Monitoring SSL Certs with "Check Certificates"

**CMK version:2.3.0p30

**Error message:Certificate obtained in 281 ms, Certificate chain verification failed: unable to get local issuer certificate

Hi guys, I’ve been “migrating” our SSL Certificate checks from the deprecated “Check HTTP Service” to “Check Certificates”. I’m experiencing some difficulties where the check can’t find the local issuer certificate. The old deprecated check doesn’t have any issues with checking it.

Any advices?

Hi Parayia,
seems like the intermediate certificate chain is not correct.

Best,

Did you ever get this figured out? I’m having the same probelm converting to the new check. All the self signed ones I can not get working.

HI, we had the Same problem on 2.4.0p26 Community Edition with the Certificate Chain and solved it with adding the intermediate certificate under General → Global Settings → Trusted Certificate authorities for SSL. After adding the Intermediate Certificate the Check went Green.

This is perhaps just a “workaround”, but personally, I have the best
and consistent experience, with this Nagios check

I typically run this via MRPE, and files, but I have also run it as an “active check”: Works perfectly.

EDIT: This is not to “discredit” the built-in check, but just meant as an alternative.