Ability to configure certmonger to passively track certificates and throw warning about impending expiration into logs would be useful, especially for ca-less IPA installations.
There is plenty of log monitoring systems out there so this would offer a lot of flexibility.
Discussion: https://www.redhat.com/archives/freeipa-devel/2016-July/msg00138.html
Metadata Update from @pspacek: - Issue set to the milestone: 0.0 NEEDS_TRIAGE