Hello everyone,
I am currently looking into certificate-based encryption for a larger Zabbix environment and would like to understand what the recommended approach is in practice.
For organizations with many Proxies and hundreds or even thousands of Agents:
- What solution are you using for certificate management?
- Are you using an internal CA, Active Directory Certificate Services, Vault, step-ca, or something else?
- How do you handle certificate issuance and renewal at scale?
- Is the entire process automated, or is there still some manual intervention required?
- Are you using certificate-based encryption only between Zabbix Cloud and Proxies, or also between Agents and Proxies?
My goal is to have a solution that provides:
- Encrypted communication
- Automatic certificate renewal
- Minimal administrative overhead
- Good scalability for large environments
I would be very interested in hearing about real-world deployments and what has worked well (or not worked well) for your organization.
Thanks in advance!
I am currently looking into certificate-based encryption for a larger Zabbix environment and would like to understand what the recommended approach is in practice.
For organizations with many Proxies and hundreds or even thousands of Agents:
- What solution are you using for certificate management?
- Are you using an internal CA, Active Directory Certificate Services, Vault, step-ca, or something else?
- How do you handle certificate issuance and renewal at scale?
- Is the entire process automated, or is there still some manual intervention required?
- Are you using certificate-based encryption only between Zabbix Cloud and Proxies, or also between Agents and Proxies?
My goal is to have a solution that provides:
- Encrypted communication
- Automatic certificate renewal
- Minimal administrative overhead
- Good scalability for large environments
I would be very interested in hearing about real-world deployments and what has worked well (or not worked well) for your organization.
Thanks in advance!