1"use strict";(self.webpackChunktroubleshoot_docs=self.webpackChunktroubleshoot_docs||[]).push([["7343"],{7548(e,t,c){c.r(t),c.d(t,{metadata:()=>l,default:()=>h,frontMatter:()=>o,contentTitle:()=>s,toc:()=>a,assets:()=>r});var l=JSON.parse('{"id":"host-collect-analyze/certificatesCollection","title":"SSL/TLS Certificates Collection","description":"Collect and analyze SSL/TLS certificate chain data","source":"@site/docs/host-collect-analyze/certificatesCollection.md","sourceDirName":"host-collect-analyze","slug":"/host-collect-analyze/certificatesCollection","permalink":"/docs/host-collect-analyze/certificatesCollection","draft":false,"unlisted":false,"editUrl":"https://github.com/replicatedhq/troubleshoot/tree/main/docs/docs/host-collect-analyze/certificatesCollection.md","tags":[{"inline":true,"label":"host-collect-analyze","permalink":"/docs/tags/host-collect-analyze"}],"version":"current","frontMatter":{"title":"SSL/TLS Certificates Collection","description":"Collect and analyze SSL/TLS certificate chain data","tags":["host-collect-analyze"]},"sidebar":"docs","previous":{"title":"TLS Certificates","permalink":"/docs/host-collect-analyze/certificate"},"next":{"title":"Control Groups","permalink":"/docs/host-collect-analyze/cgroups"}}'),i=c(4848),n=c(8453);let o={title:"SSL/TLS Certificates Collection",description:"Collect and analyze SSL/TLS certificate chain data",tags:["host-collect-analyze"]},s,r={},a=[{value:"SSL/TLS Certificates Collection Collector",id:"ssltls-certificates-collection-collector",level:2},{value:"Parameters",id:"parameters",level:3},{value:"<code>paths</code> (Required)",id:"paths-required",level:4},{value:"Example Collector Definition",id:"example-collector-definition",level:3},{value:"Included Resources",id:"included-resources",level:3},{value:"<code>[collector-name].json</code>",id:"collector-namejson",level:4},{value:"SSL Certificatess Collection Analyzer",id:"ssl-certificatess-collection-analyzer",level:2},{value:"Example Analyzer Definition",id:"example-analyzer-definition",level:3}];function d(e){let t={a:"a",code:"code",h2:"h2",h3:"h3",h4:"h4",li:"li",p:"p",pre:"pre",ul:"ul",...(0,n.R)(),...e.components};return(0,i.jsxs)(i.Fragment,{children:[(0,i.jsx)(t.h2,{id:"ssltls-certificates-collection-collector",children:"SSL/TLS Certificates Collection Collector"}),"\n",(0,i.jsxs)(t.p,{children:["To collect certificate chain data on the host, use the ",(0,i.jsx)(t.code,{children:"certificatesCollection"})," collector."]}),"\n",(0,i.jsxs)(t.p,{children:["Unlike the ",(0,i.jsx)(t.a,{href:"/docs/host-collect-analyze/certificate/",children:(0,i.jsx)(t.code,{children:"certificate"})})," collector, which is designed to collect a specific certificate key pair, the ",(0,i.jsx)(t.code,{children:"certificatesCollection"})," collector focuses on collecting a collection of certificates from multiple file paths."]}),"\n",(0,i.jsx)(t.h3,{id:"parameters",children:"Parameters"}),"\n",(0,i.jsxs)(t.p,{children:["In addition to the ",(0,i.jsx)(t.a,{href:"/docs/collect/collectors/#shared-properties",children:"shared collector properties"}),", the ",(0,i.jsx)(t.code,{children:"certificatesCollection"})," collector accepts the following parameters:"]}),"\n",(0,i.jsxs)(t.h4,{id:"paths-required",children:[(0,i.jsx)(t.code,{children:"paths"})," (Required)"]}),"\n",(0,i.jsx)(t.p,{children:"Includes multiple file paths for certificates on the host."