Findings
This document is bilingual (German and English) because ids and messages stay the same in both languages.
Jeder Befund hat eine stabile Id (z. B. TLS_CERT_EXPIRING) und eine Kategorie. Einmal veröffentlicht, wird eine Id nie umbenannt oder umgewidmet. Die Ids aus dem kostenlosen ADCS Health Check werden unverändert übernommen.
Every finding has a stable id and a category. Once published, an id is never renamed or reused. Ids from the free ADCS Health Check are kept as they are.
Schwere / Severity: OK · Info (Hinweis / notice) · Warning (Warnung) · Critical (Kritisch) – wie im Health Check. Zustände je Befund / states: offen, bestätigt, stumm bis, ignoriert; erledigt, sobald der Befund nicht mehr auftritt (bleibt im Verlauf). / open, acknowledged, muted until, ignored; resolved when it no longer occurs.
{0}, {1} … sind Platzhalter. / are placeholders.
TLS · Netzwerk-Scan / network scan
Objekt / object: Endpunkt host:port. Ablauf-Schwellwerte für Server und Geräte: Standard 30 Tage (Warnung) und 7 Tage (kritisch), einstellbar unter Einstellungen > Schwellwerte. / Expiry thresholds for servers and devices: 30 and 7 days by default.
| Id | Kategorie / Category | Schwere / Severity | Deutsch | English |
|---|---|---|---|---|
TLS_CERT_OK | TLS | OK | Zertifikat noch {0} Tage gültig (bis {1}). | Certificate valid for {0} more days (until {1}). |
TLS_CERT_EXPIRING | TLS | Warning / Critical | Zertifikat läuft in {0} Tagen ab ({1}). | Certificate expires in {0} days ({1}). |
TLS_CERT_EXPIRED | TLS | Critical | Zertifikat seit {0} Tagen abgelaufen ({1}). | Certificate expired {0} days ago ({1}). |
TLS_SELF_SIGNED | TLS | Info | Selbstsigniertes Zertifikat. | Self-signed certificate. |
TLS_UNTRUSTED_ISSUER | TLS | Info | Aussteller „{0}“ ist dem certmon-Server nicht vertrauenswürdig. | Issuer "{0}" is not trusted by the certmon server. |
TLS_NAME_MISMATCH | TLS | Warning | Name „{0}“ ist nicht im Zertifikat enthalten ({1}). | Name "{0}" is not in the certificate ({1}). |
TLS_WEAK_KEY | TLS | Warning | Schwacher Schlüssel: {0} {1} Bit. | Weak key: {0} {1} bit. |
TLS_WEAK_HASH | TLS | Warning | Schwacher Signaturalgorithmus: {0}. | Weak signature algorithm: {0}. |
TLS_OLD_PROTOCOL | TLS | Info | Der Endpunkt handelt nur {0} aus. | The endpoint negotiates only {0}. |
TLS_ENDPOINT_UNREACHABLE | TLS | Warning | Der Endpunkt antwortet nicht mehr mit TLS ({0}). | The endpoint no longer answers with TLS ({0}). |
Hinweise / notes:
- Name wird nur geprüft, wenn das Ziel als Hostname eingetragen ist (dann auch per SNI angefragt). Bei reinen IP-Adressen gibt es keinen
TLS_NAME_MISMATCH. / The name is only checked for targets entered as host names. - Aussteller „vertrauenswürdig“ heißt: Die Kette endet an einer Stammzertifizierungsstelle, der der certmon-Server vertraut (öffentliche CA oder eigene Unternehmens-CA). certmon lädt dafür nichts nach (keine AIA-/CRL-Abrufe). / Trusted means the chain ends at a root the certmon server trusts; nothing is downloaded for this.
- Nicht erreichbar erst nach zwei Fehlversuchen in Folge; beim ersten Fehlversuch bleiben die bisherigen Befunde unverändert. / Unreachable only after two failed runs in a row.
