<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Help configuring SSL Certificate Monitor Extension in Extensions</title>
    <link>https://community.dynatrace.com/t5/Extensions/Help-configuring-SSL-Certificate-Monitor-Extension/m-p/293471#M7017</link>
    <description>&lt;P&gt;Hi All,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I installed the SSL Certificate Monitor extension so I can monitor certificates in Dynatrace. I activated it at the ActiveGate scope and added the domain for direct monitoring, but I still can’t see any data in Dynatrace.&lt;/P&gt;
&lt;P&gt;I also checked the Defender Portal and confirmed the certificate details are correct.&lt;/P&gt;
&lt;P&gt;Do you have any suggestions on what I should check next?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 23 Jan 2026 07:28:03 GMT</pubDate>
    <dc:creator>Raidan</dc:creator>
    <dc:date>2026-01-23T07:28:03Z</dc:date>
    <item>
      <title>Help configuring SSL Certificate Monitor Extension</title>
      <link>https://community.dynatrace.com/t5/Extensions/Help-configuring-SSL-Certificate-Monitor-Extension/m-p/293471#M7017</link>
      <description>&lt;P&gt;Hi All,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I installed the SSL Certificate Monitor extension so I can monitor certificates in Dynatrace. I activated it at the ActiveGate scope and added the domain for direct monitoring, but I still can’t see any data in Dynatrace.&lt;/P&gt;
&lt;P&gt;I also checked the Defender Portal and confirmed the certificate details are correct.&lt;/P&gt;
&lt;P&gt;Do you have any suggestions on what I should check next?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jan 2026 07:28:03 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Extensions/Help-configuring-SSL-Certificate-Monitor-Extension/m-p/293471#M7017</guid>
      <dc:creator>Raidan</dc:creator>
      <dc:date>2026-01-23T07:28:03Z</dc:date>
    </item>
    <item>
      <title>Re: Help configuring SSL Certificate Monitor Extension</title>
      <link>https://community.dynatrace.com/t5/Extensions/Help-configuring-SSL-Certificate-Monitor-Extension/m-p/293481#M7018</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I would suggest checking &lt;A title="ActiveGate extension logs" href="https://docs.dynatrace.com/docs/shortlink/sgw-files" target="_blank" rel="noopener"&gt;ActiveGate extension logs&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jan 2026 13:42:31 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Extensions/Help-configuring-SSL-Certificate-Monitor-Extension/m-p/293481#M7018</guid>
      <dc:creator>AntonPineiro</dc:creator>
      <dc:date>2026-01-22T13:42:31Z</dc:date>
    </item>
    <item>
      <title>Re: Help configuring SSL Certificate Monitor Extension</title>
      <link>https://community.dynatrace.com/t5/Extensions/Help-configuring-SSL-Certificate-Monitor-Extension/m-p/293617#M7020</link>
      <description>&lt;P&gt;I checked the ActiveGate and extension logs on the ActiveGate host. The ActiveGate is running fine and the SSL Certificate Monitor extension is executing regularly.&lt;/P&gt;&lt;P&gt;I don’t see any errors in the logs, but no certificates are discovered and no data appears in Dynatrace.&lt;/P&gt;&lt;P&gt;The certificates do exist and are in use (confirmed in Microsoft Defender), and (I'm not sure )they are used by Kubernetes ingress endpoints.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jan 2026 12:53:15 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Extensions/Help-configuring-SSL-Certificate-Monitor-Extension/m-p/293617#M7020</guid>
      <dc:creator>Raidan</dc:creator>
      <dc:date>2026-01-26T12:53:15Z</dc:date>
    </item>
    <item>
      <title>Re: Help configuring SSL Certificate Monitor Extension</title>
      <link>https://community.dynatrace.com/t5/Extensions/Help-configuring-SSL-Certificate-Monitor-Extension/m-p/293624#M7021</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I would open a support case with ActiveGate diagnostics attached.&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jan 2026 13:39:33 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Extensions/Help-configuring-SSL-Certificate-Monitor-Extension/m-p/293624#M7021</guid>
      <dc:creator>AntonPineiro</dc:creator>
      <dc:date>2026-01-26T13:39:33Z</dc:date>
    </item>
    <item>
      <title>Re: Help configuring SSL Certificate Monitor Extension</title>
      <link>https://community.dynatrace.com/t5/Extensions/Help-configuring-SSL-Certificate-Monitor-Extension/m-p/293645#M7022</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;I know this might be trivial, but it often happens that the ActiveGate can’t establish a TLS connection to the target domain/URL. You know, DNS, routing,firewall, proxy. Or, if you try reach kubernetess Ingress you can&amp;nbsp;hitting the wrong certificate because SNI isn’t applied correctly&lt;BR /&gt;&lt;A href="https://docs.dynatrace.com/docs/observe/infrastructure-observability/extensions/ssl-certificate-monitor" target="_self"&gt;SSL Certificate Monitor extension&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;in this documentation&amp;nbsp;Dynatrace explicitly notes that for remote monitoring the ActiveGate must have access to the provided URLs/domains and firewall/network changes may be required.&lt;BR /&gt;&lt;BR /&gt;Test from the ActiveGate host do something like that&amp;nbsp;&lt;STRONG&gt;nslookup your.domain&lt;/STRONG&gt; or &lt;STRONG&gt;openssl s_client -connect your.domain:443 -servername your.domain &amp;lt;/dev/null 2&amp;gt;/dev/null | openssl x509 -noout -subject -issuer -dates &lt;/STRONG&gt;or just&amp;nbsp;&lt;STRONG&gt;curl -vkI &lt;A href="https://your.domain" target="_blank"&gt;https://your.domain&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It could be also SNI for Kubernetes Ingress - in documentation&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Additional SNI domains
An optional setting to configure additional Server Name Indication domains:

Add domain. An advanced setting to provide a list of domains to use in with Server Name Indication. SNI is an extension to the TLS protocol which is used in HTTPS. Use this setting to specify the domain name of a website during the initial TLS Handshake instead of when the HTTPS connection opens after the handshake.&lt;/LI-CODE&gt;&lt;P&gt;when multiple hostnames/certs share the same IP/LB; otherwise you may get the default cert or fail to extract the expected one. Also check that you monitor correct&amp;nbsp;FQDN used by the Ingress.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Another option -&amp;nbsp;Enable the certificate status metric&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="t_pawlak_0-1769450241351.png" style="width: 400px;"&gt;&lt;img src="https://community.dynatrace.com/t5/image/serverpage/image-id/31746iE56E8111BA0117D6/image-size/medium?v=v2&amp;amp;px=400" role="button" title="t_pawlak_0-1769450241351.png" alt="t_pawlak_0-1769450241351.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;You can also Enable debug + domain discovery error alerts&lt;BR /&gt;From documentation:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Activate debug—check this box to activate debug level logging. Logs are available (by default) on Linux at: /var/lib/dynatrace/remotepluginmodule/log/extensions/datasources and on Windows at: C:\ProgramData\dynatrace\remotepluginmodule\log\extensions\datasources.&lt;/LI-CODE&gt;&lt;P&gt;If all this&amp;nbsp;checks look fine&amp;nbsp;&lt;SPAN&gt;open a support ticket&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jan 2026 18:00:47 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Extensions/Help-configuring-SSL-Certificate-Monitor-Extension/m-p/293645#M7022</guid>
      <dc:creator>t_pawlak</dc:creator>
      <dc:date>2026-01-26T18:00:47Z</dc:date>
    </item>
  </channel>
</rss>

