{% extends "base.html" %} {% block content %}

Operations

Monitoring settings

Configure expiry thresholds and notification delivery.

Checks and notifications

New findings, threshold escalations and recoveries create notifications. Unchanged findings are not sent again. Changes take effect on the next check.

Checks and thresholds

Checks use the publication CRL URLs or the public base URL. They verify reachability, signature, expiry, CRL number and known revocations, including archived CAs until expiry. HTTP(S) redirects are rejected. HTTPS must be trusted by this host. Intranet addresses are supported; loopback, link-local and metadata addresses are blocked.

Email

Use plain email addresses, up to ten comma-separated recipients. Leave the username blank for a TLS relay without authentication. Re-enter the password when changing the SMTP server or account.

Webhook

PKIMaster sends JSON with an events array. Each event has a stable id, status, severity, title, detail and changed_at timestamp. Accept with HTTP 2xx. Retries use the same event ids and an Idempotency-Key header; receivers should deduplicate them.

Only the selected notification channel is used. Credentials are stored encrypted and never displayed. Saving settings does not send a message; Run checks now sends pending findings through the selected channel.

Back to monitoring
{% endblock %}