PKI-Kern / PKI core
Dieselben Ids und Schweregrade wie der ADCS Health Check 0.2.1; neu in certmon sind CA_REQUESTS_PENDING, CA_REQUESTS_FAILED und TEMPLATE_UNUSED. Schwellwerte: CA-Zertifikate 365/90 Tage, Sperrlisten mit langer Laufzeit (ab 30 Tagen, Offline-CA) und ausgestellte Zertifikate 30/7 Tage; kurzlebige Sperrlisten gelten als überfällig, wenn weniger als 20 % ihrer Laufzeit übrig sind und keine neue Version vorliegt. / Same ids and severities as the Health Check; new in certmon: pending/failed requests and unused templates.
Die Texte weichen im Wortlaut leicht vom Health Check ab (Zahlen und Fundorte als Platzhalter, damit jeder Benutzer den Befund in seiner Sprache sieht). / Texts differ slightly from the Health Check (numbers and locations as placeholders).
| Id | Kategorie / Category | Schwere / Severity | Deutsch | English |
|---|---|---|---|---|
CA_NONE | CAS | Info | Keine Enterprise-CA im AD registriert. | No enterprise CA is registered in AD. |
CA_PING_OK | CAS | OK | CA-Dienst auf {0} antwortet. {1} Vorlagen veröffentlicht. | CA service on {0} is responding. {1} templates published. |
CA_PING_FAILED | CAS | Critical | CA-Dienst auf {0} antwortet nicht (certutil -ping, Code {1}). | CA service on {0} is not responding (certutil -ping, code {1}). |
CA_PING_SKIPPED | CAS | Info | certutil.exe ist auf dem certmon-Server nicht verfügbar, Erreichbarkeit nicht geprüft. | certutil.exe is not available on the certmon server, availability not checked. |
CA_REQUESTS_PENDING | CAS | Info | {0} ausstehende Anforderungen, die älteste seit {1}. | {0} pending requests, the oldest since {1}. |
CA_REQUESTS_FAILED | CAS | Info / Warning (ab 20) | {0} fehlgeschlagene oder abgelehnte Anforderungen in den letzten 24 Stunden. | {0} failed or denied requests in the last 24 hours. |
CA_CERT_OK | CA_CERTS | OK | Noch {0} Tage gültig (bis {1}). Fundort: {2}. | Valid for another {0} days (until {1}). Found in: {2}. |
CA_CERT_EXPIRING | CA_CERTS | Warning / Critical | Läuft in {0} Tagen ab ({1}). Fundort: {2}. | Expires in {0} days ({1}). Found in: {2}. |
CA_CERT_EXPIRED | CA_CERTS | Critical | Seit {0} Tagen abgelaufen ({1}). Fundort: {2}. | Expired {0} days ago ({1}). Found in: {2}. |
CA_CERT_EXPIRED_LEFTOVER | CA_CERTS | Info | {0} abgelaufene(s) CA-Zertifikat(e) liegen noch im AD ({1}). Abgelaufen am: {2}. | {0} expired CA certificate(s) still published in AD ({1}). Expired on: {2}. |
CA_CERT_WEAK_KEY | CA_CERTS | Warning | RSA-Schlüssel mit nur {0} Bit. | RSA key with only {0} bits. |
CA_CERT_WEAK_HASH | CA_CERTS | Warning | Signiert mit veraltetem Hash-Verfahren {0}. | Signed with the outdated hash algorithm {0}. |
CA_CHAIN_OK | CA_CERTS | OK | Zertifikatskette gültig, Sperrstatus prüfbar ({0} Zertifikate). | Certificate chain is valid, revocation status can be checked ({0} certificates). |
CA_CHAIN_ERROR | CA_CERTS | Warning / Critical | Kettenprüfung: {0} | Chain validation: {0} |
