# \#certificates

**URL:** https://community.icinga.com/tag/certificates/88.md

[Latest](https://community.icinga.com/latest.md) · [Categories](https://community.icinga.com/categories.md) · [Tags](https://community.icinga.com/tags.md)

---

## [What should I do to update the cert on the Satellite/Agent side?](https://community.icinga.com/t/what-should-i-do-to-update-the-cert-on-the-satellite-agent-side/15280)

<div class="topic-metadata">

**Author:** [@Mysteoa](https://community.icinga.com/u/Mysteoa)\
**Replies:** 3\
**Last updated:** [November 28, 2025, 3:19pm UTC](https://community.icinga.com/t/what-should-i-do-to-update-the-cert-on-the-satellite-agent-side/15280 "2025-11-28T15:19:17Z")

</div>

Hello Due to some circumstances, I have to migrate our Master setup to new OS/VM. The current masters are using icinga2 version2.13.2-1 on Centos8 and the new Masters are using version 2.15.0-1 on Ubuntu 22.04. I could …

---

## [Icinga certs questions](https://community.icinga.com/t/icinga-certs-questions/6421)

<div class="topic-metadata">

**Author:** [@sysres-dev](https://community.icinga.com/u/sysres-dev)\
**Replies:** 11\
**Last updated:** [June 26, 2025, 11:52am UTC](https://community.icinga.com/t/icinga-certs-questions/6421 "2025-06-26T11:52:15Z")

</div>

Hello Community and Devs, I have several questions about what’s possible with icinga CA. Is it possible (now or in the future) to use an external CA (a company one for example) for icinga to sign endpoints csr instea…

---

## [Wrong certificate Timestamp registered on the server during node setup](https://community.icinga.com/t/wrong-certificate-timestamp-registered-on-the-server-during-node-setup/14808)

<div class="topic-metadata">

**Author:** [@maxnumberone](https://community.icinga.com/u/maxnumberone)\
**Replies:** 2\
**Last updated:** [April 22, 2025, 6:17am UTC](https://community.icinga.com/t/wrong-certificate-timestamp-registered-on-the-server-during-node-setup/14808 "2025-04-22T06:17:18Z")

</div>

Hello, I have a problem with the node registration on the icinga server using ‘icinga2 node setup’. We noticed some strange Timestamp on the server for some certificates. After some analysis I discovered the Timestamp…

---

## [How to force renewal of Icinga2 client cert?](https://community.icinga.com/t/how-to-force-renewal-of-icinga2-client-cert/14691)

<div class="topic-metadata">

**Author:** [@offsides](https://community.icinga.com/u/offsides)\
**Replies:** 4\
**Last updated:** [March 12, 2025, 1:56pm UTC](https://community.icinga.com/t/how-to-force-renewal-of-icinga2-client-cert/14691 "2025-03-12T13:56:40Z")

</div>

Starting about 2-3 years ago, Icinga2 included a feature to auto-renew client certificates, which is good. But my servers that are older than that still have their original 15-year certificates on them, and I’d like to …

---

## [Uppercase in agent name running on Windows server](https://community.icinga.com/t/uppercase-in-agent-name-running-on-windows-server/14596)

<div class="topic-metadata">

**Author:** [@jeanm](https://community.icinga.com/u/jeanm)\
**Replies:** 1\
**Last updated:** [February 14, 2025, 10:54am UTC](https://community.icinga.com/t/uppercase-in-agent-name-running-on-windows-server/14596 "2025-02-14T10:54:12Z")

</div>

Hello, I have an error on an agent deployed on a Windows 2022 server. Agent version: 2.14.3. A similar server has been deployed with the agent no later than last week, with no issue. I do not understand what could be…

---

## [Own CA for Icinga Cluster/API communication?](https://community.icinga.com/t/own-ca-for-icinga-cluster-api-communication/243)

<div class="topic-metadata">

**Author:** [@dnsmichi](https://community.icinga.com/u/dnsmichi)\
**Replies:** 12\
**Last updated:** [December 16, 2024, 9:50am UTC](https://community.icinga.com/t/own-ca-for-icinga-cluster-api-communication/243 "2024-12-16T09:50:00Z")

