You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何查询Monit的SSL及其他配置选项?SSL配置问题求助

Monit配置渠道与SSL证书检测问题解答

一、查阅Monit完整配置选项的渠道

  • 本地手册页:执行man monit和man monitrc,这两个文档包含Monit所有支持的配置参数、语法细节和版本专属特性,比在线文档更全面准确。
  • 版本匹配:运行monit -V查看当前版本,不同版本的参数支持可能有差异,务必参考对应版本的手册页。
  • 源码与示例:Monit的GitHub仓库中,config目录下的示例配置文件和源码注释,能直观看到实际支持的配置项。

二、ca-directory/ca-file报错问题

你在ssl options块中使用ca-directory/ca-file导致报错,是因为这两个参数不能在单个check的ssl options里配置。它们属于全局SSL配置项,需要在monitrc的全局部分设置,比如:

# 全局配置(放在文件开头)
set ssl ca-directory /etc/ssl/example.com/
# 或者指定单个CA文件
set ssl ca-file /etc/ssl/example.com/example.com.crt

设置后,所有启用SSL验证的check都会使用这个CA配置。

三、证书过期检测未生效问题

你第二个配置中的certificate valid > 30 days指令,并非用于检测远程站点的SSL证书有效期,而是针对Monit自身的SSL证书(比如用于Monit Web界面或Monit与M/Monit通信的证书)。

要检测远程站点的SSL证书过期,正确的配置方式是将ssl check-expiry直接放在failed块中,结合protocol https使用:

check host site with address example.com
    start program = "/bin/true"
    stop program = "/bin/true"
    if failed
        port 443
        protocol https
        ssl check-expiry 30 days
    then alert

如果需要验证证书链的合法性,先在全局配置CA目录/文件,再启用ssl验证:

# 全局配置
set ssl ca-directory /etc/ssl/certs

# 检测配置
check host site with address example.com
    start program = "/bin/true"
    stop program = "/bin/true"
    if failed
        port 443
        protocol https
        ssl options { verify: enable }
        ssl check-expiry 30 days
    then alert

内容的提问来源于stack exchange,提问作者user3327338

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.28 15:44:57