Latest release · Self-hosted · Docker amd64 & arm64

Status page for your TLS certificates

CertUI is a tiny, self-hosted status page for the certificates of the endpoints you track. See expiry at a glance, then expand any endpoint for its full certificate chain, TLS handshake, domain resolution and WHOIS. go Binary, declaratively configured with a YAML file.

Free & open source · Built with Go + Vue

localhost:8080
CertUI
TLS Version: 772 Handshake Complete: Yes Did Resume: No Cipher Suite: 4865

Peer Certificates

62 days 4 hours 51 min
Valid From: 2025-08-11T08:22:14Z
Valid To: 2025-11-07T09:16:03Z
Subject: CN=www.google.com
Issuer: CN=WR2,O=Google Trust Services,C=US
Signature Algorithm: SHA256-RSA Public Key Algorithm: ECDSA
999 days 2 hours 8 min
Valid From: 2023-12-13T09:00:00Z
Valid To: 2029-02-20T14:00:00Z
Subject: CN=WR2,O=Google Trust Services,C=US
Issuer: CN=GTS Root R1,O=Google Trust Services LLC,C=US
Signature Algorithm: SHA256-RSA Public Key Algorithm: RSA

WHOIS

Registrar: MarkMonitor Inc.
Name Servers: ns1.google.comns2.google.comns3.google.comns4.google.com
Expiration Date: 2028-09-14T04:00:00Z

Everything you need to watch your certificates

Purpose-built to do one job well: show the state of your TLS certificates, simply.

Expiry at a glance

Every configured endpoint gets a clear status badge — days remaining when healthy, a warning inside 30 days, and a red Expired flag once the leaf certificate lapses.

Full certificate chain

Expand any endpoint to walk the whole chain — subject, issuer, validity window, signature and public-key algorithm for the leaf and every intermediate.

TLS handshake details

See the negotiated TLS version, cipher suite, whether the handshake completed and whether the session resumed — straight from the live connection.

Domain resolution

Confirms each domain resolves and shows the address it points to, so a DNS or routing problem is obvious before you go hunting for it.

WHOIS lookup

Surfaces the registrar, name servers and domain expiration date — because a domain lapsing is just as bad as a certificate lapsing.

Deliberately minimal

CertUI keeps a tight scope on purpose:

  • No alerting — it is a status page, not a monitor
  • No external metrics — no API or Prometheus scraping
  • No history — it shows the certificates as they are right now

Install CertUI

Drop two files next to each other and bring it up. No database, no auth, no fuss.

compose.yml
services:
  certui:
    image: ghcr.io/ben-burwood/certui:latest
    container_name: certui
    restart: unless-stopped
    ports:
      - "8080:8080"
    environment:
      CERTUI_CONFIG_PATH: /config/config.yml
    volumes:
      - ./config:/config:ro
config/config.yml
# ./config/config.yml
endpoints:
  - https://www.google.com
  - https://www.github.com
  - https://expired.badssl.com
start it
$ docker compose up -d

Open localhost:8080. The config directory is mounted read-only; edit config/config.yml, then use the refresh button to re-probe. Results are cached for an hour.

Configuration
Key Default Description
CERTUI_CONFIG_PATH config/config.yml Path to a config file, or a directory of .yml / .yaml files that are merged together.
endpoints (required) YAML list of the URLs to track. Supports ${ENV_VAR} expansion; use $$ for a literal $.