Forum Discussion
Piping v15 EXPIRED_CERTIFICATE_IN_USE listing to text from CLI
I am familiar with list sys crypto cert. The key part of my quest is "in use". Those are the ones where we have to chase app owners to renew.
I can scrape the EXPIRED_CERTIFICATE_IN_USE page, but I'd rather deal with this with crontab and CLI commands to produce periodic text files.
I agree that is a very important detail. I would then suggest looking into cleaning up th un-used certs, since they probably serve no purpose.
Paulis's response/article did find some other options with the crypto check-cert utility
K14318: Monitoring SSL certificate expiration on the BIG-IP system
https://my.f5.com/manage/s/article/K14318
I would also consider having some sort of syslog server, or SIEM like Splunk to alert whenever the expired cert logs appear.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com