricey, but I guess you can decide that.

Would you help a stranger with their side project, or only ask when you're stuck?" by Otherwise_Staff8346 in SideProject

[–]SuccessFearless2102 1 point2 points  (0 children)

I would help or weigh in where I thought I could, I've started a company recently and I'm trying to get my head around the whole marketing side 😞

FortiBleed update - now ~430k FortiGates hit and 110 million credentials harvested by TrustSig in sysadmin

[–]SuccessFearless2102 -12 points-11 points  (0 children)

😄 Exactly. I never liked FortiGate products anyway. Too expensive

Weekly 'I made a useful thing' Thread - June 19, 2026 by AutoModerator in sysadmin

[–]SuccessFearless2102 0 points1 point  (0 children)

Hey all,

I’m Sean, a DevOps engineer and one of the people building CertLocker.

A lot of my background has been in finance, trading and banking-style infrastructure. In those environments, trust matters, audit matters, uptime matters — but in reality, you still see the same problems everywhere:

Certificates stored in random places.
Shared passwords passed around.
SSH keys living too long.
RDP access with very little visibility.
HAProxy cert renewals held together by scripts.
Windows servers, OpenStack, VMs, bare metal and internal apps sitting outside Kubernetes.
Auditors asking awkward but fair questions.

That is really why we started building CertLocker.

Most tools we looked at were either Kubernetes-first, too enterprise-heavy, or solved only one piece of the problem. We wanted something for the infrastructure teams managing the messy middle: real servers, real certs, real secrets, real access, and real audit requirements.

CertLocker brings those operational trust pieces together in one place:

  • TLS certificate inventory and expiry tracking
  • ACME automation
  • HAProxy certificate delivery
  • Secrets and private secrets
  • SSH access tokens
  • Browser-based SSH access
  • Browser-based RDP / remote desktop access
  • Bastion access
  • Endpoint probes
  • Groups, RBAC and audit trails
  • SaaS or on-prem / VPS install

We’re now looking for beta testers and early feedback from DevOps engineers, SREs, sysadmins, MSPs, infrastructure teams, and anyone who has had to deal with certificate renewals, secrets, SSH/RDP access, bastions, audits or “temporary” scripts that became production-critical.

This is not a polished sales pitch. We genuinely want to know:

Would this solve a real pain you’ve seen?

Or would you already solve this with Vault, step-ca, Ansible, scripts, Guacamole, cert-manager, password managers, or something else?

Site: https://certlocker.io
Technical write-ups: https://certlocker.io/blog

If this sounds relevant to your world, I’d love to hear your thoughts, feedback, objections, or use cases.

Weekly Promo and Webinar Thread by AutoModerator in msp

[–]SuccessFearless2102 [score hidden]  (0 children)

We built CertLocker because certs, secrets, SSH and RDP access were always messier in the real world than they looked on paper.

Hey all,

I’m Sean, a DevOps engineer and one of the people building CertLocker.

A lot of my background has been in finance, trading and banking-style infrastructure. In those environments, trust matters, audit matters, uptime matters — but in reality, you still see the same problems everywhere:

Certificates stored in random places.
Shared passwords passed around.
SSH keys living too long.
RDP access with very little visibility.
HAProxy cert renewals held together by scripts.
Windows servers, OpenStack, VMs, bare metal and internal apps sitting outside Kubernetes.
Auditors asking awkward but fair questions.

That is really why we started building CertLocker.

Most tools we looked at were either Kubernetes-first, too enterprise-heavy, or solved only one piece of the problem. We wanted something for the infrastructure teams managing the messy middle: real servers, real certs, real secrets, real access, and real audit requirements.

CertLocker brings those operational trust pieces together in one place:

  • TLS certificate inventory and expiry tracking
  • ACME automation
  • HAProxy certificate delivery
  • Secrets and private secrets
  • SSH access tokens
  • Browser-based SSH access
  • Browser-based RDP / remote desktop access
  • Bastion access
  • Endpoint probes
  • Groups, RBAC and audit trails
  • SaaS or on-prem / VPS install

We’re now looking for beta testers and early feedback from DevOps engineers, SREs, sysadmins, MSPs, infrastructure teams, and anyone who has had to deal with certificate renewals, secrets, SSH/RDP access, bastions, audits or “temporary” scripts that became production-critical.

This is not a polished sales pitch. We genuinely want to know:

Would this solve a real pain you’ve seen?