NTAUTH_OK | NTAUTH | OK | Aktuelles CA-Zertifikat ist im NTAuth-Speicher eingetragen. | Current CA certificate is present in the NTAuth store. |
NTAUTH_MISSING | NTAUTH | Warning | Aktuelles CA-Zertifikat fehlt im NTAuth-Speicher. | Current CA certificate is missing from the NTAuth store. |
ISSUED_SUMMARY | ISSUED | Info | {0} gültige ausgestellte Zertifikate, {1} Inhaber/Vorlagen-Kombinationen, davon {2} laufen in den nächsten {3} Tagen ab und sind noch nicht erneuert. | {0} valid issued certificates, {1} subject/template combinations; {2} of them expire within the next {3} days and have not been renewed yet. |
ISSUED_MORE | ISSUED | Info | Weitere {0} ablaufende Zertifikate nicht einzeln aufgeführt. | {0} more expiring certificates are not listed individually. |
ISSUED_CERT_EXPIRING | ISSUED | Warning / Critical | Läuft in {0} Tagen ab ({1}). Vorlage: {2}, Antragsteller: {3}, Anforderungs-ID {4}, CA {5}. | Expires in {0} days ({1}). Template: {2}, requester: {3}, request ID {4}, CA {5}. |
ISSUED_DB_UNREADABLE | ISSUED | Info | CA-Datenbank konnte nicht gelesen werden ({0}). | Could not read the CA database ({0}). |
CRL_OK | CRL | OK | Sperrliste aktuell, nächste Aktualisierung {1}. Nummer {3}, {4} Einträge. Ort: {5}. | CRL is current, next update {1}. Number {3}, {4} entries. Location: {5}. |
CRL_EXPIRING | CRL | Warning / Critical | Sperrliste läuft in {0} Tagen ab ({1}), Laufzeit {2} Tage (typisch für Offline-CA). Nummer {3}, {4} Einträge. Ort: {5}. | CRL expires in {0} days ({1}), validity period {2} days (typical for an offline CA). Number {3}, {4} entries. Location: {5}. |
CRL_EXPIRED | CRL | Critical | Sperrliste seit {0} Tagen abgelaufen ({1}). Nummer {3}, {4} Einträge. Ort: {5}. | CRL expired {0} days ago ({1}). Number {3}, {4} entries. Location: {5}. |
CRL_OVERDUE | CRL | Warning | Sperrliste läuft in {6} Stunden ab ({1}), eine neue Version wurde noch nicht veröffentlicht. Nummer {3}, {4} Einträge. Ort: {5}. | CRL expires in {6} hours ({1}) and no newer version has been published yet. Number {3}, {4} entries. Location: {5}. |
CRL_NO_NEXT_UPDATE | CRL | Warning | Sperrliste ohne „Nächste Aktualisierung“. Nummer {3}, {4} Einträge. Ort: {5}. | CRL has no "Next Update" field. Number {3}, {4} entries. Location: {5}. |
CRL_STALE_COPY | CRL | Warning | Veraltete Kopie: CRL-Nummer {0}, an anderem Ort liegt bereits Nummer {1}. | Stale copy: CRL number {0}, another location already has number {1}. |
CRL_ORPHANED | CRL | Info | Verwaiste Sperrliste ({0}) des Servers {1}, zuletzt aktualisiert am {2}. Eine neuere Version liegt an anderer Stelle. | Orphaned CRL ({0}) of server {1}, last updated {2}. A newer version exists elsewhere. |
CRL_LDAP_MISSING | CRL | Critical | LDAP-Sperrliste nicht im AD gefunden. Verwendet in Zertifikaten von: {0}. | LDAP CRL not found in AD. Used in certificates of: {0}. |
CRL_AD_UNREADABLE | CRL | Warning | Sperrliste im AD nicht lesbar: {0} | CRL in AD cannot be read: {0} |
