VLT-EXAMPLE-001
Expired certificate remains publicly accessible
An internet-facing service presented a certificate beyond its validity period. External clients can observe the defect without authenticating to the service.
Observed evidence
- Observed host
- legacy.example.com
- Certificate subject
- legacy.example.com
- Validity status
- Expired 31 days before observation
- External service
- HTTPS on TCP 443
- Confidence
- Confirmed through repeated outside-in observation
Why it matters
Users receive certificate warnings and may be trained to ignore future warnings. The service may also indicate an unmaintained or forgotten asset that has fallen outside normal patching, ownership, and monitoring processes.
Required corrective work
- Confirm the business owner and whether the public service is still required.
- If required, renew the certificate using the approved certificate authority and deploy the complete chain.
- If not required, remove the DNS record and securely decommission the public service.
- Record ownership and renewal monitoring in the organization's asset-management process.
Verification test
- The public endpoint no longer presents the expired certificate.
- The replacement certificate chains to an approved trust anchor.
- The subject names match the externally observed hostname.
- The endpoint remains corrected during a scheduled follow-up observation.