In case your Checkmk Server is using https, and you're using the agent bakery, your SSL Certificate will be expiring at some time. If the CA for the new certificate stays the same, this should be no problem for the agent bakery.
However, if the CA changes you would have to follow some extra steps.
Add the steps involved:
P.S. to step 3: As this article is written (v2.0.0p8), Checkmk cannot handle the chain correctly if it is contained in a single file. All certs (client, root, intermediate) need to be added separately.
If you have everyting in one .crt file this is quite easy: just upload the file & save, then copy the rule. Checkmk automatically converts the file to text, and now you can split the certificates at ther "BEGIN/END Certificate" sections.
When done, delete the initial rule.
Related articles appear here based on the labels you select. Click to edit the macro and add or change labels.
|