NSCAServer¶
A server that listens for incoming NSCA connection and processes incoming requests.
Enable module¶
To enable this module and and allow using the commands you need to ass NSCAServer = enabled to the [/modules] section in nsclient.ini:
[/modules]
NSCAServer = enabled
Configuration¶
| Path / Section | Description |
|---|---|
| /settings/NSCA/server | NSCA SERVER SECTION |
| /settings/default | Default values |
NSCA SERVER SECTION ¶
Section for NSCA (NSCAServer) (check_nsca) protocol options.
| Key | Default Value | Description |
|---|---|---|
| allowed ciphers | ALL:!ADH:!LOW:!EXP:!MD5:@STRENGTH | ALLOWED CIPHERS |
| allowed hosts | 127.0.0.1 | Allowed hosts |
| bind to | BIND TO ADDRESS | |
| ca | ${certificate-path}/ca.pem | CA |
| cache allowed hosts | true | Cache list of allowed hosts |
| certificate | ${certificate-path}/certificate.pem | SSL CERTIFICATE |
| certificate format | PEM | CERTIFICATE FORMAT |
| certificate key | SSL CERTIFICATE | |
| debug verify | false | Debug peer certificate verification |
| dh | DH KEY | |
| encryption | aes256 | ENCRYPTION |
| inbox | inbox | INBOX |
| password | Password | |
| payload length | 512 | PAYLOAD LENGTH |
| performance data | true | PERFORMANCE DATA |
| port | 5667 | PORT NUMBER |
| socket queue size | 0 | LISTEN QUEUE |
| ssl options | VERIFY MODE | |
| thread pool | 10 | THREAD POOL |
| timeout | 30 | TIMEOUT |
| timezone | utc | TIMEZONE |
| tls version | tlsv1.2+ | TLS version to use |
| use ssl | false | ENABLE SSL ENCRYPTION |
| verify mode | none | VERIFY MODE |
# Section for NSCA (NSCAServer) (check_nsca) protocol options.
[/settings/NSCA/server]
allowed ciphers=ALL:!ADH:!LOW:!EXP:!MD5:@STRENGTH
allowed hosts=127.0.0.1
ca=${certificate-path}/ca.pem
cache allowed hosts=true
certificate=${certificate-path}/certificate.pem
certificate format=PEM
debug verify=false
encryption=aes256
inbox=inbox
payload length=512
performance data=true
port=5667
socket queue size=0
thread pool=10
timeout=30
timezone=utc
tls version=tlsv1.2+
use ssl=false
verify mode=none
ALLOWED CIPHERS ¶
The chipers which are allowed to be used. The default here will differ is used in “insecure” mode or not. check_nrpe uses a very old chipers and should preferably not be used. For details of chipers please see the OPEN ssl documentation: https://www.openssl.org/docs/apps/ciphers.html
| Key | Description |
|---|---|
| Path: | /settings/NSCA/server |
| Key: | allowed ciphers |
| Advanced: | Yes (means it is not commonly used) |
| Default value: | ALL:!ADH:!LOW:!EXP:!MD5:@STRENGTH |
Sample:
[/settings/NSCA/server]
# ALLOWED CIPHERS
allowed ciphers=ALL:!ADH:!LOW:!EXP:!MD5:@STRENGTH
Allowed hosts ¶
A comma separated list of allowed hosts. You can use netmasks (/ syntax) or * to create ranges.
| Key | Description |
|---|---|
| Path: | /settings/NSCA/server |
| Key: | allowed hosts |
| Default value: | 127.0.0.1 |
Sample:
[/settings/NSCA/server]
# Allowed hosts
allowed hosts=127.0.0.1
BIND TO ADDRESS ¶
Allows you to bind server to a specific local address. This has to be a dotted ip address not a host name. Leaving this blank will bind to all available IP addresses.
| Key | Description |
|---|---|
| Path: | /settings/NSCA/server |
| Key: | bind to |
| Default value: | N/A |
Sample:
[/settings/NSCA/server]
# BIND TO ADDRESS
bind to=
CA ¶
| Key | Description |
|---|---|
| Path: | /settings/NSCA/server |
| Key: | ca |
| Advanced: | Yes (means it is not commonly used) |
| Default value: | ${certificate-path}/ca.pem |
Sample:
[/settings/NSCA/server]
# CA
ca=${certificate-path}/ca.pem
Cache list of allowed hosts ¶
If host names (DNS entries) should be cached, improves speed and security somewhat but won’t allow you to have dynamic IPs for your Nagios server.
