Xymon Mailing List Archive search

Intermediate cert monitoring

list Ralph Mitchell
Fri, 27 Feb 2015 22:24:43 -0500
Message-Id: <CAAEjoCV0_ArOOz4wT3BiQSUJwLvRn=user-ca3d43ef3a9b@xymon.invalid>

Having the Xymon server validate the intermediate certificates won't help
if they're missing off the server that owns the certificate.  The Xymon
server would have the certs installed and always get a match.

Where are the intermediate certs missing?  Does the web server even start
properly if it can't validate its own cert?

Ralph Mitchell


On Thu, Feb 26, 2015 at 1:51 PM, Eli via Xymon <xymon at xymon.com> wrote:
---------- Forwarded message ----------
From: Eli <user-eeb3a3c6c848@xymon.invalid>
To: Mark Felder <user-db141d317836@xymon.invalid>
Cc: xymon at xymon.com
Date: Thu, 26 Feb 2015 11:50:43 -0700
Subject: Re: [Xymon] Intermediate cert monitoring
The issue was missing or not installed. As you know newer browsers doesn't
have problem but the older one show cert error when the intermediate cert
missing. We have bunch of cert so some time engineers forget to install the
intermediate cert and caused issue.


Mark Felder <user-db141d317836@xymon.invalid> wrote:

What was the exact problem with the intermediate certificate? What
should be monitored? Maybe we can come up with a way to add additional
monitoring parameters to Xymon's SSL monitoring if we know exactly what
should be monitored.

My first guess is expiration, but I'm not sure if you can sign a cert if
it expires after your intermediate is due to expire. The only other
thought is if the chain was incomplete...