PageSourceSearch

https://troubleshoot.sh/assets/js/05544e15.270e8daa.js

js troubleshoot.sh collected 2026-10-02 16:22:00 UTC 6,973 bytes, 1 lines download raw bytes

1"use strict";(self.webpackChunktroubleshoot_docs=self.webpackChunktroubleshoot_docs||[]).push([["7343"],{7548(e,t,c){c.r(t),c.d(t,{metadata:()=>l,default:()=>h,frontMatter:()=>o,contentTitle:()=>s,toc:()=>a,assets:()=>r});var l=JSON.parse('{"id":"host-collect-analyze/certificatesCollection","title":"SSL/TLS Certificates Collection","description":"Collect and analyze SSL/TLS certificate chain data","source":"@site/docs/host-collect-analyze/certificatesCollection.md","sourceDirName":"host-collect-analyze","slug":"/host-collect-analyze/certificatesCollection","permalink":"/docs/host-collect-analyze/certificatesCollection","draft":false,"unlisted":false,"editUrl":"https://github.com/replicatedhq/troubleshoot/tree/main/docs/docs/host-collect-analyze/certificatesCollection.md","tags":[{"inline":true,"label":"host-collect-analyze","permalink":"/docs/tags/host-collect-analyze"}],"version":"current","frontMatter":{"title":"SSL/TLS Certificates Collection","description":"Collect and analyze SSL/TLS certificate chain data","tags":["host-collect-analyze"]},"sidebar":"docs","previous":{"title":"TLS Certificates","permalink":"/docs/host-collect-analyze/certificate"},"next":{"title":"Control Groups","permalink":"/docs/host-collect-analyze/cgroups"}}'),i=c(4848),n=c(8453);let o={title:"SSL/TLS Certificates Collection",description:"Collect and analyze SSL/TLS certificate chain data",tags:["host-collect-analyze"]},s,r={},a=[{value:"SSL/TLS Certificates Collection Collector",id:"ssltls-certificates-collection-collector",level:2},{value:"Parameters",id:"parameters",level:3},{value:"<code>paths</code> (Required)",id:"paths-required",level:4},{value:"Example Collector Definition",id:"example-collector-definition",level:3},{value:"Included Resources",id:"included-resources",level:3},{value:"<code>[collector-name].json</code>",id:"collector-namejson",level:4},{value:"SSL Certificatess Collection Analyzer",id:"ssl-certificatess-collection-analyzer",level:2},{value:"Example Analyzer Definition",id:"example-analyzer-definition",level:3}];function d(e){let t={a:"a",code:"code",h2:"h2",h3:"h3",h4:"h4",li:"li",p:"p",pre:"pre",ul:"ul",...(0,n.R)(),...e.components};return(0,i.jsxs)(i.Fragment,{children:[(0,i.jsx)(t.h2,{id:"ssltls-certificates-collection-collector",children:"SSL/TLS Certificates Collection Collector"}),"\n",(0,i.jsxs)(t.p,{children:["To collect certificate chain data on the host, use the ",(0,i.jsx)(t.code,{children:"certificatesCollection"})," collector."]}),"\n",(0,i.jsxs)(t.p,{children:["Unlike the ",(0,i.jsx)(t.a,{href:"/docs/host-collect-analyze/certificate/",children:(0,i.jsx)(t.code,{children:"certificate"})})," collector, which is designed to collect a specific certificate key pair, the ",(0,i.jsx)(t.code,{children:"certificatesCollection"})," collector focuses on collecting a collection of certificates from multiple file paths."]}),"\n",(0,i.jsx)(t.h3,{id:"parameters",children:"Parameters"}),"\n",(0,i.jsxs)(t.p,{children:["In addition to the ",(0,i.jsx)(t.a,{href:"/docs/collect/collectors/#shared-properties",children:"shared collector properties"}),", the ",(0,i.jsx)(t.code,{children:"certificatesCollection"})," collector accepts the following parameters:"]}),"\n",(0,i.jsxs)(t.h4,{id:"paths-required",children:[(0,i.jsx)(t.code,{children:"paths"})," (Required)"]}),"\n",(0,i.jsx)(t.p,{children:"Includes multiple file paths for certificates on the host."