Loading full navigation.

LogicMonitor’s SSL Certificate Monitoring package monitors SSL certificates across common SSL ports to identify certificate chain and expiration issues.

The package uses standard Java-based SSL checks that are compatible with common certificate types and provide results comparable to modern browsers and applications.

LogicMonitor follows industry-standard practices to ensure the security of your portal and data. For more information, see LogicMonitor Security Best Practices.

Requirements for SSL Certificate Monitoring

To use SSL Certificate Monitoring, you need network access from the Collector to the SSL ports you want to monitor, such as port 443.

Add SSL Certificate Resources into Monitoring

Add resources that use SSL certificates (for example, HTTPS servers) into LogicMonitor. For more information, see Adding Resources.

Add Properties to SSL Certificate Resources

You can add the following resource properties to configure SSL certificate monitoring. For more information, see Resources and Instance Properties.

PropertyDescriptionRequired?
ssl.cert.monitorControls whether SSL certificate monitoring is enabled for the resource. Set to false to exclude the resource from monitoring.No
ssl.cert.timeoutSets the socket connection and TLS handshake timeout, in seconds. Default is 10.No
ssl.sni.hostnamesSpecifies a comma-separated list of application FQDNs for servers that host multiple SSL certificates on the same IP address and port using SNI. For example, app.example1.com,api.example2.com. The SSL_Certificates and SSL_Certificate_Chains DataSources create instances for each configured hostname and use the FQDN during TLS collection.No

Import LogicModules

Install all SSL Certificate LogicModules from the LogicMonitor’s Module Exchange. For more information, see the list of LogicModules in Package. If these LogicModules are already present, ensure you have the most recent version of each module. 

Data collection automatically starts when the LogicModules are imported.​

Troubleshooting

Use the following troubleshooting information to diagnose SSL certificate monitoring issues:

IssueResolution
Certificate chain failureUse the SSL_Certificate_Chains module and review the Certificate Issues and Expiry Time graphs to identify the affected certificate.
Certificate issue identifiedUse the certificate thumbprint to identify and resolve the affected certificate in your environment.
Issue reported for a certificate no longer in the chainThe web server might have cached the previous certificate chain. Restart or update the web server.
LogicMonitor reports unexpected certificate thumbprintsCompare the thumbprints reported by LogicMonitor with those returned by your web browser. If the issue persists, contact LogicMonitor Support.

LogicModules in Package

LogicMonitor’s package for SSL Certificate consists of the following LogicModules. For full coverage, ensure that all of these LogicModules are imported into your LogicMonitor platform.

Display NameTypeDescription
Device_BasicInfoPropertySourceDetects open SSL ports on Linux and Windows resources and assigns them to auto.network.listening_ssl_ports.
SSL_CertificatesDataSourceMonitors SSL certificate validity for discovered SSL ports and configured SNI hostnames.
SSL_Certificate_ChainsDataSourceProvides certificate-level details for SSL chains on discovered SSL ports and configured SNI hostnames to help diagnose certificate issues. Does not alert by default.

When setting static datapoint thresholds on the various metrics tracked by this package’s DataSources, LogicMonitor follows the technology owner’s best practice KPI recommendations.

Recommendation: Adjust predefined thresholds to meet the unique needs of your environment. For more information on tuning datapoint thresholds, see Static Thresholds for Datapoints.