4 ms·
They tweeted that it was an authentication certificate. I.e., probably not a regular TLS domain certificate or similar (still could be TLS client cert though),
by jamiesonbecker 7y ago
They tweeted that it was an authentication certificate. I.e., probably not a regular TLS domain certificate or similar (still could be TLS client cert though), but probably more like a certificate/key that one service used to log into another. A lot of microservice/container/kubernetes setups use them for all kinds of stuff, which is really a big step forward over password logins.
Not like it matters, but it kinda does, because those tend to be private and internally generated, and not necessarily signed by an external certificate authority.
- insomniacity 7y agoI have this problem, and it concerns me, because there's no external polling check that's going to spot that. You have to rely on either the code itself checking each time it uses the certificate, and alerting. Or (taken from elsewhere in this thread) you test it during your build, and hope that someone is still building the code by the time the cert comes up for renewal. I'll probably be doing both.