Catch up on the latest product updates, best practices, and expert insights from the Checkmk Conference #12 – Watch the livestream recordings now

Werk #20071: Agent Bakery: Rework signature key expiry notifications

Component Agent bakery
Title Agent Bakery: Rework signature key expiry notifications
Date Jun 25, 2026
Level Trivial Change
Class Bug Fix
Compatibility Compatible - no manual interaction needed
Checkmk versions & editions
3.0.0b1
Not yet released
Checkmk Pro, Checkmk Ultimate, Checkmk Cloud, Checkmk Ultimate MT
2.5.0p9 Checkmk Pro, Checkmk Ultimate, Checkmk Cloud, Checkmk Ultimate MT
2.4.0p35
Not yet released
Checkmk Pro, Checkmk Ultimate, Checkmk Cloud, Checkmk Ultimate MT
2.3.0p49
Not yet released
Checkmk Pro, Checkmk Ultimate, Checkmk Ultimate MT

The notifications about expiring agent signature keys introduced in Werk #17102 alarmed all users by email, including those who cannot resolve the issue themselves.

The notifications now work as follows:

  • When a key will expire within 90 days, administrators receive a single email notification. This replaces the previous notification within the Checkmk GUI.
  • When a key will expire within 20 days, administrators receive an email notification every day until the key is replaced or deleted. Previously, a single email was sent to all users at this point.
  • When a key will expire within 5 days, a single "Service Risk Advisory" email is sent to the contacts of affected hosts. A host counts as affected as soon as it is assigned to a baked agent package with active agent updater, and all keys configured in the matching agent updater rule are at risk.

To the list of all Werks