| Key | Description |
|---|---|
| Path: | /settings/NSCA/server |
| Key: | cache allowed hosts |
| Default value: | true |
Sample:
[/settings/NSCA/server]
# Cache list of allowed hosts
cache allowed hosts=true
SSL CERTIFICATE ¶
| Key | Description |
|---|---|
| Path: | /settings/NSCA/server |
| Key: | certificate |
| Advanced: | Yes (means it is not commonly used) |
| Default value: | ${certificate-path}/certificate.pem |
Sample:
[/settings/NSCA/server]
# SSL CERTIFICATE
certificate=${certificate-path}/certificate.pem
CERTIFICATE FORMAT ¶
| Key | Description |
|---|---|
| Path: | /settings/NSCA/server |
| Key: | certificate format |
| Advanced: | Yes (means it is not commonly used) |
| Default value: | PEM |
Sample:
[/settings/NSCA/server]
# CERTIFICATE FORMAT
certificate format=PEM
SSL CERTIFICATE ¶
| Key | Description |
|---|---|
| Path: | /settings/NSCA/server |
| Key: | certificate key |
| Advanced: | Yes (means it is not commonly used) |
| Default value: | N/A |
Sample:
[/settings/NSCA/server]
# SSL CERTIFICATE
certificate key=
Debug peer certificate verification ¶
Set this to tru to output certificate verification errors, these are outputed to stdout (not the log).
| Key | Description |
|---|---|
| Path: | /settings/NSCA/server |
| Key: | debug verify |
| Advanced: | Yes (means it is not commonly used) |
| Default value: | false |
Sample:
[/settings/NSCA/server]
# Debug peer certificate verification
debug verify=false
DH KEY ¶
| Key | Description |
|---|---|
| Path: | /settings/NSCA/server |
| Key: | dh |
| Advanced: | Yes (means it is not commonly used) |
| Default value: | N/A |
Sample:
[/settings/NSCA/server]
# DH KEY
dh=
ENCRYPTION ¶
Name of encryption algorithm to use. Has to be the same as your agent i using or it wont work at all.This is also independent of SSL and generally used instead of SSL. Available encryption algorithms are: none = No Encryption (not safe) xor = XOR des = DES 3des = DES-EDE3 cast128 = CAST-128 xtea = XTEA blowfish = Blowfish twofish = Twofish rc2 = RC2 aes128 = AES aes192 = AES aes = AES serpent = Serpent gost = GOST
| Key | Description |
|---|---|
| Path: | /settings/NSCA/server |
| Key: | encryption |
| Default value: | aes256 |
Sample:
[/settings/NSCA/server]
# ENCRYPTION
encryption=aes256
INBOX ¶
The default channel to post incoming messages on
| Key | Description |
|---|---|
| Path: | /settings/NSCA/server |
| Key: | inbox |
| Default value: | inbox |
Sample:
[/settings/NSCA/server]
# INBOX
inbox=inbox
Password ¶
Password used to authenticate against server
| Key | Description |
|---|---|
| Path: | /settings/NSCA/server |
| Key: | password |
| Default value: | N/A |
Sample:
[/settings/NSCA/server]
# Password
password=
PAYLOAD LENGTH ¶
Length of payload to/from the NSCA agent. This is a hard specific value so you have to “configure” (read recompile) your NSCA agent to use the same value for it to work.
| Key | Description |
|---|---|
| Path: | /settings/NSCA/server |
| Key: | payload length |
| Default value: | 512 |
Sample:
[/settings/NSCA/server]
# PAYLOAD LENGTH
payload length=512
PERFORMANCE DATA ¶
Send performance data back to nagios (set this to false to remove all performance data).
| Key | Description |
|---|---|
| Path: | /settings/NSCA/server |
| Key: | performance data |
| Default value: | true |
Sample:
[/settings/NSCA/server]
# PERFORMANCE DATA
performance data=true
PORT NUMBER ¶
Port to use for NSCA.
| Key | Description |
|---|---|
| Path: | /settings/NSCA/server |
| Key: | port |
| Default value: | 5667 |
Sample:
[/settings/NSCA/server]
# PORT NUMBER
port=5667
LISTEN QUEUE ¶
Number of sockets to queue before starting to refuse new incoming connections. This can be used to tweak the amount of simultaneous sockets that the server accepts.
