Description

Plugin monitors installed Sophos certificates for their validity via the Sophos XML API. Built-in ruleset for WARN/CRIT values. All data is processed within the RAM, Private Keys are always ignored for security, per-user-certificates are ignored by default.

SETUP:

  1. create sophos profile, api user and configure api access:

    • log on to firewall
    • System > Profiles > Device access > Add: create new profile (i. e. Profile name "API admin" with Read-write permissions for "Objects", "Network" ("Download certificates" and "Other certificate configuration")
    • Configure > Authentication > Users > Add: new user (i. E. named "checkmk"), User type "Administrator" and give him the profile added before
    • System > Administration > API access > activate API access and add your Checkmk as IP host to the list, hit apply
  2. api documentation:

    • https://docs.sophos.com/nsg/sophos-firewall/19.0/Help/en-us/webhelp/onlinehelp/AdministratorHelp/BackupAndFirmware/API/APIAllowAccess/index.html
    • https://docs.sophos.com/nsg/sophos-firewall/19.0/Help/en-us/webhelp/onlinehelp/AdministratorHelp/BackupAndFirmware/API/APIConfiguration/index.html
    • https://docs.sophos.com/nsg/sophos-firewall/19.0/Help/en-us/webhelp/onlinehelp/AdministratorHelp/Certificates/HowToArticles/CertificatesAPIGetCertificate/index.html
  3. Integration:

    • Configure API credentials under Setup > Agents > Other integrations > Sophos XGS Certificates
  4. Host configuration:

    • Monitoring agents > Checkmk agent /API integrations > Configured API integrations
Version 1.0.0
Latest version

Uploaded on: 21 Jul 2026

Downloads: 0

Built on Checkmk version: 2.4.0p31

Minimum Checkmk version required: 2.4.0

MKP MD5 hash: e3893c02909cbf5b8e013d5adf61b801