Support and answers

CertStat FAQ

Practical guidance for monitoring certificate expiry, configuring warnings, and troubleshooting endpoints.

What does CertStat monitor?

CertStat connects to SSL/TLS endpoints, retrieves their certificates, and displays certificate expiry dates, remaining validity, issuer, common name, health status, and related TLS security details.

Can I monitor hostnames and IP addresses?

Yes. Add the hostname, fully qualified domain name, or IP address for the service you want to inspect. The endpoint must be reachable from your Android device when CertStat checks it.

Are custom ports supported?

Yes. Configure the port used by an endpoint when its TLS service is not on the standard HTTPS port. This is useful for NAS interfaces, reverse proxies, routers, development services, and internal applications.

How do expiration warnings work?

CertStat provides configurable warning, critical, and red alert thresholds. Daily background checks use these thresholds, and local notifications can alert you as a certificate moves into a more urgent window.

Does CertStat monitor in the background?

Yes. CertStat supports background certificate checks for proactive monitoring. Android battery and notification settings can affect background behavior, so allow notifications and review system restrictions if alerts do not arrive as expected.

Do I need an account or endpoint credentials?

CertStat uses a local-first design and does not require a CertStat account. Publicly presented TLS certificates normally do not require service login credentials; the endpoint only needs to be reachable for the TLS connection.

Can I organize a large endpoint list?

Yes. Create custom groups for customers, projects, teams, environments, or infrastructure types. Endpoints can also remain ungrouped, and the dashboard supports filtering.

Can I move my configuration to another device?

CertStat provides JSON import and export for saved FQDNs and groups. Runtime certificate status and notification history are not included in that transfer.

Does certificate data leave my device?

The Google Play data-safety declaration states that the app collects no data and shares no data with third parties. CertStat is described as local-first and checks the endpoints you configure.

Why is an endpoint unreachable?

Confirm the hostname or IP address, port, network route, and firewall rules. Internal services may require Wi-Fi or VPN access. Also verify that the service is actually presenting TLS on the configured port.

Why might an internal certificate fail validation?

Private certificate authorities, incomplete certificate chains, hostname mismatches, expired certificates, and self-signed certificates can all affect validation. Review the certificate details and compare the configured endpoint with the certificate's names.

Does CertStat replace an enterprise certificate-management platform?

No. CertStat is a practical mobile-first monitoring and inspection tool. It complements broader operational systems but is not positioned as a replacement for centralized enterprise certificate lifecycle management.

How can I get support?

Email reelmemories1987@gmail.com with your question and relevant troubleshooting details.

Ready to begin?

Add your first certificate endpoint.

Follow the concise setup guide to start monitoring.

Getting Started