Monopam · Certificate Manager

An expired certificate
is an outage. Never again.

Public TLS certificate lifetimes are shrinking toward 47 days — manual tracking is over. Monopam builds certificate lifecycle management (CLM) into your PAM: it discovers every certificate you own, issues from ACME, AD CS, or a built-in CA, and renews and deploys automatically. Agentless, approval-gated, audit-ready.

  • Agentless discovery & deployment
  • ACME + AD CS + built-in CA
  • Post-quantum readiness reports
What you get

Machine identities, managed like privileged ones.

The platform that brokers privileged access already reaches every server you run — Monopam uses that same agentless channel to manage the certificates on them.

Discover every certificate you own

TLS-handshake scanning across your network plus file-system and Windows certificate-store discovery over the Monopam Gateway — no agents to deploy.

  • Network scans by IP range, subnet, CIDR, and port
  • File-system and Windows cert-store discovery via SSH / WinRM
  • Scheduled re-scans keep the inventory current
  • Thumbprint-deduplicated inventory with per-endpoint locations

Issue from the CA you already trust

ACME for public certificates, Microsoft AD CS for the enterprise, a built-in private CA for everything internal — every request behind an approval workflow.

  • ACME with Let's Encrypt or any ACMEv2 endpoint (HTTP-01, DNS-01)
  • Microsoft AD CS integration and CSR generation
  • Built-in private CA: root, intermediate, and leaf
  • SCEP / EST device enrollment

Renew and deploy without agents

Renewal policies renew certificates before they expire and push them to the servers that use them — closing the loop that spreadsheets never could.

  • Automatic renewal policies with archive-on-replace
  • Linux deploy: PEM write + nginx / Apache reload
  • Windows deploy: PFX import, IIS binding, service restart
  • Renew-then-deploy as one closed loop

See risk before it becomes an outage

Expiry alerting is table stakes. Monopam also probes TLS configuration, watches CT logs, and reports on your post-quantum readiness.

  • Expiry digests at 30 / 14 / 7 / 1 days
  • TLS protocol probing from SSLv3 through TLS 1.3
  • Certificate Transparency log monitoring with alerts
  • Crypto-agility report: weak keys, SHA-1, quantum-vulnerable inventory
How it works

From spreadsheet to closed loop in three steps.

01

Scan

Point Monopam at your IP ranges and servers. Discovery builds a deduplicated inventory of every certificate, everywhere it lives.

02

Set policy

Map certificates to CAs, define renewal windows and approval gates, and choose deployment targets per certificate.

03

Automate

Monopam renews, deploys, reloads, and alerts — and your team stops chasing expiry dates in spreadsheets.

Ready to start managing
identities the right way?

Spin up a fully-loaded trial tenant in under five minutes. No credit card. No sales gate.