Problems to Solve
Problems to Solve
Problem #33SourceRedditFriction Level: 8/10

Decentralized internal SSL certificate expiration tracking across legacy systems

1. The Problem — What is Difficult or Frustrating?
System administrators lack a centralized, foolproof way to inventory and track expiration dates for internal, self-signed, or isolated SSL certificates without complex enterprise PKI setups.
2. Who Experiences It — The Affected Audience

System administrators

3. The Proposed Tool — Specific Web App or Software Concept
A web application that passively scans internal network segments for exposed management interfaces (e.g., HTTP/HTTPS, SNMP, SSH) and extracts certificate metadata without credential injection.
4. Core Features & Architecture
1.
Network-based certificate fingerprinting

Scans for TLS endpoints (ports 443, 8443, etc.) and extracts certificate chains, issuer details, and expiration dates via passive probing.

SolvesEliminates the need for manual SSH/CLI checks by automating discovery of exposed certificates on legacy systems.
2.
Self-signed/isolated CA detection

Flags certificates not issued by public CAs or known internal PKIs, with optional manual override for false positives.

SolvesIdentifies internal self-signed certificates that are often overlooked in enterprise PKI tools.
3.
Expiration alerting with context

Generates alerts for impending expirations, including the certificate’s path (e.g., /etc/ssl/certs/) and associated service (e.g., Apache on host X).

SolvesProvides actionable context for administrators to locate and replace certificates before outages.
4.
Legacy protocol support

Handles deprecated protocols (e.g., SSLv3, TLS 1.0) and non-standard certificate formats (e.g., Java keystores, PEM files) via pattern matching.

SolvesCovers certificates on outdated systems that modern PKI tools ignore.
5. Potential Value — Operational Impact

Eliminates certificate-related outages for system administrators by surfacing hidden internal certificates and their expirations without manual intervention.

Limitations & Technical Boundaries
Cannot detect certificates on fully air-gapped systems or those behind authentication walls without pre-configured credentials. Also misses certificates not exposed via network services (e.g., internal Java truststores).
6. Suggested Validation Questions (Not Researched Facts)

Suggested exploration questions to confirm real demand, alternatives, and willingness to pay before building:

  • Demand question: How often do you discover SSL certificate expirations on legacy servers only after they’ve already caused service disruptions?
  • Possible existing alternatives to check: Tools like Certify The Web, DigiCert Certificate Utility, or OpenSSL-based scripts. Gap to test: whether these cover passive discovery of self-signed/internal CA certificates on non-agented appliances.
  • Willingness-to-pay question: What monthly price would you consider fair to eliminate the time spent manually hunting for internal certificate expirations across scattered systems?
Technical Feasibility & Platform Terms Risk

Access to internal network segments where appliances reside may require VPN or on-prem proxy configuration.

🛠️ Technical Blueprint & Implementation Concept
Build a React‑based SPA (create‑react‑app with TypeScript) that displays a dashboard of discovered certificates, uses Ant Design for tables and charts, and connects to a FastAPI backend (Python 3.11). The FastAPI service runs a Celery worker pool (Redis broker) that executes scan jobs. Scanning is performed by a Go binary compiled with the quic-go and crypto/tls libraries; it iterates over CIDR blocks supplied via a PostgreSQL‑backed schedule table, opens a TCP connection to each target port (443, 8443, 8445, 8446, 8447, 9443, 22 for SSH banner), performs a TLS handshake with InsecureSkipVerify, extracts the leaf certificate and full chain via tls.ConnectionState(). The Go binary also runs a lightweight packet‑capture mode using gopacket to sniff ServerHello messages on passive interfaces, allowing detection of certificates on devices that do not accept connections. Extracted PEM blobs are sent back to FastAPI over a gRPC endpoint (protobuf definitions for CertificateInfo). FastAPI stores metadata in a DuckDB file for fast ad‑hoc queries, and writes audit logs to Elasticsearch for alerting. Alerting uses the built‑in FastAPI background tasks to push notifications to a Slack webhook and to create incidents in ServiceNow via its REST API. The React UI polls a `/certificates` endpoint with server‑sent events (EventSource) for real‑time updates. Authentication is handled by OAuth2‑Proxy in front of the FastAPI service, integrating with the corporate IdP via OpenID Connect. Deployment uses Docker Compose for dev and Helm charts for production on a Kubernetes cluster, with the Go scanner running as a DaemonSet on nodes that have access to the internal VLANs.
📊 The Limitations of Current Alternatives
Existing scripts rely on explicit host lists and credentialed SSH access, so any service that does not expose a TLS endpoint remains invisible. Commercial PKI dashboards ingest only certificates issued by managed CAs, ignoring self‑signed or legacy keystores, and they require agents on each host, which legacy appliances cannot host. Spreadsheet‑based tracking introduces manual transcription errors and cannot correlate a certificate to its service context, forcing admins to log into each system to locate the file path. Moreover, tools that only perform active probing miss certificates that are only presented during specific protocol handshakes (e.g., SNMP over TLS), leading to blind spots in compliance reporting.
🎯 Key Engineering Value & Benefits
By automating passive discovery and correlating certificates to services, the tool eliminates repetitive SSH checks and reduces the mean time to detect expiring internal certificates from days to minutes. Centralized storage in DuckDB enables rapid queries for compliance audits without heavy ETL pipelines, and alert routing to Slack/ServiceNow prevents outages caused by missed renewals. The approach also lowers compute overhead because the Go scanner reuses existing network sockets and only parses TLS handshakes, avoiding full port scans on every run.
Relevant Platform Categories

Categories where this tool could be deployed or integrated.

Featured In Curated Collection

25 Tool Ideas for CRM Data Entry, Invoicing & Small Business Ops

Part of the Problems 26–50 collection published on Sep 26, 2026.

View Full 25-Idea Collection
Explore More

Related Problems to Solve

GitHubProblem #12
Friction: 6/10

Portable inventory management tool for e-commerce dissolution operations

The Problem

I wish there was a tool for getting and dissolving items. It would be convenient to have a portable tool that stores electricity for easy access and dissolution of items anytime, anywhere.

Audience:Fulfillment coordinators and warehouse field technicians
Proposed Tool:

A mobile-first web application that scans barcodes or QR codes to instantly dissolve e-commerce inventory items, syncing status updates to the central platform via API.

Shopify CommunityProblem #17
Friction: 7/10

WooCommerce's missing native features force manual workflows for e-commerce operations

The Problem

Users experience frustration when WooCommerce lacks native features for specific operational workflows, forcing them to rely on tedious manual workarounds or complex custom coding.

Audience:WooCommerce store owners and e-commerce developers
Proposed Tool:

A web application that acts as a no-code automation layer for WooCommerce, allowing users to define and execute workflows for missing native features via a visual interface.