Nagios xi and nsclient++ certificate based communication

This support forum board is for support questions relating to Nagios XI, our flagship commercial network monitoring solution.
Locked
tejanagios
Posts: 24
Joined: Wed Feb 03, 2016 6:45 am

Nagios xi and nsclient++ certificate based communication

Post by tejanagios »

HI,

Please let me know the following:

I am using Nsclient++(x64) on Windows server 2012 R2; we have about some 30 of them.
I am using the following:
NSCP version 0.4.3
running system checks using check_nt and powershell scripts using check_nrpe.
I am looking at locking down the service and encrypting the communication channel as well as providing authentication. I can see that when i install NSCP the default mode is the safe mode, the client certificates are under Nsclient++\Security folder , iahve ca.pem, certificate.pem and nrpe_dh-512.pem files.

IN this regards, what configuration settings do i need to do, to enable certificate based encryption and authentication. please let me know. I am attaching my current nsc.ini file along for you to point me where things need changing. thank you.

P.S. if there are any other methods that can improve security please suggest.
You do not have the required permissions to view the files attached to this post.
rkennedy
Posts: 6579
Joined: Mon Oct 05, 2015 11:45 am

Re: Nagios xi and nsclient++ certificate based communication

Post by rkennedy »

Take a look at this document - https://www.medin.name/blog/2012/12/02/ ... ntication/

It's written by Michael himself, and has quite a bit of information available in regards to the certificate based authentication.
Former Nagios Employee
Locked