Ad Widget

Collapse

Best practice for certificate management in large Zabbix environments?

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Jannis Ehrnhofer
    Junior Member
    • Sep 2026
    • 1

    #1

    Best practice for certificate management in large Zabbix environments?

    Hello everyone,

    I am currently looking into certificate-based encryption for a larger Zabbix environment and would like to understand what the recommended approach is in practice.

    For organizations with many Proxies and hundreds or even thousands of Agents:
    - What solution are you using for certificate management?
    - Are you using an internal CA, Active Directory Certificate Services, Vault, step-ca, or something else?
    - How do you handle certificate issuance and renewal at scale?
    - Is the entire process automated, or is there still some manual intervention required?
    - Are you using certificate-based encryption only between Zabbix Cloud and Proxies, or also between Agents and Proxies?

    My goal is to have a solution that provides:
    - Encrypted communication
    - Automatic certificate renewal
    - Minimal administrative overhead
    - Good scalability for large environments

    I would be very interested in hearing about real-world deployments and what has worked well (or not worked well) for your organization.

    Thanks in advance!
Working...