</div>

Every now and then you may be required to answer the question on “why not use the company’s CA certificates” or “The REST API is not trusted in my browser, fix it”. Here’s some ideas and pros and cons. Please discuss yo…

---

## [Check TLS version of certificate](https://community.icinga.com/t/check-tls-version-of-certificate/14310)

<div class="topic-metadata">

**Author:** [@aclark6996](https://community.icinga.com/u/aclark6996)\
**Replies:** 2\
**Last updated:** [November 19, 2024, 2:16pm UTC](https://community.icinga.com/t/check-tls-version-of-certificate/14310 "2024-11-19T14:16:54Z")

</div>

Hello Icinga Community, How do you check the SSL/TLS version of your certificates? I want to create a monitoring check to notify if SSL2, SSL3, TLS1 or TLS1.1 are used. These protocols have vulnerabilities, and I want…

---

## [Reconnect loop for self-signed certificates in icinga2 2.14](https://community.icinga.com/t/reconnect-loop-for-self-signed-certificates-in-icinga2-2-14/13973)

<div class="topic-metadata">

**Author:** [@brianjaustin](https://community.icinga.com/u/brianjaustin)\
**Replies:** 6\
**Last updated:** [August 20, 2024, 12:14am UTC](https://community.icinga.com/t/reconnect-loop-for-self-signed-certificates-in-icinga2-2-14/13973 "2024-08-20T00:14:30Z")

</div>

I believe I may be seeing an instance of Icinga 2 reconnects in a loop for self-signed certificates · Issue #7680 · Icinga/icinga2 · GitHub with icinga2 version r2.14.2-1. After a recent rebuild of my organization’s icin…

---

## [Icinga Agent for Windows Change CA](https://community.icinga.com/t/icinga-agent-for-windows-change-ca/10820)

<div class="topic-metadata">

**Author:** [@Doberitus](https://community.icinga.com/u/Doberitus)\
**Replies:** 4\
**Last updated:** [July 3, 2023, 8:30am UTC](https://community.icinga.com/t/icinga-agent-for-windows-change-ca/10820 "2023-07-03T08:30:01Z")

</div>

Hello guys, since the old Kickstart for icinga-agent installation on windows hosts is deprecated, im tryin to figure out, how to setup my automatic deployment with the new Icinga for Windows. so far everything is worki…

---

## [Certificate issue while connecting from master to client](https://community.icinga.com/t/certificate-issue-while-connecting-from-master-to-client/11991)

<div class="topic-metadata">

**Author:** [@hrai](https://community.icinga.com/u/hrai)\
**Replies:** 4\
**Last updated:** [May 22, 2023, 7:42am UTC](https://community.icinga.com/t/certificate-issue-while-connecting-from-master-to-client/11991 "2023-05-22T07:42:05Z")

</div>

The Icinga server is monitoring everything like ping and SSL status correctly but services like disk, users and load are not being monitored the dashboard displays this error Remote Icinga instance 'client1.domain.com'…

---

## [Remove a signed CA](https://community.icinga.com/t/remove-a-signed-ca/4120)

<div class="topic-metadata">

**Author:** [@ehsank777](https://community.icinga.com/u/ehsank777)\
**Replies:** 7\
**Last updated:** [May 2, 2023, 8:54pm UTC](https://community.icinga.com/t/remove-a-signed-ca/4120 "2023-05-02T20:54:31Z")

</div>

Hi everyone, I’ve signed a certificate request accidentally. How can I remove it from CA list. When I run Icinga2 ca remove it says : Certificate request for CN ‘X.X.com’ already signed, removal is not possible. I want…

---

## [\[Thruk v3.04 / Icinga2 v2.13.7\] no client certificate | unknow ca certificate | 400: Bad Request](https://community.icinga.com/t/thruk-v3-04-icinga2-v2-13-7-no-client-certificate-unknow-ca-certificate-400-bad-request/11844)

<div class="topic-metadata">

**Author:** [@ulrichmonji](https://community.icinga.com/u/ulrichmonji)\
**Replies:** 0\
**Last updated:** [April 20, 2023, 10:15am UTC](https://community.icinga.com/t/thruk-v3-04-icinga2-v2-13-7-no-client-certificate-unknow-ca-certificate-400-bad-request/11844 "2023-04-20T10:15:36Z")

