More Info:

Ensure Cloud Monitoring monitors SSL certificate expiry.

Risk Level

Medium

Address

Security

Compliance Standards

HITRUST, SOC2, GDPR, NISTCSF

Triage and Remediation

Remediation

To remediate SSL certificate expiry misconfiguration in GCP using GCP console, please follow the below steps:

  1. Open the GCP Console and navigate to the Cloud Monitoring page.
  2. Click on the “Uptime Checks” tab on the left-hand side of the page.
  3. Click on the “Create Uptime Check” button.
  4. In the “Create Uptime Check” page, provide the following details:
    • Check Type: HTTPS
    • Hostname: The hostname of the website that needs to be monitored
    • Path: The path to the SSL certificate on the website
    • Check Frequency: The frequency at which the check needs to be performed
    • Timeout: The maximum time allowed for the check to complete
    • Content Match: The content to match on the website to ensure that the SSL certificate is valid
  5. Click on the “Save” button to create the uptime check.

Once the uptime check is created, it will monitor the SSL certificate expiry and notify you if the certificate is about to expire. You can configure notification channels to receive notifications via email, SMS, or other channels.

Additional Reading: