Expired TLS certificate

Renew service TLS certificates before they expire.

Description

An expired TLS certificate registered with API Gateway, the IAM server certificate store, or ACM cannot provide valid server authentication.

Potential impact

Browsers and API clients that validate certificates may reject connections, interrupting service access and integrations.

Remediation

Replace the certificate and verify that the service presents the new one. Set up expiry alerts and renewal procedures; do not work around the problem by disabling certificate validation.

Examples

These excerpts show only the certificate body. Check the actual validity period, domain, and trust chain regardless of the filename.

Before

hcl
resource "aws_api_gateway_domain_name" "example" {
  certificate_body = file("expiredCertificate.pem")
  domain_name      = "api.example.com"
}

After

hcl
resource "aws_api_gateway_domain_name" "example" {
  certificate_body = file("validCertificate.pem")
  domain_name      = "api.example.com"
}

References