Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Community Member

SSL module not sending certificate expiration notice

Hi all

Has anyone had any experience with this feature on the SSL module?

I've set the "ssl-proxy pki certificate check-expiring interval 1" command and has a syslog and SNMP receiver up and running. Logging is set to debug both for buffer and syslog.

The thing is that I have a proxy service with a certificate that's about to expire tomorrow and there is notification either in the log buffer or on the syslog.

/Fredrik

2 REPLIES
Silver

Re: SSL module not sending certificate expiration notice

The ssl-proxy pki history command enables logging of certificate history records per-proxy service into memory and generates a syslog message per record. Each record tracks the addition or deletion of a key pair or certificate into the proxy services key and the certificate table.

Up to 512 records can be stored in the memory at one time.

http://www.cisco.com/en/US/docs/interfaces_modules/services_modules/ssl/3.1/command/reference/comref.html#wp1008891

Re: SSL module not sending certificate expiration notice

Do you have following traps configured

snmp-server enable traps ssl-proxy oper-status

snmp-server enable traps ssl-proxy cert-expiring

snmp-server host ssl-proxy

Syed

107
Views
0
Helpful
2
Replies
CreatePlease to create content