}),"\n",(0,i.jsx)(t.h3,{id:"example-collector-definition",children:"Example Collector Definition"}),"\n",(0,i.jsx)(t.pre,{children:(0,i.jsx)(t.code,{className:"language-yaml",children:"apiVersion: troubleshoot.sh/v1beta2\nkind: SupportBundle\nmetadata:\n  name: certificates\nspec:\n  hostCollectors:\n    - certificatesCollection:\n        paths: \n        - /Users/ubuntu/apiserver-kubelet-client.crt\n        - /etc/ssl/corp.crt\n"})}),"\n",(0,i.jsx)(t.h3,{id:"included-resources",children:"Included Resources"}),"\n",(0,i.jsxs)(t.p,{children:["The results of the ",(0,i.jsx)(t.code,{children:"certificatesCollection"})," collector are stored in the ",(0,i.jsx)(t.code,{children:"host-collectors/certificatesCollection"})," directory of the support bundle."]}),"\n",(0,i.jsx)(t.h4,{id:"collector-namejson",children:(0,i.jsx)(t.code,{children:"[collector-name].json"})}),"\n",(0,i.jsxs)(t.p,{children:["If the ",(0,i.jsx)(t.code,{children:"collectorName"})," field is not specified, it will be named ",(0,i.jsx)(t.code,{children:"certificatesCollection.json"}),"."]}),"\n",(0,i.jsx)(t.p,{children:"Example of the resulting file:"}),"\n",(0,i.jsx)(t.pre,{children:(0,i.jsx)(t.code,{children:'[\n	{\n		"certificatePath": "/Users/ubuntu/apiserver-kubelet-client.crt",\n		"certificateChain": [\n			{\n				"certificate": "",\n				"subject": "CN=kubernetes",\n				"subjectAlternativeNames": [\n					"kubernetes"\n				],\n				"issuer": "CN=kubernetes",\n				"notAfter": "2033-04-17T06:11:21Z",\n				"notBefore": "2023-04-20T06:11:21Z",\n				"isValid": true,\n				"isCA": true\n			}\n		],\n		"message": "cert-valid"\n	},\n	{\n		"certificatePath": "/etc/ssl/corp.crt",\n		"message": "cert-missing"\n	}\n]\n'})}),"\n",(0,i.jsx)(t.h2,{id:"ssl-certificatess-collection-analyzer",children:"SSL Certificatess Collection Analyzer"}),"\n",(0,i.jsx)(t.p,{children:"The certificates analyzer validates certificates and checks the expiration day, and can provide multiple outcomes such as:"}),"\n",(0,i.jsxs)(t.ul,{children:["\n",(0,i.jsxs)(t.li,{children:[(0,i.jsx)(t.code,{children:"Certificate is valid"}),": The certificate is valid and not expired."]}),"\n",(0,i.jsxs)(t.li,{children:[(0,i.jsx)(t.code,{children:"notAfter < Today + 4 days"}),": The certificate is about to expired in 4 days."]}),"\n",(0,i.jsxs)(t.li,{children:[(0,i.jsx)(t.code,{children:"notAfter < Today"}),":  The certificate has expired."]}),"\n"]}),"\n",(0,i.jsx)(t.h3,{id:"example-analyzer-definition",children:"Example Analyzer Definition"}),"\n",(0,i.jsx)(t.pre,{children:(0,i.jsx)(t.code,{className:"language-yaml",children:'apiVersion: troubleshoot.sh/v1beta2\nkind: SupportBun
1dle\nmetadata:\n  name: certificate\nspec:\n  hostAnalyzers:\n    - certificatesCollection:\n        outcomes:\n          - pass:\n              message: Certificate is valid\n          - warn:\n              when: "notAfter < Today + 4 days"\n              message: Certificate is about to expire\n          - fail:\n              when: "notAfter < Today"\n              message: Certificate is expired\n'})})]})}function h(e={}){let{wrapper:t}={...(0,n.R)(),...e.components};return t?(0,i.jsx)(t,{...e,children:(0,i.jsx)(d,{...e})}):d(e)}},8453(e,t,c){c.d(t,{R:()=>o,x:()=>s});var l=c(6540);let i={},n=l.createContext(i);function o(e){let t=l.useContext(n);return l.useMemo(function(){return"function"==typeof e?e(t):{...t,...e}},[t,e])}function s(e){let t;return t=e.disableParentContext?"function"==typeof e.components?e.components(i):e.components||i:o(e.components),l.createElement(n.Provider,{value:t},e.children)}}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.