eG Monitoring
 

Measures reported by CtxNsSslCertTest

In the Citrix NetScaler VPX/MPX appliance, SSL certificates are used to establish the secure connection between the users and the web applications that are accessed by the users via the appliance. The SSL certificates are important to maintain the confidentiality of data and also organization’s reputation and integrity. The SSL certificates are small data files that digitally bind a cryptographic key to organization’s details. With the SSL certificates, data is encrypted prior to being transmitted via Internet, and the encrypted data can be decrypted only by the application server to which you actually send it. This ensures that the information you transmit will not be stolen. Typically, the SSL certificates are prepared with a specific validity time beyond which the connections will be no longer secure. If the certificates are suddenly expires, the users will no longer be able to access the applications and encounter the applications with the expired SSL certificate. To avoid this, administrators should proactively identify certificates nearing expiry and renew the certificates before expiry. This is where the CtxNsSslCertTest test helps administrators!

This test monitors all the SSL certificates that have been configured for the Citrix NetScaler VPX/MPX appliance. For each SSL certificate, this test captures the expiry date of the SSL certificates, computes how long each certificate will remain valid, and proactively alerts administrators if any certificate is nearing expiry. In addition, this test also reports the current status of each certificate and checks whether the expiry monitor for each SSL certificate has been enabled or not.

Outputs of the test : One set of results for every SSL certificate on the NetScaler VPX/MPX being monitored.

Note:

This test will be applicable only for the Windows hosts 2012 and above.

The measures made by this test are as follows:

Measurement Description Measurement Unit Interpretation
Days_to_expire Indicates the number of days from the current day for which this SSL certificate will be valid. Number A high value is preferred for this measure. A low value of this measure indicates that the SSL certificate is going to be expired soon and you should update the certificate before it expires.

The detailed diagnosis of this measure reveals the key file name, the format of the certificate file and the notification period beyond which the alert will be generated.
Status Indicates the current status of this SSL certificate.   The values that this measure can report and their numeric equivalents are listed in the table below:

Measure Value Numeric Value
Valid 0
Expired 1

Note:

By default, this measure reports the above-mentioned Measure Values to indicate the state of the SSL certificate. However, in the graph of this measure the SSL certificate state will be represented using the corresponding numeric equivalents only - i.e., 0 or 1.

Expiry_monitor Indicates whether/not the Expiry Monitor has been enabled for this SSL certificate.   The values that this measure can report and their numeric equivalents are listed in the table below:

Measure Value Numeric Value
Enabled 0
Disabled 1

Note:

By default, this measure reports the above-mentioned Measure Values to indicate whether the Expiry Monitor has been enabled for each SSL certificate. However, in the graph of this measure the SSL certificate state will be represented using the corresponding numeric equivalents only - i.e., 0 or 1.