Skip to content

Instantly share code, notes, and snippets.

@nyrahul
Last active June 21, 2023 13:25
Show Gist options
  • Star 1 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save nyrahul/a9871522cdf863ace985a332607ed935 to your computer and use it in GitHub Desktop.
Save nyrahul/a9871522cdf863ace985a332607ed935 to your computer and use it in GitHub Desktop.
| Name | Address | Status | Version | Ciphersuite | Hash | Signature | Verification |
| ------------------------------------------------------------------------------------- | -------------------- | ---------- | ------- | ---------------------------- | ------ | --------- | -------------------------------------------- |
| accuknox-agents/agents-operator[health-check] | 172.20.183.36:9090 | PLAIN_TEXT | | | | | |
| accuknox-agents/agents-operator[spire-agent] | 172.20.183.36:9091 | PLAIN_TEXT | | | | | |
| accuknox-agents/discovery-engine | 172.20.200.29:9089 | PLAIN_TEXT | | | | | |
| accuknox-dev-cluster-entity-daemon/cluster-entity-daemon[cluster-entity-daemon] | 172.20.65.225:8080 | CONNFAIL | | | | | |
| accuknox-dev-cluster-mgmt/cluster-management-service[cluster-management-service] | 172.20.165.230:80 | PLAIN_TEXT | | | | | |
| accuknox-dev-cluster-onboard/cluster-onboarding-service[cluster-onboarding-service] | 172.20.20.15:80 | PLAIN_TEXT | | | | | |
| accuknox-dev-data-offloader/data-offloader[data-offloader] | 172.20.9.80:8080 | CONNFAIL | | | | | |
| accuknox-dev-datapipeline-api/datapipelineapi-service[datapipelineapi-service] | 172.20.80.197:80 | PLAIN_TEXT | | | | | |
| accuknox-dev-divy/nginx-service[https] | 172.20.63.154:443 | TLS | TLSv1.2 | ECDHE-RSA-AES256-GCM-SHA384 | SHA256 | RSA-PSS | OK |
| accuknox-dev-divy/uwsgi | 172.20.130.194:8000 | PLAIN_TEXT | | | | | |
| accuknox-dev-integration/channel-integration-service[channel-integration-service] | 172.20.211.59:80 | PLAIN_TEXT | | | | | |
| accuknox-dev-istio-ext-authz/istio-ext-authz[grpc] | 172.20.51.150:9000 | PLAIN_TEXT | | | | | |
| accuknox-dev-istio-ext-authz/istio-ext-authz[http] | 172.20.51.150:8000 | PLAIN_TEXT | | | | | |
| accuknox-dev-knox-gateway/knox-gateway[knox-gateway] | 172.20.25.248:3000 | TLS | TLSv1.3 | TLS_AES_128_GCM_SHA256 | SHA256 | ECDSA | unable to get local issuer certificate |
| accuknox-dev-label-service/labelmanagement[labelmanagement] | 172.20.115.107:80 | PLAIN_TEXT | | | | | |
| accuknox-dev-monitoring/alertmanager[http] | 172.20.37.205:9093 | PLAIN_TEXT | | | | | |
| accuknox-dev-monitoring/monitoring-service[https] | 172.20.27.129:443 | TLS | TLSv1.3 | TLS_AES_256_GCM_SHA384 | SHA256 | RSA-PSS | self-signed certificate |
| accuknox-dev-monitoring/monitoring-service[http] | 172.20.27.129:80 | PLAIN_TEXT | | | | | |
| accuknox-dev-monitoring/prometheus-grafana[http-web] | 172.20.146.23:80 | PLAIN_TEXT | | | | | |
| accuknox-dev-monitoring/prometheus-kube-prometheus-operator[https] | 172.20.37.70:443 | TLS | TLSv1.3 | TLS_AES_128_GCM_SHA256 | SHA256 | ECDSA | unable to verify the first certificate |
| accuknox-dev-monitoring/prometheus-kube-prometheus-prometheus[http-web] | 172.20.44.25:9090 | PLAIN_TEXT | | | | | |
| accuknox-dev-monitoring/prometheus-kube-state-metrics[http] | 172.20.250.101:8080 | PLAIN_TEXT | | | | | |
| accuknox-dev-monitoring/prometheus-prometheus-node-exporter[http-metrics] | 172.20.183.9:9100 | PLAIN_TEXT | | | | | |
| accuknox-dev-observability-api/observability-api[observability-api] | 172.20.1.212:80 | PLAIN_TEXT | | | | | |
