# LDAPS Monitor with Certificate Expiration

**URL:** <https://community.f5.com/t/ldaps-monitor-with-certificate-expiration/54937>\
**Category:** Technical Forums\
**Tags:** availability, deployment, ltm, application-delivery, monitor, microsoft\
**Created:** [October 6, 2015, 3:34am UTC](https://community.f5.com/t/ldaps-monitor-with-certificate-expiration/54937 "2015-10-06T03:34:47Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![danielpenna](https://avatars.discourse-cdn.com/v4/letter/d/c68b51/32.png) [@danielpenna](https://community.f5.com/u/danielpenna)\
**Post date:** [October 6, 2015, 3:34am UTC](https://community.f5.com/t/ldaps-monitor-with-certificate-expiration/54937/1 "2015-10-06T03:34:47Z")

</div>

Hi Team,

I have been working with my AD team trying to resolve a problem where they forget to update a Domain Controller certificate and it expires and ADLDAPS queries fail since they dont bind to expired certificates. They have requested to see if we can drop a member out of the pool if the certificate is expired ( ie, not a valid SSL cert )

I have been messing with the LDAP Health monitor, turning on the Security settings, but I dont believe this would actually check that a certificate is valid or not. I know with server side SSL configuration you can enable SSL authentication but would just stop traffic from flow, not actually drop a member out of the pool.

Any ideas ?

---

<div class="post-metadata">

**Author:** ![MVA](https://avatars.discourse-cdn.com/v4/letter/m/8dc957/32.png) [@MVA](https://community.f5.com/u/MVA)\
**Post date:** [October 6, 2015, 1:22pm UTC](https://community.f5.com/t/ldaps-monitor-with-certificate-expiration/54937/2 "2015-10-06T13:22:43Z")

</div>

Hi, we resolved this a few years back, if I recall, by enabling “Mandatory Attributes” in the health monitor. Test against an expired cert DC with this setting enabled/disabled.

---

<div class="post-metadata">

**Author:** ![mikeshimkus\_111](https://avatars.discourse-cdn.com/v4/letter/m/4af34b/32.png) [@mikeshimkus\_111](https://community.f5.com/u/mikeshimkus_111)\
**Post date:** [October 6, 2015, 2:24pm UTC](https://community.f5.com/t/ldaps-monitor-with-certificate-expiration/54937/3 "2015-10-06T14:24:35Z")

</div>

Hi danielpenna, I think you could use an iCall script to check for a valid cert and update the pool membership accordingly:

[https://devcentral.f5.com/articles/icall-all-new-event-based-automation-system](https://devcentral.f5.com/articles/icall-all-new-event-based-automation-system)

[https://devcentral.f5.com/codeshare?sid=288](https://devcentral.f5.com/codeshare?sid=288)

---

<div class="post-metadata">

**Author:** ![danielpenna](https://avatars.discourse-cdn.com/v4/letter/d/c68b51/32.png) [@danielpenna](https://community.f5.com/u/danielpenna)\
**Post date:** [October 6, 2015, 9:39pm UTC](https://community.f5.com/t/ldaps-monitor-with-certificate-expiration/54937/4 "2015-10-06T21:39:42Z")

</div>

Thanks Guys, will give Mel’s solution a try since its the simplest. If that doesn’t work, will give Mikes a go.

Will supply feedback on how I go.

Edit: Althought reading the context help on the F5 box, Mandatory attributes refer _I think_ to the actual healthcheck returning proper LDAP attributes. I remember reading that the basic LDAP healthcheck doesnt request attributes, this must enforce that. Unsure how the expired cert checking fits in but will give it a go.

Mandatory Attributes Specifies whether the target must include attributes in its response to be considered up.

No: Specifies that the system performs only a one-level search (based on the Filter setting), and does not require that the target returns any attributes.

Yes: Specifies that the system performs a sub-tree search, and if the target returns no attributes, the target is considered down.

---

<div class="post-metadata">

**Author:** ![SlipperyPete](https://avatars.discourse-cdn.com/v4/letter/s/ba9def/32.png) [@SlipperyPete](https://community.f5.com/u/SlipperyPete)\
**Post date:** [July 18, 2023, 2:21am UTC](https://community.f5.com/t/ldaps-monitor-with-certificate-expiration/54937/5 "2023-07-18T02:21:50Z")

</div>

Hi Daniel, interested to know how you went with this testing (if you remember back to 2015!). I am currently setting up a similar test for the same issue.
