Automatically notification when a certificate and a DANE TLSA record no longer match.
4.2K
This project is about being automatically notified when a certificate and a DANE TLSA record no longer match. This happens, for example, when certificates are used via Lets Encrypt and auto renewal.
A notification is sent via a Discord WebHook.
GitHub project: https://github.com/J-SIT/tlsa-checker/
The following can be set via the environment variables:
There is a test mode which can be used to test the Discord connection.
To start the container use this command or compose for version 1 (without automatic update functionality).
docker run -e DOMAIN="abc.de" -e TLSA_RECORD="_25._tcp" -e DISCORD_WEBHOOK_URL="https://discord.com/api/webhooks/1303443" -e CHECK_INTERVAL=86400 schefflerit/tlsa-checker:v1
version: '3.8'
services:
tlsa_checker:
image: schefflerit/tlsa-checker:v1
container_name: TLSA-Checker
environment:
- DOMAIN=abc.de
- TLSA_RECORD=_25._tcp
- DISCORD_WEBHOOK_URL=https://discord.com/api/webhooks/1303443
- CHECK_INTERVAL=86400
restart: unless-stopped
This is version 2 with automatic Cloudflare Update:
Create a Bearer API Token with write authorization for the corresponding DNS zone. Together with the API zone ID, the corresponding entries can then be updated automatically
docker run -e DOMAIN="abc.de" -e TLSA_RECORD="_25._tcp" -e DISCORD_WEBHOOK_URL="https://discord.com/api/webhooks/1303443" -e CHECK_INTERVAL=86400 -e CLOUDFLARE_API_TOKEN="XXX" -e CLOUDFLARE_ZONE_ID="XXX" schefflerit/tlsa-checker:v2
version: '3.8'
services:
tlsa_checker:
image: tlsa-checker-v2
container_name: TLSA-Checker_v2
environment:
DOMAIN: "sxxxx.de"
TLSA_RECORDS: "_25._tcp,_143._tcp,_465._tcp"
DISCORD_WEBHOOK_URL: "https://discord.com/api/webhooks/13034XXX"
CHECK_INTERVAL: 86400
CLOUDFLARE_API_TOKEN: "XXX"
CLOUDFLARE_ZONE_ID: "XXX"
restart: unless-stopped
Content type
Image
Digest
sha256:fce1c2345…
Size
59.6 MB
Last updated
almost 2 years ago
docker pull schefflerit/tlsa-checker