| accuknox-dev-policy-provider-service/policy-provider-service[policy-provider-service] | 172.20.51.57:443 | TLS | TLSv1.3 | TLS_AES_128_GCM_SHA256 | SHA256 | ECDSA | unable to get local issuer certificate |
| accuknox-dev-policy-service/policymanagement[policymanagement] | 172.20.201.85:80 | PLAIN_TEXT | | | | | |
| accuknox-dev-policy-storage-service/policy-storage-service[policy-storage-service] | 172.20.223.157:80 | PLAIN_TEXT | | | | | |
| accuknox-dev-postgres/postgres-postgresql[tcp-postgresql] | 172.20.112.123:5432 | PLAIN_TEXT | | | | | |
| accuknox-dev-pulsar/pulsar-proxy[http] | 172.20.202.221:8000 | PLAIN_TEXT | | | | | |
| accuknox-dev-pulsar/pulsar-proxy[pulsar] | 172.20.202.221:6650 | PLAIN_TEXT | | | | | |
| accuknox-dev-saltstack/saltmaster-service[80] | 172.20.100.120:80 | PLAIN_TEXT | | | | | |
| accuknox-dev-saltstack/saltmaster-service[443] | 172.20.100.120:443 | PLAIN_TEXT | | | | | |
| accuknox-dev-saltstack/saltmaster-service[8000] | 172.20.100.120:8000 | TLS | TLSv1.3 | TLS_AES_256_GCM_SHA384 | SHA256 | RSA-PSS | self-signed certificate |
| accuknox-dev-soarcast/redis-service[redis-port] | 172.20.17.250:6666 | TLS | TLSv1.3 | TLS_CHACHA20_POLY1305_SHA256 | SHA256 | RSA-PSS | certificate has expired |
| accuknox-dev-spire/spire-agent[grpc] | 172.20.68.167:9091 | PLAIN_TEXT | | | | | |
| accuknox-dev-spire/spire-agent[health] | 172.20.68.167:9090 | PLAIN_TEXT | | | | | |
| accuknox-dev-spire/spire-server[grpc] | 172.20.115.159:8081 | TLS | TLSv1.3 | TLS_AES_128_GCM_SHA256 | SHA256 | ECDSA | unable to get local issuer certificate |
| accuknox-dev-spire/spire-server[health] | 172.20.115.159:9090 | PLAIN_TEXT | | | | | |
| accuknox-dev-user-mgmt/usermanagement-service[usermanagement-service] | 172.20.144.43:80 | PLAIN_TEXT | | | | | |
| accuknox-dev-vault/consul-consul-dns[dns-tcp] | 172.20.9.34:53 | PLAIN_TEXT | | | | | |
| accuknox-dev-vault/consul-consul-ui[https] | 172.20.1.221:443 | TLS | TLSv1.3 | TLS_AES_128_GCM_SHA256 | SHA256 | ECDSA | unable to verify the first certificate |
| accuknox-dev-vault/vault[http] | 172.20.135.200:8200 | TLS | TLSv1.3 | TLS_AES_128_GCM_SHA256 | SHA256 | RSA-PSS | certificate has expired |
| accuknox-dev-vault/vault[https-internal] | 172.20.135.200:8201 | PLAIN_TEXT | | | | | |
| accuknox-dev-vault/vault-active[http] | 172.20.115.204:8200 | CONNFAIL | | | | | |
| accuknox-dev-vault/vault-active[https-internal] | 172.20.115.204:8201 | CONNFAIL | | | | | |
| accuknox-dev-vault/vault-standby[http] | 172.20.38.117:8200 | CONNFAIL | | | | | |
| accuknox-dev-vault/vault-standby[https-internal] | 172.20.38.117:8201 | CONNFAIL | | | | | |
| accuknox-dev-vulnerability-scanner/vulnerability-scanner[vulnerability-scanner] | 172.20.35.49:80 | CONNFAIL | | | | | |
| accuknox-dev-vulnerability-service/vulnerability-service[vulnerability-service] | 172.20.29.103:80 | PLAIN_TEXT | | | | | |
| accuknox-loki/loki-canary[http-metrics] | 172.20.245.9:3500 | PLAIN_TEXT | | | | | |
| accuknox-loki/loki-gateway[http] | 172.20.48.40:80 | PLAIN_TEXT | | | | | |
| cert-manager/cert-manager[tcp-prometheus-servicemonitor] | 172.20.204.22:9402 | PLAIN_TEXT | | | | | |
| cert-manager/cert-manager-webhook[https] | 172.20.196.209:443 | TLS | TLSv1.3 | TLS_AES_128_GCM_SHA256 | SHA384 | ECDSA | unable to verify the first certificate |
| cloud-watch/cloudwatch-prometheus-cloudwatch-exporter[http] | 172.20.240.253:9106 | PLAIN_TEXT | | | | | |
| default/kubernetes[https] | 172.20.0.1:443 | TLS | TLSv1.3 | TLS_AES_128_GCM_SHA256 | SHA256 | RSA-PSS | unable to verify the first certificate |
| ingress-nginx/ingress-nginx-controller[http] | 172.20.21.210:80 | PLAIN_TEXT | | | | | |
