SSL Certificate Expiration Date Monitor
This SAM application monitor template, tests a web server's ability to accept incoming sessions over a secure HTTPS channel, then tests the security certificate's expiration date. You can configure the number of times that SAM attempts to connect to a server before assuming that the SSL certificate expired; by default, SAM tries once.
This template includes a single, predefined component monitor, the SSL Certificate Expiration Date Monitor that uses TCP port 443, by default. Click the link to learn more about configuring the retry mechanism, or monitoring devices with web-accessible interfaces.
Note the following details about the component monitor:
- This monitor assumes that target nodes are running a web service of some type at the remote end.
- It does not currently support proxies.
- You can use this monitor for devices with web-accessible interfaces that are secured with certificates. The web interface may serve as the primary way to interact with the service the device provides (for example, an SSL VPN), or it may be the interface used to configure and manage the device.
- SAM supports monitoring multiple SSL certificates that share the same IP Address by using Server Name Indication (SNI), an optional field you can configure in the component monitor.
(Recommended) For Internet Security (IPsec) VPN devices, monitor the same certificate used to secure the management web interface of the device. In addition to increased security and consistency, this allows SAM to monitor the certificate expiration via HTTPS.
Prerequisites
Target nodes should run a web service of some type at the remote end.
Only HTTPS connections are supported.
Credentials:
None.
Default Settings
The SSL Certificate Expiration Date application monitor includes settings inherited from the template. Once assigned to a node, these can be overridden, see Assigned Application Monitor.
Application Monitor Name:
SSL Certificate Expiration Date
Polling Frequency:
300 seconds
Polling Timeout:
300 seconds
Advanced Settings
Preferred Polling Method:
Agent
Debug logging:
Off
Number of log files to keep:
30. The number of most recent log files to be kept for this application when debug logging is on.
Platform to run polling job on:
x86
Custom Properties:
Available when the template itself is modified.