如何查询Monit的SSL及其他配置选项?SSL配置问题求助
Monit配置渠道与SSL证书检测问题解答
一、查阅Monit完整配置选项的渠道
- 本地手册页:执行
man monit和man monitrc,这两个文档包含Monit所有支持的配置参数、语法细节和版本专属特性,比在线文档更全面准确。 - 版本匹配:运行
monit -V查看当前版本,不同版本的参数支持可能有差异,务必参考对应版本的手册页。 - 源码与示例:Monit的GitHub仓库中,
config目录下的示例配置文件和源码注释,能直观看到实际支持的配置项。
二、ca-directory/ca-file报错问题
你在ssl options块中使用ca-directory/ca-file导致报错,是因为这两个参数不能在单个check的ssl options里配置。它们属于全局SSL配置项,需要在monitrc的全局部分设置,比如:
# 全局配置(放在文件开头) set ssl ca-directory /etc/ssl/example.com/ # 或者指定单个CA文件 set ssl ca-file /etc/ssl/example.com/example.com.crt
设置后,所有启用SSL验证的check都会使用这个CA配置。
三、证书过期检测未生效问题
你第二个配置中的certificate valid > 30 days指令,并非用于检测远程站点的SSL证书有效期,而是针对Monit自身的SSL证书(比如用于Monit Web界面或Monit与M/Monit通信的证书)。
要检测远程站点的SSL证书过期,正确的配置方式是将ssl check-expiry直接放在failed块中,结合protocol https使用:
check host site with address example.com start program = "/bin/true" stop program = "/bin/true" if failed port 443 protocol https ssl check-expiry 30 days then alert
如果需要验证证书链的合法性,先在全局配置CA目录/文件,再启用ssl验证:
# 全局配置 set ssl ca-directory /etc/ssl/certs # 检测配置 check host site with address example.com start program = "/bin/true" stop program = "/bin/true" if failed port 443 protocol https ssl options { verify: enable } ssl check-expiry 30 days then alert
内容的提问来源于stack exchange,提问作者user3327338
相关产品推荐
相关产品推荐

