A CA-signed certificate replaced the browser warnings on the management interface at go-live, and twelve months later the warnings returned - unnoticed until the day a partial outage made the GUI the only way in. What should have been added to the post-deployment monitoring set?
Select an answer to reveal the explanation.
Short Explanation
A certificate is a time bomb you set yourself on install day. Put an eye on the expiry date so you get a ping well before the browser blocks your login - especially for the GUI that becomes your only lifeline during an outage. Silent expiry is the trap; the alert is the fix.
Full Explanation
Management services present certificates with finite validity periods, and browsers escalate expired TLS from warnings to hard blocks, so a forgotten renewal eventually denies the GUI entirely. Expiry is a known-future event - ideal monitoring material: track days-to-expiry per management endpoint and alert weeks ahead so renewal happens on your schedule, not the incident's. Certificate failures cluster into the worst windows: the interface you stopped watching is the one you need when other access paths have degraded. Reverting to the default certificate solves the wrong problem - defaults are exactly what the CA-signed replacement eliminated, because they fail identity validation and mark the interface untrusted. Suppressing warnings in browsers deletes the signal while keeping the exposure, cannot be enforced on future admins, and does nothing when a browser hard-blocks an expired chain. A five-year calendar horizon mismatches how certificates actually live - enterprise lifetimes are commonly a year or less - and shared-mailbox ownership evaporates, which is why expiry belongs in monitoring. Exam caveat: certificates used by automation and integrations expire too, and NTP drift can make a valid certificate appear broken - verify time synchronization on both ends. Operational check: add days-to-expiry for each management service to the monitored set, test the alert with a short-lived certificate, and record the renewal owner in the runbook.