Applies To:
Show VersionsBIG-IQ Centralized Management
- 5.1.0
How do I monitor SSL certificate expiration dates for my managed devices?
When you manage BIG-IP® devices that load balance SSL traffic, you must monitor both their SSL traffic and SSL system certificates. Traffic certificates are server certificates that a device uses for traffic management tasks. System certificates are the web certificates that allow client systems to log in to the BIG-IP Configuration utility.
BIG-IQ® imports the certificates for every managed BIG-IP device you discover. This makes it easy to monitor the expiration dates all of your devices' SSL certificates from one location.
You can also:
- Set up alerts to let you know when a certain certificate is about to expire within a specified number of days.
- Download the data to a CSV file for reporting purposes.
Configuring SMTP for sending alerts
You must configure a DNS server before you can specify an SMTP server.
Monitoring SSL certificate expiration dates
You must have discovered at least one device before any certificates display in the Certificate Management inventory.
You must also set up SMTP to receive notifications for alerts.
- Log in to F5® BIG-IQ® Centralized Management with your user name and password.
- At the top left of the screen, select Device Management from the BIG-IQ menu.
- At the top of the screen, click Operations.
- On the left, click CERTIFICATE MANAGEMENT.
- Click the Alert Settings button.
- For the Device Certificate Expiration condition, select the Enabled check box, and in the Threshold field, type the number of days notice you want before the certificate expires.
- To receive an alert when a certificate has expired, for the Device Certificate Expired setting, select the Enabled check box.
- Click the Save button at the bottom of the screen.