- CheckMates
- :
- Products
- :
- General Topics
- :
- Identity Broker certificate monitoring (since R81....
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Identity Broker certificate monitoring (since R81.20 JHF T 26)
Hi mates,
release notes of take 26 shows:
PRJ-45912, | Identity Awareness | UPDATE: Implemented monitoring functionality and alerts for tracking the expiration date of Identity Broker certificates. |
does anybody know how to use this functionality?
Cheers
Vince
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I suspect this is part of a larger project to allow for mass renewal of the various platform/VPN certificates, something that we plan to provide in the near future.
Which means the full functionality may not be exposed just yet.
Let me see what I can find out.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Vince,
The ability to monitor and alert once we approach the expiration date of the Identity Broker certificate has been added to R81.20 jumbo take 26, we are working on adding it to R81 and R81.10 jumbos as well.
This functionality is enabled by default, we have added a new alert logs + warning/error status to the relevant Subscriber object.
The behavior is as follows:
Certificate expiration date < 90 days:
- GW/Cluster changes to warning with an appropriate message (as can be seen in the screenshot below).
- Alert log triggered in SmartConsole once a day (as can be seen in the screenshot below)
Certificate expiration date < 30 days :
- GW/Cluster status changes to error with an appropriate message.
- Alert log will be still triggered in SmartConsole once a day
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks for your explanation. So we'll see the alert messages on SmartLog and in our case via LogExporter in our elastic stack as well.
An option to monitor this via api, prometheus, snmp is not present or planned?
thanks
Vince