| ingress-nginx/ingress-nginx-controller[https] | 172.20.21.210:443 | TLS | TLSv1.3 | TLS_AES_256_GCM_SHA384 | SHA256 | RSA-PSS | self-signed certificate |
| ingress-nginx/ingress-nginx-controller-admission[https-webhook] | 172.20.250.139:443 | TLS | TLSv1.3 | TLS_AES_128_GCM_SHA256 | SHA256 | ECDSA | unable to verify the first certificate |
| istio-system/istio-ingressgateway[http2] | 172.20.227.36:80 | CONNFAIL | | | | | |
| istio-system/istio-ingressgateway[https] | 172.20.227.36:443 | PLAIN_TEXT | | | | | |
| istio-system/istio-ingressgateway[tcp] | 172.20.227.36:31400 | PLAIN_TEXT | | | | | |
| istio-system/istio-ingressgateway[tls] | 172.20.227.36:15443 | CONNFAIL | | | | | |
| istio-system/istiod[grpc-xds] | 172.20.16.197:15010 | PLAIN_TEXT | | | | | |
| istio-system/istiod[https-dns] | 172.20.16.197:15012 | TLS | TLSv1.3 | TLS_AES_128_GCM_SHA256 | SHA256 | RSA-PSS | unable to verify the first certificate |
| istio-system/istiod[https-webhook] | 172.20.16.197:443 | TLS | TLSv1.3 | TLS_AES_128_GCM_SHA256 | SHA256 | RSA-PSS | unable to verify the first certificate |
| istio-system/istiod[http-monitoring] | 172.20.16.197:15014 | PLAIN_TEXT | | | | | |
| kube-system/kube-dns[dns-tcp] | 172.20.0.10:53 | PLAIN_TEXT | | | | | |
| kube-system/kubearmor | 172.20.6.168:32767 | PLAIN_TEXT | | | | | |
| kube-system/kubearmor-annotation-manager-metrics-service[https] | 172.20.255.23:443 | TLS | TLSv1.3 | TLS_AES_128_GCM_SHA256 | SHA256 | RSA-PSS | unable to verify the first certificate |
| kube-system/kubearmor-host-policy-manager-metrics-service[https] | 172.20.48.93:8443 | TLS | TLSv1.3 | TLS_AES_128_GCM_SHA256 | SHA256 | RSA-PSS | self-signed certificate in certificate chain |
| kube-system/kubearmor-policy-manager-metrics-service[https] | 172.20.227.208:8443 | TLS | TLSv1.3 | TLS_AES_128_GCM_SHA256 | SHA256 | RSA-PSS | self-signed certificate in certificate chain |
| kube-system/metrics-server[https] | 172.20.13.138:443 | TLS | TLSv1.3 | TLS_AES_128_GCM_SHA256 | SHA256 | RSA-PSS | self-signed certificate in certificate chain |
| kubecost/kubecost-cost-analyzer[tcp-model] | 172.20.192.102:9003 | PLAIN_TEXT | | | | | |
| kubecost/kubecost-cost-analyzer[tcp-frontend] | 172.20.192.102:9090 | PLAIN_TEXT | | | | | |
| kubecost/kubecost-kube-state-metrics[http] | 172.20.143.20:8080 | PLAIN_TEXT | | | | | |
| kubecost/kubecost-prometheus-server[http] | 172.20.210.54:80 | PLAIN_TEXT | | | | | |
| postgres-exporter/postgres-prometheus-postgres-exporter[http] | 172.20.9.182:9092 | PLAIN_TEXT | | | | | |
| rabbitmq-system/rabbitmq-cluster-operator-rabbitmq-messaging-topology-operator[http] | 172.20.212.148:443 | TLS | TLSv1.3 | TLS_AES_128_GCM_SHA256 | SHA256 | RSA-PSS | unable to verify the first certificate |
| rabbitmq-system/webhook-service | 172.20.111.137:443 | TLS | TLSv1.3 | TLS_AES_128_GCM_SHA256 | SHA256 | RSA-PSS | self-signed certificate |
| rabbitmq/rabbitmq[amqps] | 172.20.134.231:5671 | TLS | TLSv1.3 | TLS_AES_256_GCM_SHA384 | SHA256 | ECDSA | unable to verify the first certificate |
| rabbitmq/rabbitmq[management-tls] | 172.20.134.231:15671 | TLS | TLSv1.3 | TLS_AES_256_GCM_SHA384 | SHA256 | ECDSA | unable to verify the first certificate |
| rabbitmq/rabbitmq[prometheus-tls] | 172.20.134.231:15691 | TLS | TLSv1.3 | TLS_AES_256_GCM_SHA384 | SHA256 | ECDSA | unable to verify the first certificate |
Summary:
| Status | Count |
| ----------------------- | ----- |
| certificate has expired | 2 |
| self-signed certificate | 7 |
| insecure port | 53 |
| connection failure | 11 |
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment