# Plugin runs OK interactively, gives error running from Sensu

**URL:** <https://discourse.sensu.io/t/plugin-runs-ok-interactively-gives-error-running-from-sensu/257>\
**Category:** Sensu Classic (EOL)\
**Created:** [September 19, 2014, 9:08pm UTC](https://discourse.sensu.io/t/plugin-runs-ok-interactively-gives-error-running-from-sensu/257 "2014-09-19T21:08:05Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Matt\_Cave](https://avatars.discourse-cdn.com/v4/letter/m/48db29/32.png) [@Matt\_Cave](https://discourse.sensu.io/u/Matt_Cave)\
**Post date:** [September 19, 2014, 9:08pm UTC](https://discourse.sensu.io/t/plugin-runs-ok-interactively-gives-error-running-from-sensu/257/1 "2014-09-19T21:08:05Z")

</div>

I’m using a nagios plugin ([http://exchange.nagios.org/directory/Plugins/Network-Protocols/HTTP/check\_ssl\_cert/details](http://exchange.nagios.org/directory/Plugins/Network-Protocols/HTTP/check_ssl_cert/details)) to do SSL cert checks

When I run it interactively from command line, it runs fine.

_# /etc/sensu/plugins/check-ssl-cert.sh -H [mydomain.com](http://mydomain.com) -w 90 -c 14 -S 3_

SSL\_CERT OK - X.509 certificate for ‘[mydomain.com](http://mydomain.com)’ from ‘Go Daddy Secure Certificate Authority - G2’ valid until Jun 23 17:48:28 2015 GMT

When it gets called from within Sensu, it gives the following

_SSL\_CERT CRITICAL [mydomain.com](http://mydomain.com): Cannot verify certificate\nverification error: unable to get local issuer certificate verification error: certificate not trusted\n_

Any ideas on what could be causing this difference in behaviours?

---

<div class="post-metadata">

**Author:** ![Kyle\_Anderson](https://avatars.discourse-cdn.com/v4/letter/k/e5b9ba/32.png) [@Kyle\_Anderson](https://discourse.sensu.io/u/Kyle_Anderson)\
**Post date:** [September 20, 2014, 1:39am UTC](https://discourse.sensu.io/t/plugin-runs-ok-interactively-gives-error-running-from-sensu/257/2 "2014-09-20T01:39:00Z")

</div>

Is it possible that a SSL cert required to verify is not accessible to  
the Sensu user?  
Can you run the check from the cli \*as\* sensu to reproduce?

> **···**
>
> On Fri, Sep 19, 2014 at 2:08 PM, Matt Cave \<m@ttcave.ca\> wrote:
> 
> > I'm using a nagios plugin  
> > ([Directory - Nagios Exchange](http://exchange.nagios.org/directory/Plugins/Network-Protocols/HTTP/check_ssl_cert/details%5C))  
> > to do SSL cert checks
> > 
> > When I run it interactively from command line, it runs fine.
> > 
> > # /etc/sensu/plugins/check-ssl-cert.sh -H mydomain.com -w 90 -c 14 -S 3  
> > SSL\_CERT OK - X.509 certificate for 'mydomain.com' from 'Go Daddy Secure  
> > Certificate Authority - G2' valid until Jun 23 17:48:28 2015 GMT
> > 
> > When it gets called from within Sensu, it gives the following
> > 
> > SSL\_CERT CRITICAL mydomain.com: Cannot verify certificate\nverification  
> > error: unable to get local issuer certificate verification error:  
> > certificate not trusted\n
> > 
> > Any ideas on what could be causing this difference in behaviours?

---

<div class="post-metadata">

**Author:** ![Matt\_Cave](https://avatars.discourse-cdn.com/v4/letter/m/48db29/32.png) [@Matt\_Cave](https://discourse.sensu.io/u/Matt_Cave)\
**Post date:** [September 22, 2014, 6:52pm UTC](https://discourse.sensu.io/t/plugin-runs-ok-interactively-gives-error-running-from-sensu/257/3 "2014-09-22T18:52:52Z")

</div>

That was actually my first guess… Still seeing the same error.

-bash-4.1$ whoami

sensu

-bash-4.1$ /etc/sensu/plugins/check-ssl-cert.sh -H [accu-chekto.com](http://accu-chekto.com) -w 90 -c 14 -S 3

SSL\_CERT OK - X.509 certificate for ‘[accu-chekto.com](http://accu-chekto.com)’ from ‘Go Daddy Secure Certificate Authority - G2’ valid until Jun 23 17:48:28 2015 GMT

> **···**
>
> On Friday, September 19, 2014 9:39:02 PM UTC-4, Kyle Anderson wrote:
> 
> > Is it possible that a SSL cert required to verify is not accessible to
> > 
> > the Sensu user?
> > 
> > Can you run the check from the cli _as_ sensu to reproduce?
> > 
> > On Fri, Sep 19, 2014 at 2:08 PM, Matt Cave [m...@ttcave.ca](mailto:m...@ttcave.ca) wrote:
> > 
> > > I’m using a nagios plugin
> > 
> > > ([http://exchange.nagios.org/directory/Plugins/Network-Protocols/HTTP/check\_ssl\_cert/details](http://exchange.nagios.org/directory/Plugins/Network-Protocols/HTTP/check_ssl_cert/details))
> > 
> > > to do SSL cert checks
> > 
> > > 
> > 
> > > When I run it interactively from command line, it runs fine.
> > 
> > > 
> > 
> > > # /etc/sensu/plugins/check-ssl-cert.sh -H [mydomain.com](http://mydomain.com) -w 90 -c 14 -S 3
> > 
> > > SSL\_CERT OK - X.509 certificate for ‘[mydomain.com](http://mydomain.com)’ from 'Go Daddy Secure
> > 
> > > Certificate Authority - G2’ valid until Jun 23 17:48:28 2015 GMT
> > 
> > > 
> > 
> > > When it gets called from within Sensu, it gives the following
> > 
> > > 
> > 
> > > SSL\_CERT CRITICAL [mydomain.com](http://mydomain.com): Cannot verify certificate\nverification
> > 
> > > error: unable to get local issuer certificate verification error:
> > 
> > > certificate not trusted\n
> > 
> > > 
> > 
> > > Any ideas on what could be causing this difference in behaviours?

---

<div class="post-metadata">

**Author:** ![Kyle\_Anderson](https://avatars.discourse-cdn.com/v4/letter/k/e5b9ba/32.png) [@Kyle\_Anderson](https://discourse.sensu.io/u/Kyle_Anderson)\
**Post date:** [September 23, 2014, 3:23pm UTC](https://discourse.sensu.io/t/plugin-runs-ok-interactively-gives-error-running-from-sensu/257/4 "2014-09-23T15:23:45Z")

</div>

I would run the script with set -vx to and diff the outputs. (feel  
free to pastebin)  
I would also throw in a "set" at the top of the script to dump the  
environment and compare that too.

> **···**
>
> On Mon, Sep 22, 2014 at 11:52 AM, Matt Cave \<m@ttcave.ca\> wrote:
> 
> > That was actually my first guess.... Still seeing the same error.
> > 
> > -bash-4.1$ whoami  
> > sensu  
> > -bash-4.1$ /etc/sensu/plugins/check-ssl-cert.sh -H accu-chekto.com -w 90 -c  
> > 14 -S 3  
> > SSL\_CERT OK - X.509 certificate for 'accu-chekto.com' from 'Go Daddy Secure  
> > Certificate Authority - G2' valid until Jun 23 17:48:28 2015 GMT
> > 
> > On Friday, September 19, 2014 9:39:02 PM UTC-4, Kyle Anderson wrote:
> > 
> > > Is it possible that a SSL cert required to verify is not accessible to  
> > > the Sensu user?  
> > > Can you run the check from the cli \*as\* sensu to reproduce?
> > > 
> > > On Fri, Sep 19, 2014 at 2:08 PM, Matt Cave \<m...@ttcave.ca\> wrote:  
> > > \> I'm using a nagios plugin  
> > > \>  
> > > \> ([Directory - Nagios Exchange](http://exchange.nagios.org/directory/Plugins/Network-Protocols/HTTP/check_ssl_cert/details%5C))  
> > > \> to do SSL cert checks  
> > > \>  
> > > \> When I run it interactively from command line, it runs fine.  
> > > \>  
> > > \> # /etc/sensu/plugins/check-ssl-cert.sh -H mydomain.com -w 90 -c 14 -S 3  
> > > \> SSL\_CERT OK - X.509 certificate for 'mydomain.com' from 'Go Daddy Secure  
> > > \> Certificate Authority - G2' valid until Jun 23 17:48:28 2015 GMT  
> > > \>  
> > > \> When it gets called from within Sensu, it gives the following  
> > > \>  
> > > \> SSL\_CERT CRITICAL mydomain.com: Cannot verify certificate\nverification  
> > > \> error: unable to get local issuer certificate verification error:  
> > > \> certificate not trusted\n  
> > > \>  
> > > \> Any ideas on what could be causing this difference in behaviours?
