Monitors the expiry of the certificates used by an Active Directory Federation Services (ADFS) host.
A special agent connects to the ADFS host and collects all relevant certificates in one place, so you get an early warning long before any of them expires:
- Token-signing and token-encryption certificates, read from the ADFS federation metadata (/federationmetadata/2007-06/federationmetadata.xml). ADFS publishes the same certificate inside several role descriptors — these duplicates are removed automatically (dedup by SHA-256 fingerprint), so each certificate is monitored exactly once. A running index is added only when a real second certificate exists, e.g. during a signing certificate rollover.
- The Service communications certificate (the TLS certificate of the ADFS web endpoint). This one is not part of the federation metadata, so the agent reads it directly from the TLS handshake — the certificate that would otherwise be easy to miss.
For every certificate a service is created showing the remaining validity in days, with the days-remaining value available as a metric for graphing. Warning and critical thresholds are freely configurable (default 30 / 14 days).
Configuration is done through a WATO rule ("ADFS Certificate Monitoring") and includes:
- optional HTTP(S) proxy for the metadata request,
- an option to disable TLS verification for internal/self-signed setups,
- a debug switch that prints detailed diagnostics (metadata URL, HTTP status, found and deduplicated certificates, full tracebacks) for troubleshooting.
Uploaded on: 24 Jul 2026
Downloads: 0
Built on Checkmk version: 2.4.0p19
Minimum Checkmk version required: 2.4.0
MKP MD5 hash: 5caed33609228a50ebb5f644cf55813e