Using let's encrypt certificates for CheckMK Appliance

5 votes

Running CheckMK on a native Linux Server it's well described to implement automated Let's encrypt automatic certificate change:
https://docs.checkmk.com/latest/en/omd_https.html#letsencrypt
Sadly the prerequisites for using it are not installed on the Appliance by default.
Following https://docs.checkmk.com/latest/en/appliance_usage.html#service it's not clear if it's allowed to install the needed packages without loosing support.

With March 2027 publich webserver certificates will have a lifetime of just 100 days (2029 only 47 days; https://www.digicert.com/blog/tls-certificate-lifetimes-will-officially-reduce-to-47-days). To reduce efforts by administrators with a published checkmk instance it will be very helpful to bring the packages in the appliance firmware.
It would be even better if we can configure it in the Appliance Webconfiguration frontend.

Under consideration Appliance Suggested by: Jan Upvoted: 28 May Comments: 0

Comments: 0