Rank (7562) Views 7552 On Mon, Aug 31, 2009 5:29 AM, 162 days ago By Raphael Burri

Download

"Only registered users may download. Registration is free."

Version:
Importance:
Guide:
Who Reviewed
          
Who Viewed
    
0

0

Update Sept 13, 2009  - Version 1.0.0.260 now available for download. (more than 100 downloads of previous version the month or so it was available).

PKI Certificates serve to protect web sites by enabling SSL, secure cross-server communication and see many other uses.

The PKI Certificate Verification MP discovers PKI Certificates and Certificate Revocation Lists inside computers' local certificate stores. It helps preventing service interruptions caused by invalid certificates by alerting when: 

- a certificate’s lifetime is about to expire
 - a certificate’s lifetime has ended
 - a certificate has become invalid because of a different reason
 - a CRL has not been updated in a timely manner

The MP conatins a full set of inventory reports to help you audit certificates. The included guide contains detailed instructions on how to configure the MP. Click the Download button at right to download the management pack.


The PKI Certificate Verification MP was a jointly developed by Raphael Burri, Pete Zerger and Jaime Correia, specifically for release on the SystemCenterCentral.com site.
Look out for a multi part article series on MP authoring using the Authoring Console by the same authors. The series uses the PKI Certificate Verification MP as a sample to explain the concepts and procedures of writing a Management Pack. Part 1 is available on the site at the link below

MP Creation Zen: Part 1 - Concepts and Application Modeling

Latest Media (3)
Folder(s) | View All
Categories
  img Share This  img Retweet  
Bookmark this Post
Related Pages
Add New Comment (15)

on 9/2/2009 5:31:53 PM Update to 1.0.0.244: I have updated the MP. It ignores archived (superseded) certificates still present in the certificate stores.

on 9/2/2009 7:15:16 PM Hi! Great MP, very usefull !! Question for you, my certificates - about to expire is empty ? Any idea ? When I try to run a report about it I'm getting the error : The 'ColumnList' parameter is missing a value. Regards

on 9/3/2009 5:06:35 PM Francis, both the 'Certificates - About to Expire' view and the 'Expiring Certificates' report will only contain certificates that are going to expire within a month from now. If OpsMgr hasn't discovered any of them, the view will be empty and the report will unfortunately throw the 'ColumList' error.

on 10/15/2009 9:40:39 AM Hi Raphael Any clue on how-to troubleshoot PKI MP report. We installed the MP on our SP1-environment. The discovery and monitoring worked fine, the reporting didn't work(error pop-up) We have now upgraded to R2 and now the reports runs without any errors, but are all empty (only headers are shown) I have a test environment where we did the same thing (Firs SP1 and the R2) and here the reports work fine. Henrik

on 10/15/2009 11:02:02 AM Hendrik: The Reports are based on groups. Can you check of these groups (e.g. Valid Certificates) have been populated correctly? Also make sure you choose a reasonably large time window when running the report.

on 10/16/2009 5:32:44 PM Hi Raphael Thank you for your reply. Most groups are populated (Valid Certificates,Expired Certificates or Expiring Certificates) The only one I'm not sure about is "Certificates required by Windows Group" That has no members. I installed the MP last month so I have triied with a timespan 01-09-2009 to 16-10-2010 The report runs fairly quick and returms with report header, stating that the report includes 29 objects(I choose 29 Stores) Btw it's the Certifucate inventory report. Henrik

on 10/19/2009 2:36:28 PM Hendrik - I have an idea what could be the cause but I'll need you to run a couple of SQL queries. Could you drop me an email at: raburri (a) bluewin (dot) ch? So we can investigate the issue offline.

on 11/2/2009 4:38:29 PM To finish this off - It turned out that the collation of the DB instance was a case sensitive one. The databases itself was the correct collation. Thank you Raphael for your effort and patience,

on 12/15/2009 8:45:15 AM I have limited knowledge of compatibility between OpsMgr07 and 05. I would imagine that this MP is not compatible with 05, correct?

on 12/15/2009 9:48:53 AM Khue Absolutely, a OpsMgr 2007 MP can not run on MOM 2005. While it is possible to convert a MOM 2005 one for OpsMgr 2007, the other way round is not supported. The two products actually have (technically speaking) very little in common.

Add my comment
 Print  

Quick Links
Top Contributors
Pete Zerger
Points: 25235
Level: System Center Expert
Simon Skinner
Points: 20333
Level: System Center Expert
Tommy Gunn
Points: 19054
Level: System Center Expert
MadHatter
Points: 11573
Level: System Center Expert
Stefan Koell
Points: 10134
Level: System Center Expert