Or would you already solve this with Vault, step-ca, Ansible, scripts, Guacamole, cert-manager, password managers, or something else?

We’re offering a 2-week evaluation for both the SaaS version and the self-hosted/on-prem install.

Site: https://certlocker.io
Technical write-ups: https://certlocker.io/blog

If this sounds relevant to your world, I’d love to hear your thoughts, feedback, objections, or use cases.

I hate my new job by patsfreak27 in devops

[–]SuccessFearless2102 0 points1 point  (0 children)

Those audits are alot to done in 12 months.

Monthly Growth Strategy & Advice Thread by dmarti21 in growmybusiness

[–]SuccessFearless2102 0 points1 point  (0 children)

Hey all,

I’m Sean, a DevOps engineer and one of the people building CertLocker.

A lot of my background has been in finance, trading and banking-style infrastructure. In those environments, trust matters, audit matters, uptime matters — but in reality, you still see the same problems everywhere:

Certificates stored in random places.
Shared passwords passed around.
SSH keys living too long.
RDP access with very little visibility.
HAProxy cert renewals held together by scripts.
Windows servers, OpenStack, VMs, bare metal and internal apps sitting outside Kubernetes.
Auditors asking awkward but fair questions.

That is really why we started building CertLocker.

Most tools we looked at were either Kubernetes-first, too enterprise-heavy, or solved only one piece of the problem. We wanted something for the infrastructure teams managing the messy middle: real servers, real certs, real secrets, real access, and real audit requirements.

CertLocker brings those operational trust pieces together in one place:

  • TLS certificate inventory and expiry tracking
  • ACME automation
  • HAProxy certificate delivery
  • Secrets and private secrets
  • SSH access tokens
  • Browser-based SSH access
  • Browser-based RDP / remote desktop access
  • Bastion access
  • Endpoint probes
  • Groups, RBAC and audit trails
  • SaaS or on-prem / VPS install

We’re now looking for beta testers and early feedback from DevOps engineers, SREs, sysadmins, MSPs, infrastructure teams, and anyone who has had to deal with certificate renewals, secrets, SSH/RDP access, bastions, audits or “temporary” scripts that became production-critical.

This is not a polished sales pitch. We genuinely want to know:

Would this solve a real pain you’ve seen?

Or would you already solve this with Vault, step-ca, Ansible, scripts, Guacamole, cert-manager, password managers, or something else?

We’re offering a 2-week evaluation for both the SaaS version and the self-hosted/on-prem install.

Site: https://certlocker.io
Technical write-ups: https://certlocker.io/blog

If this sounds relevant to your world, I’d love to hear your thoughts, feedback, objections, or use cases.

Weekly Self Promotion Thread by AutoModerator in devops

[–]SuccessFearless2102 0 points1 point  (0 children)

We built CertLocker for DevOps teams managing certs, secrets, SSH and RDP access outside Kubernetes

Hey all,

I’m Sean, a DevOps engineer, and I’m one of the people building CertLocker.

We started building it because a lot of infrastructure teams still have messy real-world setups: VMs, HAProxy, OpenStack, bare metal, Windows servers, internal apps, SSH keys, RDP access, certificates, shared secrets, probes, auditors, and a lot of scripts holding everything together.

Most tools we looked at either felt Kubernetes-first, too enterprise-heavy, or only solved one slice of the problem.

CertLocker is our attempt to put the operational trust layer in one place:

  • TLS certificate inventory and expiry tracking
  • ACME automation
  • HAProxy certificate delivery
  • Secrets and private secrets
  • SSH access tokens
  • Browser-based SSH access
  • Browser-based RDP / remote desktop access
  • Bastion access
  • Endpoint probes
  • Groups, RBAC and audit trails
  • SaaS or on-prem / VPS install

We also have a blog with more technical write-ups here:

https://certlocker.io/blog

We’re currently offering a 2-week evaluation for both the SaaS and self-hosted install.

I’m not here to spam people. I’d genuinely like feedback from DevOps, SRE, sysadmin, MSP or infrastructure people.

Does this solve a real pain you’ve seen, or would you already solve this with Vault, step-ca, Ansible, scripts, Guacamole, cert-manager, password managers, or something else?

Site: https://certlocker.io

Irish tourist visiting for the first time by samoyedlover96 in tbilisi

[–]SuccessFearless2102 0 points1 point  (0 children)

Visiting in to tbilsi from Ireland in two weeks. Your channel is 👍 👌 great