| Key | Description |
|---|---|
| Path: | /settings/NSCA/server |
| Key: | socket queue size |
| Advanced: | Yes (means it is not commonly used) |
| Default value: | 0 |
Sample:
[/settings/NSCA/server]
# LISTEN QUEUE
socket queue size=0
VERIFY MODE ¶
Comma separated list of verification flags to set on the SSL socket.
default-workarounds Various workarounds for what I understand to be broken ssl implementations no-sslv2 Do not use the SSLv2 protocol (prefer tls version instead). no-sslv3 Do not use the SSLv3 protocol (prefer tls version instead). no-tlsv1 Do not use the TLSv1 protocol (prefer tls version instead). no-tlsv1_1 Do not use the TLSv1.1 protocol (prefer tls version instead). no-tlsv1_2 Do not use the TLSv1.2 protocol (prefer tls version instead). no-tlsv1_3 Do not use the TLSv1.3 protocol (prefer tls version instead). single-dh-use Always create a new key when using temporary/ephemeral DH parameters. This option must be used to prevent small subgroup attacks, when the DH parameters were not generated using “strong” primes (e.g. when using DSA-parameters).
| Key | Description |
|---|---|
| Path: | /settings/NSCA/server |
| Key: | ssl options |
| Advanced: | Yes (means it is not commonly used) |
| Default value: | N/A |
Sample:
[/settings/NSCA/server]
# VERIFY MODE
ssl options=
THREAD POOL ¶
| Key | Description |
|---|---|
| Path: | /settings/NSCA/server |
| Key: | thread pool |
| Advanced: | Yes (means it is not commonly used) |
| Default value: | 10 |
Sample:
[/settings/NSCA/server]
# THREAD POOL
thread pool=10
TIMEOUT ¶
Timeout (in seconds) when reading packets on incoming sockets. If the data has not arrived within this time we will bail out.
| Key | Description |
|---|---|
| Path: | /settings/NSCA/server |
| Key: | timeout |
| Default value: | 30 |
Sample:
[/settings/NSCA/server]
# TIMEOUT
timeout=30
TIMEZONE ¶
Reference timezone for the wire timestamp emitted in the IV packet and used by the replay-window check. The protocol specification calls for UTC (default). Set to ‘local’ (or any POSIX TZ string) only when interoperating with a legacy agent that wrote local-clock-as-Unix-time into the wire field. Both ends must agree on the value.
| Key | Description |
|---|---|
| Path: | /settings/NSCA/server |
| Key: | timezone |
| Default value: | utc |
Sample:
[/settings/NSCA/server]
# TIMEZONE
timezone=utc
TLS version to use ¶
Valid options are tlsv1.3, tlsv1.2, tlsv1.1, tlsv1.0, sslv3 as well as tlsv1.3+, tlsv1.2+, tlsv1.1+, tlsv1.0+, sslv3+ (Which uses the version mentioned and above)
| Key | Description |
|---|---|
| Path: | /settings/NSCA/server |
| Key: | tls version |
| Advanced: | Yes (means it is not commonly used) |
| Default value: | tlsv1.2+ |
Sample:
[/settings/NSCA/server]
# TLS version to use
tls version=tlsv1.2+
ENABLE SSL ENCRYPTION ¶
This option controls if SSL should be enabled.
| Key | Description |
|---|---|
| Path: | /settings/NSCA/server |
| Key: | use ssl |
| Default value: | false |
Sample:
[/settings/NSCA/server]
# ENABLE SSL ENCRYPTION
use ssl=false
VERIFY MODE ¶
Comma separated list of verification flags to set on the SSL socket.
none The server will not send a client certificate request to the client, so the client will not send a certificate. peer The server sends a client certificate request to the client and the certificate returned (if any) is checked. fail-if-no-cert if the client did not return a certificate, the TLS/SSL handshake is immediately terminated. This flag must be used together with peer. peer-cert Alias for peer and fail-if-no-cert. workarounds Various bug workarounds. single Always create a new key when using tmp_dh parameters. client-once Only request a client certificate on the initial TLS/SSL handshake. This flag must be used together with verify-peer
| Key | Description |
|---|---|
| Path: | /settings/NSCA/server |
| Key: | verify mode |
| Advanced: | Yes (means it is not commonly used) |
| Default value: | none |
Sample:
[/settings/NSCA/server]
# VERIFY MODE
verify mode=none
Default values ¶
Default values used in other config sections.
