Description
An expired TLS certificate registered with API Gateway, the IAM server certificate store, or ACM cannot provide valid server authentication.
Potential impact
Browsers and API clients that validate certificates may reject connections, interrupting service access and integrations.
Remediation
Replace the certificate and verify that the service presents the new one. Set up expiry alerts and renewal procedures; do not work around the problem by disabling certificate validation.
Examples
These excerpts show only the certificate body. Check the actual validity period, domain, and trust chain regardless of the filename.
Before
hcl
resource "aws_api_gateway_domain_name" "example" {
certificate_body = file("expiredCertificate.pem")
domain_name = "api.example.com"
}
After
hcl
resource "aws_api_gateway_domain_name" "example" {
certificate_body = file("validCertificate.pem")
domain_name = "api.example.com"
}