CRL_PATHS_UNKNOWN | CRL | Info | CDP/AIA-Pfade der ausgestellten Zertifikate nicht ermittelbar (CA-Datenbank nicht lesbar). | Could not determine the CDP/AIA paths of the issued certificates (CA database not readable). |
CDP_OK | CDP_AIA | OK | Sperrliste abrufbar. Verwendet in Zertifikaten von: {0}. | CRL can be downloaded. Used in certificates of: {0}. |
CDP_UNREACHABLE | CDP_AIA | Critical | Sperrliste nicht abrufbar ({0}). Verwendet in Zertifikaten von: {1}. | CRL cannot be downloaded ({0}). Used in certificates of: {1}. |
CDP_INVALID | CDP_AIA | Critical | Abgerufene Datei ist keine gültige Sperrliste. Verwendet in Zertifikaten von: {0}. | Downloaded file is not a valid CRL. Used in certificates of: {0}. |
CDP_NO_HTTP | CDP_AIA | Info | Die ausgestellten Zertifikate enthalten nur LDAP-Pfade für die Sperrliste, keinen HTTP-Pfad. | The issued certificates only contain LDAP paths for the CRL, no HTTP path. |
AIA_OK | CDP_AIA | OK | CA-Zertifikat abrufbar ({0}, gültig bis {1}). Verwendet in Zertifikaten von: {2}. | CA certificate can be downloaded ({0}, valid until {1}). Used in certificates of: {2}. |
AIA_EXPIRED | CDP_AIA | Warning | Das CA-Zertifikat an diesem Ort ist abgelaufen ({0}, {1}). Verwendet in Zertifikaten von: {2}. | The CA certificate at this location has expired ({0}, {1}). Used in certificates of: {2}. |
AIA_UNREACHABLE | CDP_AIA | Warning | CA-Zertifikat nicht abrufbar ({0}). Verwendet in Zertifikaten von: {1}. | CA certificate cannot be downloaded ({0}). Used in certificates of: {1}. |
AIA_INVALID | CDP_AIA | Warning | Abgerufene Datei ist kein gültiges Zertifikat. Verwendet in Zertifikaten von: {0}. | Downloaded file is not a valid certificate. Used in certificates of: {0}. |
AD_UNREADABLE | GENERAL | Critical | PKI-Objekte im AD konnten nicht gelesen werden: {0} | Could not read the PKI objects from AD: {0} |
TEMPLATE_UNUSED | TEMPLATES | Info | Vorlage „{0}“ ist auf {1} veröffentlicht, in den letzten {2} Tagen wurde aber kein Zertifikat daraus ausgestellt. | Template "{0}" is published on {1}, but no certificate was issued from it in the last {2} days. |
Hinweise / notes:
- Fundort eines CA-Zertifikats sind die AD-Container:
Enrollment Services/<CA>,Certification Authorities,AIA,NTAuthCertificates. / Location = AD containers. - CA-Datenbank (
ISSUED_*,CA_REQUESTS_*,TEMPLATE_UNUSED, Pfade der ausgestellten Zertifikate) braucht die Zertifizierungsstellen-Verwaltungstools auf dem certmon-Server und das CA-Recht „Lesen“ für das Dienstkonto. / Needs RSAT-ADCS-Mgmt and the CA permission "Read". - Ungenutzte Vorlagen betrachten die letzten 180 Tage. / Unused templates: last 180 days.
Windows-Server / Windows servers
Gelesen über den JEA-Endpunkt certmon.Reader (jea/README.md). Objekt: der Server (FQDN) bzw. eine Bindung „Dienst Name“ oder ein Zertifikat im Speicher. Ablauf-Schwellwerte wie bei Geräten (Standard 30/7 Tage). / Read over the JEA endpoint; thresholds as for devices.
