You might use the SSL dashboard on NetScaler Console to monitor your certificates if your company has SSL Policy where you have defined certain SSL certificate requirements such as all certificates must have minimum key strengths of 2048 bits and a trusted CA authority must authorize it.
In another example, you might have uploaded a new certificate but forgotten to bind it to a virtual server. The SSL dashboard highlights the SSL certificates being used or not used. In the Usage section, you can see the number of certificates that have been installed, and the number of certificates being used. You can further click the graph, to see the certificates name, the instance on which it’s being used, its validity, its signature algorithm, and so on.
To monitor SSL certificates in NetScaler Console, navigate to Infrastructure > SSL Dashboard.
NetScaler Console allows you to poll SSL Certificates and add all the SSL certificates of the instances immediately to NetScaler Console. To do so,
-
Navigate to Infrastructure > SSL Dashboard.
-
Click Poll Now.
On the Poll Now page, you can either poll all managed NetScaler instances or select specific instances.
-
Click Start Polling.
In SSL Dashboard, you can monitor the NetScaler SSL certificates, SSL virtual servers, and SSL protocols.
You can click the metrics on the dashboard to view details related to SSL certificates, SSL Virtual Servers, or SSL protocols.
For example, when you click the number under Self signed vs CA signed on the dashboard, the NetScaler Console GUI displays all the SSL certificates on the NetScaler instances.
The NetScaler Console SSL Dashboard also shows the distribution of SSL protocols that are running on your virtual servers. As an administrator, you can specify the protocols that you want to monitor through the SSL policy, for more information, see
Configuring SSL Policies. The protocols supported are SSLv2, SSLv3, TLS 1.0, TLS 1.1, TLS 1.2, and TLS 1.3. The SSL protocols used on virtual servers appear in a bar chart format. Clicking a specific protocol displays a list of virtual servers using that protocol.
A donut chart appears after Diffie-Hellman (DH) or Ephemeral RSA keys are enabled or disabled on the SSL dashboard. These keys enable secure communication with export clients even if the server certificate does not support export clients, as in the case of a 1024-bit certificate. Clicking the appropriate chart displays a list of the virtual servers on which DH or Ephemeral RSA keys are enabled.