Description
If a service presents an expired SSL/TLS certificate, clients that validate certificates may reject the connection. Encouraging users to bypass expiry warnings can also weaken server identity verification.
ACM rejects certificates that are expired at import time. Imported certificates are not automatically renewed, so manage renewal, reimport and the actual service association.
Potential impact
- Certificate validation errors can interrupt service connections.
- Disabling validation or ignoring warnings can increase server impersonation risk.
Remediation
Prepare a valid certificate, its matching private key and required chain, replace the certificate and verify what the service actually presents. Monitor expiration and renew with sufficient lead time. Do not disable certificate validation to resolve connection failures.
Examples
These file-import examples use the older aws_acm module. File names are illustrative; verify the actual PEM contents, matching private key and required chain. Self-signed certificates need separate client trust configuration.
Before
- name: upload a self-signed certificate
community.aws.aws_acm:
certificate: "{{ lookup('file', 'expiredCertificate.pem') }}"
private_key: "{{ lookup('file', 'key.pem') }}"
name_tag: my_cert
If the file’s certificate is actually expired, ACM rejects the import. This task does not successfully deploy an expired certificate.
After
- name: upload a self-signed certificate
community.aws.aws_acm:
certificate: "{{ lookup('file', 'validCertificate.pem') }}"
private_key: "{{ lookup('file', 'key.pem') }}"
name_tag: my_cert
This attempts to import a valid certificate. Do not infer validity from the file name; check domain coverage, the trust chain and service association.