# Check for Self-Signed certificates

**URL:** <https://community.icinga.com/t/check-for-self-signed-certificates/10959>\
**Category:** Icinga 2\
**Tags:** certificates, icinga2\
**Created:** [November 3, 2022, 6:24pm UTC](https://community.icinga.com/t/check-for-self-signed-certificates/10959 "2022-11-03T18:24:20Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![aclark6996](https://community.icinga.com/letter_avatar_proxy/v4/letter/a/5f9b8f/32.png) [@aclark6996](https://community.icinga.com/u/aclark6996)\
**Post date:** [November 3, 2022, 6:24pm UTC](https://community.icinga.com/t/check-for-self-signed-certificates/10959/1 "2022-11-03T18:24:20Z")

</div>

I would like to monitor if a server has a self-signed certificate. We would like all our servers web certificates to get signed by our internal corporate CA and not use the local self-signed certificate. Do anyone know how to check if a server is using a self-signed certificates ?

I have setup the web certificate expiration date monitoring check using the check\_http plugin but this does not provide a self-signing certificate check option.

Thanks in advance for your help.  
Alex

---

<div class="post-metadata">

**Author:** ![moreamazingnick](https://community.icinga.com/user_avatar/community.icinga.com/moreamazingnick/32/7725_2.png) [@moreamazingnick](https://community.icinga.com/u/moreamazingnick)\
**Post date:** [November 3, 2022, 8:11pm UTC](https://community.icinga.com/t/check-for-self-signed-certificates/10959/2 "2022-11-03T20:11:21Z")

</div>

look into =\> [Icinga Template Library - Icinga 2](https://icinga.com/docs/icinga-2/latest/doc/10-icinga-template-library/#ssl_cert)

the ssl\_cert check allows to specify a ssl\_cert\_rootcert  
**Optional.** Root certificate or directory to be used for certificate validation.

there you can specify the exported ca’s public key so the check can verify the certificate signed by your local ca