| Key | Default Value | Description |
|---|---|---|
| allowed hosts | 127.0.0.1 | Allowed hosts |
| bind to | BIND TO ADDRESS | |
| cache allowed hosts | true | Cache list of allowed hosts |
| encoding | NRPE PAYLOAD ENCODING | |
| inbox | inbox | INBOX |
| password | Password | |
| socket queue size | 0 | LISTEN QUEUE |
| thread pool | 10 | THREAD POOL |
| timeout | 30 | TIMEOUT |
| timezone | local | Timezone |
# Default values used in other config sections.
[/settings/default]
allowed hosts=127.0.0.1
cache allowed hosts=true
inbox=inbox
socket queue size=0
thread pool=10
timeout=30
timezone=local
Allowed hosts ¶
A comma separated list of allowed hosts. You can use netmasks (/ syntax) or * to create ranges.
| Key | Description |
|---|---|
| Path: | /settings/default |
| Key: | allowed hosts |
| Default value: | 127.0.0.1 |
Sample:
[/settings/default]
# Allowed hosts
allowed hosts=127.0.0.1
BIND TO ADDRESS ¶
Allows you to bind server to a specific local address. This has to be a dotted ip address not a host name. Leaving this blank will bind to all available IP addresses.
| Key | Description |
|---|---|
| Path: | /settings/default |
| Key: | bind to |
| Default value: | N/A |
Sample:
[/settings/default]
# BIND TO ADDRESS
bind to=
Cache list of allowed hosts ¶
If host names (DNS entries) should be cached, improves speed and security somewhat but won’t allow you to have dynamic IPs for your Nagios server.
| Key | Description |
|---|---|
| Path: | /settings/default |
| Key: | cache allowed hosts |
| Default value: | true |
Sample:
[/settings/default]
# Cache list of allowed hosts
cache allowed hosts=true
NRPE PAYLOAD ENCODING ¶
| Key | Description |
|---|---|
| Path: | /settings/default |
| Key: | encoding |
| Advanced: | Yes (means it is not commonly used) |
| Default value: | N/A |
Sample:
[/settings/default]
# NRPE PAYLOAD ENCODING
encoding=
INBOX ¶
The default channel to post incoming messages on
| Key | Description |
|---|---|
| Path: | /settings/default |
| Key: | inbox |
| Default value: | inbox |
Sample:
[/settings/default]
# INBOX
inbox=inbox
Password ¶
Password used to authenticate against server
| Key | Description |
|---|---|
| Path: | /settings/default |
| Key: | password |
| Default value: | N/A |
Sample:
[/settings/default]
# Password
password=
LISTEN QUEUE ¶
Number of sockets to queue before starting to refuse new incoming connections. This can be used to tweak the amount of simultaneous sockets that the server accepts.
| Key | Description |
|---|---|
| Path: | /settings/default |
| Key: | socket queue size |
| Advanced: | Yes (means it is not commonly used) |
| Default value: | 0 |
Sample:
[/settings/default]
# LISTEN QUEUE
socket queue size=0
THREAD POOL ¶
| Key | Description |
|---|---|
| Path: | /settings/default |
| Key: | thread pool |
| Advanced: | Yes (means it is not commonly used) |
| Default value: | 10 |
Sample:
[/settings/default]
# THREAD POOL
thread pool=10
TIMEOUT ¶
Timeout (in seconds) when reading packets on incoming sockets. If the data has not arrived within this time we will bail out.
| Key | Description |
|---|---|
| Path: | /settings/default |
| Key: | timeout |
| Default value: | 30 |
Sample:
[/settings/default]
# TIMEOUT
timeout=30
Timezone ¶
Timezone used to render dates such as boot time. Accepts ‘local’ (default), ‘utc’, or any POSIX TZ string parseable by Boost.Date_time (e.g. ‘MST-07’ or ‘EST-05EDT,M3.2.0,M11.1.0’).
| Key | Description |
|---|---|
| Path: | /settings/default |
| Key: | timezone |
| Advanced: | Yes (means it is not commonly used) |
| Default value: | local |
Sample:
[/settings/default]
# Timezone
timezone=local