Xymon Mailing List Archive search

xymon checking wrong SSL cert on CNAME

list Elizabeth Schwartz
Thu, 13 Jun 2024 00:40:28 -0400
Message-Id: <1d1e701dabd4b$d16b06a0$744113e0$@well.com>

Hi, 

We have a website at a third-party  hosting company, where our site
https://www.example.com <http://www.example.com>;   is a cname for
something.hosting.com  (not the real name)

We have a LetsEncrypt cert issued for www.example.com
<http://www.example.com>; .

 
The cert wasn't updating, but xymon did not alert , because xymon is
apparently evaluating the CNAME and then checking the cert for hosting.com
(which has a wildcard cert *.hosting.com)

 
How do we make xymon check the cert for www.example.com
<http://www.example.com>;  , other than writing our own script? I think this
is a fairly common setup for hosted websites

(for a minute I thought about adding an A record but that would be wrong on
multiple levels) 

 
/home/xymon/server/etc/hosts.cfg has 

x.x.x.x  www.example.com # noconn httpstatus;http://www.example.com/;301;
https://www.example.com

 
(where x.x.x.x is the actual IP)

 
Running xymon 4.3.30 on Alma 8

 
Thanks very much!