On Tue, Oct 20, 2020, at 08:52, Nemanja Delic wrote: > In this case the cert has expired on Oct 13 22:12:47 2020 GMT. Since it's not > last one in chain it's not breaking things. I can set the filter accordingly > ( with smth like > -7), just thought there might be some other solution.
PKIX path validation requires that *all* certificates be valid at the time of validation: RFC 5280 Section 6.1.3. As soon as any certificate in the path expires, the entire chain is invalidated. So yeah - things are probably breaking. -- Harald -- You received this message because you are subscribed to the Google Groups "Prometheus Users" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion on the web visit https://groups.google.com/d/msgid/prometheus-users/ff354baa-15cc-4d88-9419-d94f81a8ede3%40www.fastmail.com.

