Monitor private certificates with agents
June 24, 2026 · 4 min read
Not every certificate lives on the public internet. Internal APIs, admin panels, and service-to-service mTLS all rely on certificates that expire just as surely as your public ones — and are far easier to forget. With NxMon agents, those private certificates get the same proactive alerting as everything else.
How it works
Deploy the lightweight agent inside your network. It reaches the internal endpoints you point it at, reads their certificate chains, and reports expiry, issuer, and chain health back to NxMon over an outbound, authenticated connection. No inbound firewall rules required.
One dashboard for everything
Private and public certificates show up side by side. Alerts, escalation policies, and notification channels work identically no matter where the certificate lives.
Getting started
Create an agent under Settings → Agents to receive a scoped enrollment token, run the agent, and assign it the internal domains you want watched.