</div>

Hello, I would like to connect my icinga2 server to Thruk IHM, but i am facing some TLS issues, (no client certificate). Please someone could help ? My errors message On thruk IHM, when i tried to connect to icinga2…

---

## [Migration - Puppet CA to Icinga CA](https://community.icinga.com/t/migration-puppet-ca-to-icinga-ca/11452)

<div class="topic-metadata">

**Author:** [@jaredcmf](https://community.icinga.com/u/jaredcmf)\
**Replies:** 0\
**Last updated:** [February 13, 2023, 9:51am UTC](https://community.icinga.com/t/migration-puppet-ca-to-icinga-ca/11452 "2023-02-13T09:51:13Z")

</div>

Hello All! We are currently using the Puppet CA for our certificates on our cluster class { '::icinga2::feature::api': pki =\> 'puppet', etc... } My question is has anyone moved from using P…

---

## [Icinga Auto CSR setup configuration issue](https://community.icinga.com/t/icinga-auto-csr-setup-configuration-issue/11373)

<div class="topic-metadata">

**Author:** [@MisfitToy](https://community.icinga.com/u/MisfitToy)\
**Replies:** 7\
**Last updated:** [February 2, 2023, 7:12am UTC](https://community.icinga.com/t/icinga-auto-csr-setup-configuration-issue/11373 "2023-02-02T07:12:33Z")

</div>

Hello, I’m currently setting up Icinga for the first time. I kind of feel like a fish out of water and have probably made things harder for myself but, currently, I am trying to use the Icinga 2 Agent for Windows to conn…

---

## [Error for x509 module](https://community.icinga.com/t/error-for-x509-module/11351)

<div class="topic-metadata">

**Author:** [@adrian1](https://community.icinga.com/u/adrian1)\
**Replies:** 2\
**Last updated:** [January 20, 2023, 10:37am UTC](https://community.icinga.com/t/error-for-x509-module/11351 "2023-01-20T10:37:52Z")

</div>

Hello, I have a CentOS7 with IcingaWeb, another Centos7 for database I have installed php-gmp also. defined a test for a specific host with a port. icingacli x509 scan --job test PHP Fatal error: Trait ‘ipl\\Sch…

---

## [Certificate error](https://community.icinga.com/t/certificate-error/10969)

<div class="topic-metadata">

**Author:** [@sameer](https://community.icinga.com/u/sameer)\
**Replies:** 1\
**Last updated:** [November 15, 2022, 5:10pm UTC](https://community.icinga.com/t/certificate-error/10969 "2022-11-15T17:10:36Z")

</div>

I am trying to add a satellite to master which would then be a second master…I am using puppet for automatic config…Everything installed correctly except for this…Can someone provide help Error: ‘/usr/sbin/icinga2 pki s…

---

## [Check for Self-Signed certificates](https://community.icinga.com/t/check-for-self-signed-certificates/10959)

<div class="topic-metadata">

**Author:** [@aclark6996](https://community.icinga.com/u/aclark6996)\
**Replies:** 1\
**Last updated:** [November 3, 2022, 8:11pm UTC](https://community.icinga.com/t/check-for-self-signed-certificates/10959 "2022-11-03T20:11:21Z")

</div>

I would like to monitor if a server has a self-signed certificate. We would like all our servers web certificates to get signed by our internal corporate CA and not use the local self-signed certificate. Do anyone know…

---

## [ElasticStack / Kibana WebHooks - Won't work with the default self-signed certificates](https://community.icinga.com/t/elasticstack-kibana-webhooks-wont-work-with-the-default-self-signed-certificates/9899)

<div class="topic-metadata">

**Author:** [@Andy99](https://community.icinga.com/u/Andy99)\
**Replies:** 2\
**Last updated:** [May 27, 2022, 1:02pm UTC](https://community.icinga.com/t/elasticstack-kibana-webhooks-wont-work-with-the-default-self-signed-certificates/9899 "2022-05-27T13:02:27Z")

</div>

Hi all, I am attempting to use the WebHooks feature in Kibana to send passive alerts from our ElasticStack to the Icinga API. I have no issues with the API syntax and JSON payload, however, Kibana insists that WebHooks…

---

## [X509 mail notification](https://community.icinga.com/t/x509-mail-notification/5122)

<div class="topic-metadata">

**Author:** [@lale](https://community.icinga.com/u/lale)\
**Replies:** 4\
**Last updated:** [April 22, 2022, 2:35pm UTC](https://community.icinga.com/t/x509-mail-notification/5122 "2022-04-22T14:35:49Z")

</div>

Hello, I´ve installed the x509 module. My goal is to receive an email when a certificate is issued. But only from the networks that are automatically scanned, so that we do not have to set up each individual server wi…

---

## [Master cant connect to agent](https://community.icinga.com/t/master-cant-connect-to-agent/8723)

<div class="topic-metadata">

**Author:** [@why](https://community.icinga.com/u/why)\
**Replies:** 14\
**Last updated:** [December 22, 2021, 3:49pm UTC](https://community.icinga.com/t/master-cant-connect-to-agent/8723 "2021-12-22T15:49:42Z")

</div>

My Problem is still the one in Setup agent node without connecting to the master but i was informed, that i might not get help there, because it is marked as solved. I will copy the relevant parts here: "The situatio…

---

## [Certificate re-naming](https://community.icinga.com/t/certificate-re-naming/8794)

<div class="topic-metadata">

**Author:** [@MikeKall](https://community.icinga.com/u/MikeKall)\
**Replies:** 7\
**Last updated:** [December 8, 2021, 11:24am UTC](https://community.icinga.com/t/certificate-re-naming/8794 "2021-12-08T11:24:29Z")

</div>

Hello, I want to migrate my current monitoring infra to a new one. A problem that I am facing is the certificates. Can I generate master certificates or rename the existing once to correspond to an alias? This would m…

---

## [Failed to create new self-signed certificate](https://community.icinga.com/t/failed-to-create-new-self-signed-certificate/2410)

<div class="topic-metadata">

**Author:** [@ETMA](https://community.icinga.com/u/ETMA)\
**Replies:** 3\
**Last updated:** [October 7, 2019, 11:14am UTC](https://community.icinga.com/t/failed-to-create-new-self-signed-certificate/2410 "2019-10-07T11:14:02Z")

</div>

Hi, I have a bunch of cpanel server where I am trying to install the icinga2 agent. I have done this before using the director script without any issues. However on these servers where I have just taken over monitoring,…

---

## [How to monitor for revoked TLS certificates?](https://community.icinga.com/t/how-to-monitor-for-revoked-tls-certificates/2220)

<div class="topic-metadata">

**Author:** [@mrimann](https://community.icinga.com/u/mrimann)\
**Replies:** 5\
**Last updated:** [September 16, 2019, 8:59am UTC](https://community.icinga.com/t/how-to-monitor-for-revoked-tls-certificates/2220 "2019-09-16T08:59:02Z")

</div>

Hi We’re monitoring several websites for http and https response-times - and also wether the certificate is valid. All those service checks are executed via the “check\_http” plugin from the monitoring-plugins collection…

---

## [Fix certificate not signed by our CA](https://community.icinga.com/t/fix-certificate-not-signed-by-our-ca/852)

<div class="topic-metadata">

**Author:** [@mattb](https://community.icinga.com/u/mattb)\
**Replies:** 7\
**Last updated:** [April 9, 2019, 11:04am UTC](https://community.icinga.com/t/fix-certificate-not-signed-by-our-ca/852 "2019-04-09T11:04:33Z")

</div>

Going through a distributed setup and somewhere along the way I’m getting the error below after I renamed the master and satellite zone names (I didn’t like them defaulting to the nodes fqdn) What’s the easiers way to r…

---

## [SSL Certificate Durations](https://community.icinga.com/t/ssl-certificate-durations/415)

<div class="topic-metadata">

**Author:** [@ahynes](https://community.icinga.com/u/ahynes)\
**Replies:** 2\
**Last updated:** [February 20, 2019, 8:12am UTC](https://community.icinga.com/t/ssl-certificate-durations/415 "2019-02-20T08:12:48Z")

</div>

Is there any way to adjust the duration of SSL certificates the satellites use for communication with the masters, our security group has flagged the long duration as a problem and would like them adjusted to be shorter …
