A tool that reads the BIG-IP
the way you do.

CertFlow is not a generic certificate scanner. It speaks iControl REST, knows partitions, profile inheritance and HA pairs, and treats write access with the respect a production BIG-IP deserves.

Monitoring: the whole chain, not just the date

Every scan reads certificates, client SSL profiles and virtual servers and links them together. You don't just see "expires in 14 days", you see what exactly goes down.

  • Read-only via iControl REST: an auditor account is enough. No agents, no config changes.
  • HA pairs deduplicated: a cluster appears as one device, fingerprint-based.
  • Partitions & inheritance: certificates inherited through defaultsFrom are attributed correctly.
  • History built in: first seen / last seen per certificate. Removed items are flagged, not deleted.

Alerts you won't filter away

Expiry warnings escalate in levels and fire exactly once per level. No daily noise that ends up in a mail filter, just a signal when it matters.

  • Email, Slack, Microsoft Teams: wherever your team already works.
  • Escalation levels: inform early, alarm late. Thresholds fully configurable.
  • Once per level: every message is new and relevant.

60 days out

Notice to #netops: "*.shop.example.com expires in 60 days."

30 days out

Warning with impact: 12 virtual servers affected, HA pair "prod".

7 days out

Critical, additionally emailed to the on-call rotation.

The swap: reversible, not risky

CertFlow swaps by "create new, repoint profile": the old certificate stays untouched on the device. If verification fails, the rollback simply points the profile back.

  • Validation before the first write: does the key match the certificate, do the names cover all hostnames (including wildcards), is the chain complete?
  • Blast radius: before executing, CertFlow shows which profiles get written and which merely inherit. Inheriting profiles are never touched.
  • Verification on the wire: after the swap, CertFlow confirms via a real TLS handshake that the new certificate is being served.
  • Config sync tracked: the sync to the HA peer is actively followed until it is truly "In Sync".

Security is architecture, not a feature

CertFlow is built for management networks that are unreachable from the internet. Everything runs on your infrastructure, under your rules.

  • Self-hosted Docker container: non-root, health check, one volume for all data.
  • Separate accounts for read and write: monitoring with the auditor role. The swap is an opt-in per device with its own credentials.
  • Hardened dashboard login: modern password hashing (scrypt), CSRF protection, httponly session cookies.
  • Audit log: every write with user and timestamp, also available via API.
  • License check works offline: no phone-home required.

Permissions, documented honestly

Monitoring: Auditor is enough. Certificate swap: Resource Administrator, because client SSL profiles are modified. The Certificate Manager role is not sufficient for that, and CertFlow tells you so instead of hiding it.

System requirements

A Docker host with access to the management network · F5 BIG-IP with iControl REST · a browser for the dashboard. That's it.

Try CertFlow against your own BIG-IPs

30 days free, every feature, self-hosted in your network. Afterwards you'll know whether CertFlow fits your environment.

Start free trial