PKI Certificate Verification MP
By Raphael Burri on 3/21/2012 2:56:11 PM • Rank (76285) • Views 76775
20

20

Update March 20, 2012 - Version 1.0.1.20 now available for download.
Over 2500 downloads of previous versions.

Compatible with OpsMgr 2007 R2 and OpsMgr 2012

PKI Certificates serve to protect web sites by enabling SSL, secure cross-server communication and see many other uses.
The PKI Certificate Verification MP discovers PKI Certificates and Certificate Revocation Lists inside computers' local certificate stores. It helps preventing service interruptions caused by invalid certificates by alerting when: 

- a certificate’s lifetime is about to expire
 - a certificate’s lifetime has ended
 - a certificate has become invalid because of a different reason
 - a CRL has not been updated in a timely manner

The MP conatins a full set of inventory reports to help you audit certificates. The included guide contains detailed instructions on how to configure the MP. Click the Download button at bottom to download the management pack.


The PKI Certificate Verification MP was a jointly developed by Raphael Burri, Pete Zerger and Jaime Correia, specifically for release on the SystemCenterCentral.com site.
Look out for a multi part article series on MP authoring using the Authoring Console by the same authors. The series uses the PKI Certificate Verification MP as a sample to explain the concepts and procedures of writing a Management Pack. Part 1 is available on the site at the link below

MP Creation Zen: Part 1 - Concepts and Application Modeling

Change History
Please read the release notes carefully before attempting an upgrade of any previously released version.

Changes between 1.0.1.15 (March 2011) and 1.0.1.20 (March 2012) 

  • Corrected a discovery bug that would hit when a server's locale was non-US and CA certificates were found in the store.
  • Fixed some spelling issues in display strings
  • Verified OpsMgr 2012 compatibility

Changes between 1.0.0.288 (released Jun 17, 2010) and 1.0.1.15

  • Improved discovery of Issued to and Issued by properties: Will use Subject Alternative Name if certificate doesn’t have a subject and will correctly extract the subject if CN= isn’t encountered on the first line of the subject string.
  • Additional certificate property: CA Version (based on extension szOID_CERTSRV_CA_VERSION). If this property holds a value, that certificate is a Windows CA one.
  • Does no longer discover superseded CA certificates. Evaluation is based on the CA Version property. Additional override to change that behavior if required.
  • Monitors will not mark superseded CA certificates as expired if their discovery is enabled.
  • Expose script timeout as an overidable parameter
  • Changed alert priority to ‘Low’.
  • Broke upgrade path to avoid potential agent stale issues when upgrading from V 1.0.0.280 or earlier.

 

Changes between 1.0.0.280 (released April 19, 2010) and 1.0.0.280

 

 

  • Much more relaxed script timing
  • cook down safe timing override option
  • public certificate store data source (to add custom certificate stores)
  • better compatibility with legacy Operation Systems (2000 & 2003)
  • introduces a Release Notes document; which is a must read for updates from any previous release to 1.0.0.288!

Only registered users may download. Registration is free.

Comments (63) - Comment RSS
SB wrote: on Feb 23, 2012 05:30 AM
Hi
We have an environment with several 2003 and 2008 servers. Running OpsMgr 2007 R2. We have implemented the Management Pack and followed the guide, but we have run into an issue that we cannot seem to solve. The Certificate discovery is not run (Configuration - certificate store roll up is not monitored) on some servers, but not all and it is not a clear pattern to which servers the certificates are discovered on and not (both 2003 and 2008). We have the same issue in our QA environment as well but not on the same servers as in our Production environment. Do you have any idea why this happens, troubleshooing ideas, known issues? Thanks a lot!
ben3843100 wrote: on Mar 21, 2012 01:18 PM
Is the PKI Certificate Verification MP download still available? I haven't been able to find it anywhere. The link seems dead.
Raphael Burri wrote: on Mar 21, 2012 02:59 PM
Hi Ben
I just checked and the download seems to work for me. You need to be logged on to the site and then you should be able to click the "Download" button. The file name is "PKI_Certificate_MP_V1.0.1.20.zip".
Raphael
ben3843100 wrote: on Mar 21, 2012 03:16 PM
It seems they just fixed the link. Thanks for the prompt response whomever is responsible.
mike baker wrote: on Apr 09, 2012 10:09 AM
can this be targeted to specific certificate templates that are issued to endpoints?
iditb wrote: on Apr 19, 2012 03:49 AM
Hi ,
can i monitor only the root ca server certificates and not the personal certificates?

Thanks
jasonbreeze wrote: on Apr 27, 2012 12:16 PM
Would like to see the ability to discover service account certificate stores and certificates. They are here: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Services
Maekee wrote: on May 14, 2012 04:01 AM
Hi, i am having problems discovering my CRL's. The Certificates are discovered just fine, the Discover Certificate Revocation Lists (locally) Object Discovery is enabled. Whats next?
PEM wrote: on May 17, 2012 09:42 AM
hi, can we override lifespan monitor only for intermediate store?
Siva Darsi wrote: on May 21, 2012 05:16 AM
Hi, I downloaded this MP & tested in my LAB, its working fine ( i was asked to monitor only the personal store for now). Thanks a lot.


Thanks,
Siva
Add your Comment
Latest Media - View All Media (2)
      


Who Viewed
Who Reviewed
Categories
Tags
Certificate Management Pack
Related Pages
Shortened URL
http://tinyurl.com/yenjj4d

Top Contributors
Featured Members
Pete Zerger
Points: 72684
Level: System Center Expert
Tommy Gunn
Points: 47503
Level: System Center Expert
Simon Skinner
Points: 40804
Level: System Center Expert
Andreas Zuckerhut
Points: 30700
Level: System Center Expert
Stefan Koell
Points: 30179
Level: System Center Expert