A service-to-service certificate issued by an internal authority in 2022, with a three-year validity nobody had recorded.
found by the endpoint scan, not by any renewal system,
because there is no renewal system for this one.
issued: 2022-11-14
expires: 2025-11-14
issuer: an internal CA whose key is on one host
renewed by: a documented manual procedure, last run
by somebody who left in 2023
six days of notice, from a scan that exists because of
an unrelated incident in October.
A certificate with a three-year validity is a reminder set three years in advance, and nobody sets those. The immediate fix was a renewal and the actual fix is a one-year validity with automation — a longer validity is not a convenience, it is a longer interval between exercises of a procedure that is guaranteed to have rotted.