Monitoring Benefit
The Configuration Certificates status test warns you before a certificate expires, rather than after users start seeing trust errors.
ENow checks the certificate presented by each URL you have configured, calculates how many days remain before expiry, and raises a warning and then a critical alert as that number falls past the thresholds set for the check.
Where the URLs come from
The certificate URLs are not discovered automatically. They are entered by an administrator in the ENow Admin Console under Office 365 Settings, and both that configuration and the check results are held in the ENow database.
If a certificate you expected to be monitored is not appearing on the dashboard, the most likely reason is that its URL was never added in the console.
How do we verify the monitoring test results?
Check the same certificate by hand from the ENow web server, so the result reflects the same network path ENow uses.
Using PowerShell, with no additional tools required:
$hostname = 'outlook.office365.com'
$port = 443
$tcp = [System.Net.Sockets.TcpClient]::new($hostname, $port)
$ssl = [System.Net.Security.SslStream]::new($tcp.GetStream())
$ssl.AuthenticateAsClient($hostname)
$cert = [System.Security.Cryptography.X509Certificates.X509Certificate2]$ssl.RemoteCertificate
$cert | Select-Object Subject, Issuer, NotBefore, NotAfter,
@{Name='DaysRemaining'; Expression={ ($_.NotAfter - (Get-Date)).Days }}
$ssl.Dispose(); $tcp.Dispose()
Compare DaysRemaining against the warning and critical thresholds configured for the check. ENow reads the certificate the same way, using the .NET X509Certificate2 and X509Chain classes, so a mismatch between this result and the dashboard is meaningful and worth reporting.
If you prefer OpenSSL:
openssl s_client -connect outlook.office365.com:443 -servername outlook.office365.com < /dev/null 2>/dev/null | openssl x509 -noout -subject -issuer -dates
Common warning or error results, and potential solutions
- A certificate renewed but the check stayed red. Confirm the new certificate is actually being served on the URL ENow is checking. A renewal installed on one node of a load-balanced service may not be presented on every connection.
- The check reports an expiry date that does not match what your browser shows. The ENow web server may be reaching a different endpoint — check for an intercepting proxy or TLS inspection appliance, which presents its own certificate.
- A chain or trust error rather than an expiry warning. ENow validates the chain as well as the dates. An intermediate certificate missing from the server's chain will fail here while still appearing valid in a browser, because browsers can fetch missing intermediates and this check does not.
- A URL is missing from the results entirely. Add it in the Admin Console under Office 365 Settings; nothing is monitored until it is listed there.
- The results are stale rather than wrong. If several checks stopped updating at the same time, look at the ENow database connection rather than at the certificates. Results are stored in SQL, and a database that cannot be reached leaves the last known values on the dashboard.
Comments
0 comments
Article is closed for comments.