[Check_mk (english)] Using check_mk_active-http to monitor SSL Certificate Age

Ross Bannerman ross at jhcs.com.au
Sun Jun 9 15:23:32 CEST 2019


I’m experiencing a similar issue to https://lists.mathias-kettner.de/pipermail/checkmk-en/2018-February/024611.html in 1.5.0p16

My service check to monitor SSL certificate age is as follows:
check_mk_active-http!'-C' '20,10' '--sni' '-H' '$_HOSTADDRESS_4$'

Output of the check plugin in WATO UI, for some but not all hosts (but with no obvious pattern that I can identify), is:
CRITICAL - Cannot make SSL connection.

When I execute the very same check manually from CLI however I receive the following result:
/opt/omd/versions/1.5.0p16.cre/lib/nagios/plugins/check_http -C 20,10 --sni -H xxxxxxxxxx
OK - Certificate 'xxxxxxxxxx' will expire on Sun 28 Jul 2019 12:02:29 AM GMT +0000.

Things I've tried so far:
- Removing and re-adding the check via Host & Service Parameters for all hosts
- Disabling/enabling SNI in check
- Restarting OMD
- Restarting VM that hosts Check_MK
- Downgrading to 1.5.0p15

This used to function as expected in the past for all hosts but only appears to have started failing recently.

Any ideas or guidance would be greatly appreciated. Many thanks in advance!
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.mathias-kettner.de/pipermail/checkmk-en/attachments/20190609/89858c02/attachment.html>

More information about the checkmk-en mailing list