| Id | Kategorie / Category | Schwere / Severity | Deutsch | English |
|---|---|---|---|---|
SRV_UNREACHABLE | SERVER | Warning | Server über WinRM nicht erreichbar ({0}). | Server not reachable over WinRM ({0}). |
SRV_ACCESS_DENIED | SERVER | Warning | Zugriff auf den certmon-Endpunkt verweigert ({0}). | Access to the certmon endpoint denied ({0}). |
SRV_JEA_MISSING | SERVER | Warning | Der JEA-Endpunkt certmon.Reader ist nicht eingerichtet ({0}). | The JEA endpoint certmon.Reader is not installed ({0}). |
SRV_JEA_OUTDATED | SERVER | Info | Der Endpunkt certmon.Reader hat Version {0}, certmon erwartet {1}. | The certmon.Reader endpoint has version {0}, certmon expects {1}. |
SRV_READ_LIMITED | SERVER | Info | Nicht alles war lesbar: {0} | Not everything could be read: {0} |
STORE_CERT_EXPIRING | STORE | Warning / Critical | Zertifikat läuft in {0} Tagen ab ({1}) und hat keinen Nachfolger im Speicher. Aussteller: {2}, Speicher: {3}. | Certificate expires in {0} days ({1}) and has no successor in the store. Issuer: {2}, store: {3}. |
STORE_CERT_EXPIRED | STORE | Info | Zertifikat seit {0} Tagen abgelaufen ({1}), kein Nachfolger im Speicher. Aussteller: {2}, Speicher: {3}. | Certificate expired {0} days ago ({1}), no successor in the store. Issuer: {2}, store: {3}. |
BIND_CERT_OK | BINDING | OK | {0} {1} nutzt ein Zertifikat, das noch {2} Tage gültig ist ({3}). | {0} {1} uses a certificate valid for another {2} days ({3}). |
BIND_CERT_EXPIRING | BINDING | Warning / Critical | {0} {1} nutzt ein Zertifikat, das in {2} Tagen abläuft ({3}). Nachfolger im Speicher: {4}. | {0} {1} uses a certificate that expires in {2} days ({3}). Successor in the store: {4}. |
BIND_CERT_EXPIRED | BINDING | Critical | {0} {1} nutzt ein Zertifikat, das seit {2} Tagen abgelaufen ist ({3}). Nachfolger im Speicher: {4}. | {0} {1} uses a certificate that expired {2} days ago ({3}). Successor in the store: {4}. |
BIND_CERT_MISSING | BINDING | Critical | {0} {1} ist an Zertifikat {2} gebunden, das nicht im Zertifikatsspeicher liegt. | {0} {1} is bound to certificate {2}, which is not in the certificate store. |
BIND_TLS_MISMATCH | BINDING | Warning | {0} {1} ist mit Zertifikat {3} eingerichtet, {2} liefert aber {4} aus. | {0} {1} is configured with certificate {3}, but {2} presents {4}. |
BIND_LDAPS_UNAVAILABLE | BINDING | Info | Domänencontroller {0} antwortet auf Port 636 nicht mit TLS (LDAPS). | Domain controller {0} does not answer with TLS on port 636 (LDAPS). |
AE_POLICY_DISABLED | AUTOENROLLMENT | Info | Automatische Registrierung ist per Richtlinie nicht aktiviert (AEPolicy {0}). | Autoenrollment is not enabled by policy (AEPolicy {0}). |
AE_ERRORS | AUTOENROLLMENT | Info / Warning (Fehler) | {0} Ereignis(se) der automatischen Registrierung in den letzten 7 Tagen, zuletzt Ereignis {1} am {2}: {3} | {0} autoenrollment event(s) in the last 7 days, last: event {1} at {2}: {3} |
Hinweise / notes:
- Bindungen: IIS (über die HTTP.sys-Bindungen, auch SNI), sonstige HTTP.sys-Dienste, RDP, RD-Gateway, RDS-Rollen (auf dem Verbindungsbroker), WinRM-HTTPS-Listener, LDAPS auf Domänencontrollern (per TLS-Handshake ermittelt). / Bindings.
- Nachfolger: ein neueres Zertifikat mit gleichem Antragsteller und gleicher Vorlage und privatem Schlüssel im Speicher „Eigene Zertifikate“. / Successor = newer certificate with the same subject and template.
- Speicher: gebundene, selbstsignierte und CA-Zertifikate sowie Zertifikate ohne privaten Schlüssel werden nicht einzeln gemeldet; je Antragsteller und Vorlage zählt nur das neueste. / Store findings only for unbound certificates.
- Nicht erreichbar erst nach zwei Fehlversuchen in Folge. / Unreachable after two failed runs in a row.
More documents
Installation and setup
Requirements, firewall, service account, permissions, setup (also silent), initial setup, update, backup and troubleshooting.
JEA endpoint for Windows servers
How certmon reads Windows servers only through a restricted PowerShell endpoint: setup, permissions, testing.
Notifications
Alert logic, email over SMTP or Microsoft 365, Microsoft Teams and webhooks with an HMAC signature.
Windows event log
Event ids of the certmon source for RMM and SIEM systems, with query examples.