feat: cert-checker #220
Labels
No labels
1week
2weeks
Failed compliance check
IP cameras
NATS
Possible security concern
Review effort 1/5
Review effort 2/5
Review effort 3/5
Review effort 4/5
Review effort 5/5
UI
aardvark
accessibility
amd64
api
arm64
auth
back-end
bgp
blog
bug
build
checkers
ci-cd
cleanup
cnpg
codex
core
dependencies
device-management
documentation
duplicate
dusk
ebpf
enhancement
eta 1d
eta 1hr
eta 3d
eta 3hr
feature
fieldsurvey
github_actions
go
good first issue
help wanted
invalid
javascript
k8s
log-collector
mapper
mtr
needs-triage
netflow
network-sweep
observability
oracle
otel
plug-in
proton
python
question
reddit
redhat
research
rperf
rperf-checker
rust
sdk
security
serviceradar-agent
serviceradar-agent-gateway
serviceradar-web
serviceradar-web-ng
siem
snmp
sysmon
topology
ubiquiti
wasm
wontfix
zen-engine
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
carverauto/serviceradar#220
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Imported from GitHub.
Original GitHub issue: #607
Original author: @mfreeman451
Original URL: https://github.com/carverauto/serviceradar/issues/607
Original created: 2025-04-14T13:45:19Z
Monitors SSL/TLS certificates on services (e.g., HTTPS endpoints, gRPC servers) by connecting, retrieving certificates, and checking expiry dates. Reports days until expiry and alerts if nearing expiration (e.g., <30 days).
Value Proposition:
Unique Niche: Ensures certificate health, critical for mTLS-heavy ServiceRadar (tls-security.md) and external services (e.g., APIs, web servers). No overlap with sysmon, rperf, snmp, or dusk.
Lightweight: One TLS handshake every 5m produces 100 bytes (e.g., days_left: 90). Fits SQLite’s ~24 GB/day (0.05 MB/day/host).
Proxmox Fit: Monitors certificates for services on Proxmox (e.g., containerized APIs) or ServiceRadar’s own mTLS certs (/etc/serviceradar/certs).
Security: Uses mTLS for gRPC and validates endpoint certs, aligning with tls-security.md.
Proactive: Prevents outages from expired certs, a common issue in air-gapped networks.
Implementation:
Logic: Use crypto/tls to connect and get Certificate.NotAfter. Calculate days until expiry.
Data: Store in timeseries_metrics:
Config (/etc/serviceradar/checkers/cert.json):
Poller:
Storage: Add processCertMetrics to core/server.go, storing expiry days and subject.