Dependencies: Certificate Expiry
The Certificate Expiry test opens a secure connection to your dependency, retrieves the certificate chain, and validates that no certificates expire in the next 30 days. If there is no secure connection available, and therefore no certificates, this test will pass.
Certificate Expiry
Dependencies
6 minutes
How this Scenario works
This test opens a secure connection to your dependency, retrieves the full certificate chain, and checks every certificate in that chain for an expiration date within the next 30 days. Dependencies that don't offer a secure connection have no certificates to check, so the test passes.
Why run this Scenario?
Expired certificates can lead to sudden, high-profile outages. Tools like Certbot and ACME (Automatic Certificate Management Environment) helped automate certificate issuance and renewals, but teams still need to stay on top of upcoming expirations. This Scenario helps flag certificates that are expiring soon, giving you time to renew and replace.
- Ensure operational awareness of certificate expirations.
- Validate automation for certificate renewal.
- Reduce outage risk from unnoticed expired certs.
What to expect when you run it
If a TLS certificate for a dependency expires, the dependent service will surface clear errors and alert ops immediately.
More Scenarios to try
Avoid downtime. Use Gremlin to turn failure into resilience.
Gremlin empowers you to proactively root out failure before it causes downtime. See how you can harness chaos to build resilient systems by requesting a demo of Gremlin.
