cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
225
Views
0
Helpful
2
Replies

SSL module not sending certificate expiration notice

hoffa2000
Level 3
Level 3

Hi all

Has anyone had any experience with this feature on the SSL module?

I've set the "ssl-proxy pki certificate check-expiring interval 1" command and has a syslog and SNMP receiver up and running. Logging is set to debug both for buffer and syslog.

The thing is that I have a proxy service with a certificate that's about to expire tomorrow and there is notification either in the log buffer or on the syslog.

/Fredrik

2 Replies 2

mchin345
Level 6
Level 6

The ssl-proxy pki history command enables logging of certificate history records per-proxy service into memory and generates a syslog message per record. Each record tracks the addition or deletion of a key pair or certificate into the proxy services key and the certificate table.

Up to 512 records can be stored in the memory at one time.

http://www.cisco.com/en/US/docs/interfaces_modules/services_modules/ssl/3.1/command/reference/comref.html#wp1008891

Do you have following traps configured

snmp-server enable traps ssl-proxy oper-status

snmp-server enable traps ssl-proxy cert-expiring

snmp-server host ssl-proxy

Syed

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card