Skip to content

FAQ

Do I need a Sentinel, or is public scanning enough?

Section titled “Do I need a Sentinel, or is public scanning enough?”

Public scanning stops at your perimeter, so certificates on internal hosts, on disk and in Kubernetes secrets need What the Sentinel is. Most estates run both, and the two feed one inventory.

No. NoCert stores certificates, which are public documents, and never asks for a private key. A Sentinel that finds a key file beside a certificate reports one fact about it, whether any group or other bit is set on its mode, and sends neither the key nor its path. Privacy and data handling has the detail, including Kubernetes secrets.

No. NoCert observes certificates after issuance. Your CA, ACME client or certificate manager stays responsible for issuing, renewing and deploying them, and for the private keys.

No. A domain you add by hand is not scanned until you publish a DNS TXT record on it, which is proof you control it. See Monitor your first domain.

Rules fire on expiry only, alerts go out once a day rather than immediately, and five conditions silence a certificate before your rules are consulted. Notification rules lists them.

A certificate is still served but appears retired

Section titled “A certificate is still served but appears retired”

Retired means the certificate has been silent at this endpoint for six days or more. A few enterprise setups can make a live certificate look retired:

  • Multi-vhost SNI. A different certificate is served depending on the name requested, and the matching one is not probed every cycle.
  • Anycast or multi-POP. NoCert reaches a different POP than the one serving that certificate.
  • A drained backend. The load-balancer member holding it is weighted out.

The timestamp next to the dot is the ground truth: the last time NoCert saw that certificate there. If you expect it to be live, check the Sentinel covering the endpoint, or how NoCert reaches it from the internet.

Each distinct leaf certificate seen deployed in the last six days counts once, however many endpoints, files or secrets expose it. CA certificates never count, and going over the included volume blocks nothing. Plans and billing covers the rest.

Do Sentinels need an inbound firewall rule?

Section titled “Do Sentinels need an inbound firewall rule?”

No. A Sentinel opens outbound HTTPS on TCP 443 and listens on nothing. Forward proxies are supported. See Install the Sentinel.

No, OpenID Connect only. Single sign-on covers the setup.

Business plans export compliance evidence as CSV, in five datasets that follow whatever access the person has, and any plan downloads a single certificate in PEM or DER. See TLS compliance policies.

The activity log has no export and is kept for 12 months. If you need audit history beyond that, tell us before you rely on it.