}),"\n",(0,i.jsx)(t.h3,{id:"example-collector-definition",children:"Example Collector Definition"}),"\n",(0,i.jsx)(t.pre,{children:(0,i.jsx)(t.code,{className:"language-yaml",children:"apiVersion: troubleshoot.sh/v1beta2\nkind: SupportBundle\nmetadata:\n name: certificates\nspec:\n hostCollectors:\n - certificatesCollection:\n paths: \n - /Users/ubuntu/apiserver-kubelet-client.crt\n - /etc/ssl/corp.crt\n"})}),"\n",(0,i.jsx)(t.h3,{id:"included-resources",children:"Included Resources"}),"\n",(0,i.jsxs)(t.p,{children:["The results of the ",(0,i.jsx)(t.code,{children:"certificatesCollection"})," collector are stored in the ",(0,i.jsx)(t.code,{children:"host-collectors/certificatesCollection"})," directory of the support bundle."]}),"\n",(0,i.jsx)(t.h4,{id:"collector-namejson",children:(0,i.jsx)(t.code,{children:"[collector-name].json"})}),"\n",(0,i.jsxs)(t.p,{children:["If the ",(0,i.jsx)(t.code,{children:"collectorName"})," field is not specified, it will be named ",(0,i.jsx)(t.code,{children:"certificatesCollection.json"}),"."]}),"\n",(0,i.jsx)(t.p,{children:"Example of the resulting file:"}),"\n",(0,i.jsx)(t.pre,{children:(0,i.jsx)(t.code,{children:'[\n {\n "certificatePath": "/Users/ubuntu/apiserver-kubelet-client.crt",\n "certificateChain": [\n {\n "certificate": "",\n "subject": "CN=kubernetes",\n "subjectAlternativeNames": [\n "kubernetes"\n ],\n "issuer": "CN=kubernetes",\n "notAfter": "2033-04-17T06:11:21Z",\n "notBefore": "2023-04-20T06:11:21Z",\n "isValid": true,\n "isCA": true\n }\n ],\n "message": "cert-valid"\n },\n {\n "certificatePath": "/etc/ssl/corp.crt",\n "message": "cert-missing"\n }\n]\n'})}),"\n",(0,i.jsx)(t.h2,{id:"ssl-certificatess-collection-analyzer",children:"SSL Certificatess Collection Analyzer"}),"\n",(0,i.jsx)(t.p,{children:"The certificates analyzer validates certificates and checks the expiration day, and can provide multiple outcomes such as:"}),"\n",(0,i.jsxs)(t.ul,{children:["\n",(0,i.jsxs)(t.li,{children:[(0,i.jsx)(t.code,{children:"Certificate is valid"}),": The certificate is valid and not expired."]}),"\n",(0,i.jsxs)(t.li,{children:[(0,i.jsx)(t.code,{children:"notAfter < Today + 4 days"}),": The certificate is about to expired in 4 days."]}),"\n",(0,i.jsxs)(t.li,{children:[(0,i.jsx)(t.code,{children:"notAfter < Today"}),": The certificate has expired."]}),"\n"]}),"\n",(0,i.jsx)(t.h3,{id:"example-analyzer-definition",children:"Example Analyzer Definition"}),"\n",(0,i.jsx)(t.pre,{children:(0,i.jsx)(t.code,{className:"language-yaml",children:'apiVersion: troubleshoot.sh/v1beta2\nkind: SupportBun
1dle\nmetadata:\n name: certificate\nspec:\n hostAnalyzers:\n - certificatesCollection:\n outcomes:\n - pass:\n message: Certificate is valid\n - warn:\n when: "notAfter < Today + 4 days"\n message: Certificate is about to expire\n - fail:\n when: "notAfter < Today"\n message: Certificate is expired\n'})})]})}function h(e={}){let{wrapper:t}={...(0,n.R)(),...e.components};return t?(0,i.jsx)(t,{...e,children:(0,i.jsx)(d,{...e})}):d(e)}},8453(e,t,c){c.d(t,{R:()=>o,x:()=>s});var l=c(6540);let i={},n=l.createContext(i);function o(e){let t=l.useContext(n);return l.useMemo(function(){return"function"==typeof e?e(t):{...t,...e}},[t,e])}function s(e){let t;return t=e.disableParentContext?"function"==typeof e.components?e.components(i):e.components||i:o(e.components),l.createElement(n.Provider,{value:t},e.children)}}}]);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.