Monitor certificate fingerprint changes
The Certificate Fingerprint Monitor tracks changes to your SSL certificate fingerprints over time, alerting you when a certificate is replaced or modified. A certificate fingerprint is a unique hash (SHA-256 or SHA-1) of the certificate that acts as a digital fingerprint — any change to the certificate, even reissuance by the same CA, produces a different fingerprint.
This monitoring is critical for detecting unauthorized certificate replacements, man-in-the-middle attacks, and certificate transparency violations. By comparing current fingerprints against stored baselines, you can immediately identify when a certificate has been changed, whether legitimately during renewal or suspiciously due to compromise.