5 ms·
I personally think that TLS certificate expiry should be a server problem not a client problem. The TLS server code is the piece that is using the certificate
by szc 6y ago
I personally think that TLS certificate expiry should be a server problem not a client problem.
The TLS server code is the piece that is using the certificate every time a page is requested.
Why doesn't server code log an error warning that the certificate is going to expire?
Why doesn't the server just stop serving connections when the cert has expired?
Stopping connections ought to get the attention of the service owner rather than force clients to use out-of-band mechanisms to reach the service owner.
Alternatively perhaps imminent expiry should be a trigger for renewal or some other alerting mechanism.
Is there a callback like this in current TLS API stacks that could be used to make this work? (I'm not super familiar with TLS server side APIs, I know there are client callbacks for certificate validation).
It would probably be wise to do the check carefully so as to not consume too many resources. A well thought out mechanism could trigger an external process for notification or even automatic renewal - even when needing to cross a privilege boundary, perhaps touching a file or an IPC message.
I think this would be slightly better than some of the current setups for things like Let's Encrypt that end up running many times unnecessarily. Would be a much better fit for resource constrained embedded devices.
[edited: added back a sentence I inadvertently removed]