Expired SSL/TLS certificate

Renew certificates before expiry and verify that the service presents the replacement.

Description

If a service presents an expired SSL/TLS certificate, clients that validate certificates may reject the connection. Encouraging users to bypass expiry warnings can also weaken server identity verification.

ACM rejects certificates that are expired at import time. Imported certificates are not automatically renewed, so manage renewal, reimport and the actual service association.

Potential impact

  • Certificate validation errors can interrupt service connections.
  • Disabling validation or ignoring warnings can increase server impersonation risk.

Remediation

Prepare a valid certificate, its matching private key and required chain, replace the certificate and verify what the service actually presents. Monitor expiration and renew with sufficient lead time. Do not disable certificate validation to resolve connection failures.

Examples

These file-import examples use the older aws_acm module. File names are illustrative; verify the actual PEM contents, matching private key and required chain. Self-signed certificates need separate client trust configuration.

Before

yaml
- name: upload a self-signed certificate
  community.aws.aws_acm:
    certificate: "{{ lookup('file', 'expiredCertificate.pem') }}"
    private_key: "{{ lookup('file', 'key.pem') }}"
    name_tag: my_cert

If the file’s certificate is actually expired, ACM rejects the import. This task does not successfully deploy an expired certificate.

After

yaml
- name: upload a self-signed certificate
  community.aws.aws_acm:
    certificate: "{{ lookup('file', 'validCertificate.pem') }}"
    private_key: "{{ lookup('file', 'key.pem') }}"
    name_tag: my_cert

This attempts to import a valid certificate. Do not infer validity from the file name; check domain coverage, the trust chain and service association.

References