question

Steve-1095 avatar image
0 Votes"
Steve-1095 asked Steve-1095 edited

Lifetime of OCSP certificates Scom best practise

We have an OCSP certificate with a validity period of 6 weeks, and a renewal period of 1 week
Scom generates alerts 21 days before the certificate expires.
I can make an override for the Certificate lifetimespan to eg 5 days
But if the certificate is renewed this override is no longer valid as the thumbprint has changed
Is it possible to make an override for a certificate with such a short validity period?
Thanks

msc-operations-manager
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

CyrAz avatar image
0 Votes"
CyrAz answered CyrAz edited

You could create a SCOM group that would dynamically contain every OCSP certificate based on their template, and then create the override for that group.
Or simply exclude the OCSP certificates from the certificate discovery entirely.

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Steve-1095 avatar image
0 Votes"
Steve-1095 answered CyrAz commented

Thanks CyrAz.
How to create a SCOM group that would dynamically contain every OCSP certificate based on their template?
141348-ocsp-group.jpg



Is this the way to create de Scom group?
Thanks


ocsp-group.jpg (69.7 KiB)
· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Yes, that should work (assuming this is the proper Template name, I can't check myself right now)

0 Votes 0 ·
Steve-1095 avatar image
0 Votes"
Steve-1095 answered Steve-1095 edited

We manage multiple customers with scom. A gateway server is installed at every customer. This problem occurs with 1 customer.
In the print screen you see part of the display name as preview, but I ended up using the template name. Without spaces.
I've created the group, but don't see any members (yet).
Is it also better to mention the domain of the client in the discovery rule?

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.