Ad Widget

Collapse

Zabbix Agent 2 behind TLS interception

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • abockhold
    Junior Member
    • Apr 2024
    • 14

    #1

    Zabbix Agent 2 behind TLS interception

    Hello,

    I've got a host (Debian 12) which is situated behind a firewall which does TLS interception. General TLS traffic works after adding the root CA to the system store. The Zabbix Agent 2 continues to fail. systemctl status zabbix-agent2.service shows:

    Code:
    [101] cannot connect to [zabbix.example.com:10051]: C0F6FFAB597F0000:error:0A000410:SSL routines:ssl3_read_bytes:sslv3 alert handshake failure:../ssl/record/rec_layer_s3.c:1586:SSL alert
    How can I add the root CA to the certificate trust store of Zabbix Agent 2? Thanks!

    Regards
    Andreas
  • cyber
    Senior Member
    Zabbix Certified SpecialistZabbix Certified Professional
    • Dec 2006
    • 4807

    #2
    By using all the provided TLS* config vars here.. https://www.zabbix.com/documentation.../zabbix_agentd

    Comment

    • abockhold
      Junior Member
      • Apr 2024
      • 14

      #3
      Thank you - unfortunately I didn't see your answer earlier. Probably I should try "TLSCAFile".

      Comment

      • abockhold
        Junior Member
        • Apr 2024
        • 14

        #4
        As a follow up: actually it did not work with adjusting TLS-settings. We had to disable TLS intercept for the agent traffic.

        Comment

        Working...