ACM certificates with fewer than 30 days left before expiry, or already expired
What does ZopNight detect here?
ZopNight flags an AWS Certificate Manager certificate when its `NotAfter` date is fewer than 30 days away, and reports certificates that have already expired separately. The rule is critical severity with no dollar figure, because an expired certificate breaks TLS for every load balancer, CloudFront distribution or API that serves it.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-198 |
| Category | compliance |
| Severity | critical |
| Metric | none — pure configuration read |
| Threshold | fewer than 30 days to expiry |
| Source | ZopNight |
| Permissions used | acm:ListCertificates · acm:DescribeCertificate |
Where it applies
When ACM does not renew in time
ACM renews Amazon-issued certificates automatically, but only under conditions. The managed renewal guide lists imported certificates and already-expired certificates as not eligible. For DNS-validated certificates, the DNS renewal page says ACM checks 45 days before expiry that the certificate is in use by an AWS service and that every ACM-provided CNAME record is still reachable in public DNS. Remove a CNAME during a DNS migration, or import a certificate from another CA, and nothing renews it. Email-validated certificates need the domain owner to respond to renewal mail.
Checking expiry dates yourself
list-certificates returns the expiry date, whether the certificate was imported, and its renewal
eligibility:
aws acm list-certificates \ --query 'CertificateSummaryList[].[DomainName,NotAfter,Type,RenewalEligibility,InUse]' \ --output tableFor one certificate, see the renewal status and where it is used:
aws acm describe-certificate --certificate-arn CERT_ARN \ --query 'Certificate.{notAfter:NotAfter,renewal:RenewalSummary.RenewalStatus,usedBy:InUseBy}'The 30-day trigger
ZopNight computes the whole number of days between now and the certificate’s expiry date. The finding fires when that number is below 30. A negative value means the certificate has already expired, and the finding says so explicitly (“has already expired, N days past expiry”) rather than counting down.
Certificates that are not evaluated
A certificate that has not been issued yet, such as one still pending validation, has no expiry date and is skipped. ZopNight uses only the expiry date it read from ACM; a tag on the certificate claiming a date is ignored.
Outage risk instead of a saving
The finding carries a fixed $0 estimate. The cost of ignoring it is an outage: browsers and API clients reject an expired certificate, so every endpoint behind it goes dark at the same moment. That is why the rule is rated critical.
Getting the certificate renewed
- For a DNS-validated certificate, confirm the validation CNAME records are still published; the
values are under
DomainValidationOptionsindescribe-certificate. - For an email-validated certificate, respond to the renewal email AWS sends to the domain contacts.
- If automatic renewal failed, read
RenewalSummaryin the ACM console or CLI for the reason. - Request a new certificate if renewal is not possible, attach it to the load balancer or distribution, and remove the old one.