# Keep your certificates young and fresh

- Link: https://www.agilicus.com/keep-your-certificates-young-and-fresh/
- Published: 2019-05-21T15:11:41+00:00
- Author: Don Bowman

Imagine my surprise this am to find a post on LinkedIn, with their shortener, inaccessible.
It turns out the TLS certificate expired this am for [linkd.in](https://lnkd.in/gB4KiRR).
Hmm.

This is a general problem, and one for which some great solutions exist. E.g. using
[Let’s Encrypt](https://letsencrypt.org/), we can use [CertManager](https://github.com/jetstack/cert-manager)
to auto-create/refresh. There are tools to watch the expiry date as well.

When good certificates go bad it trains users to ‘accept’ the error (curl -k, accept
in browser, etc). This is not acceptable, users should see a NET:ERR_CERT_DATE_INVALID
as a hard-fail, not as a “oh, security, we’ll yada yada that”.

![c6ecd2d8 image](https://www.agilicus.com/www/2019/05/c6ecd2d8-image.png "Keep 
your certificates young and fresh 1")
