TLS expiry warning is skipped on some checks, at random #204

Closed
opened 2026-10-02 01:34:46 +02:00 by clawbot · 2 comments
Collaborator

Found while checking the README for #108.

The README says a certificate inside the warning window gets a warning "repeated each check until renewed or expired". checkTLSExpiry in internal/watcher/watcher.go sends none for a hostname and address that got one less than DNSWATCHER_TLS_INTERVAL ago. TLS checks start once per interval, but each runs after a DNS pass of varying length, so two checks' warnings are the interval apart plus the difference between those DNS passes. When the later pass is the shorter, the gap is under the interval and the warning is skipped: a certificate about to expire is warned about on every check or every other check, at random.

#18 asked for fewer repeats; the README promises one per check. Which is wanted is the owner's call.

Definition of done

  • Expiry warnings follow one rule, stated in the README, that does not depend on how long a DNS pass took.
  • A test shows it on certificate data built in the test, with no DNS involved.

Model: opus-5-5

Found while checking the README for https://git.eeqj.de/sneak/dnswatcher/issues/108. The README says a certificate inside the warning window gets a warning "repeated each check until renewed or expired". `checkTLSExpiry` in `internal/watcher/watcher.go` sends none for a hostname and address that got one less than `DNSWATCHER_TLS_INTERVAL` ago. TLS checks start once per interval, but each runs after a DNS pass of varying length, so two checks' warnings are the interval apart plus the difference between those DNS passes. When the later pass is the shorter, the gap is under the interval and the warning is skipped: a certificate about to expire is warned about on every check or every other check, at random. https://git.eeqj.de/sneak/dnswatcher/issues/18 asked for fewer repeats; the README promises one per check. Which is wanted is the owner's call. ## Definition of done - Expiry warnings follow one rule, stated in the README, that does not depend on how long a DNS pass took. - A test shows it on certificate data built in the test, with no DNS involved. Model: opus-5-5
clawbot added this to the 1.0 milestone 2026-10-02 01:37:55 +02:00
Author
Collaborator

Plan; this needs no decision from sneak. TLS checks start once per DNSWATCHER_TLS_INTERVAL, so "one warning per check", as the README says, is also the "no more than once per interval" that #18 asked for. The rule: each TLS check sends at most one expiry warning per hostname and address while the certificate is in the warning window, and the decision does not compare wall-clock times against the interval. The README keeps its wording; the test runs successive checks on certificate data built in the test, with gaps shorter and longer than the interval, and expects one warning per check.

Model: opus-5-5

Plan; this needs no decision from sneak. TLS checks start once per `DNSWATCHER_TLS_INTERVAL`, so "one warning per check", as the README says, is also the "no more than once per interval" that https://git.eeqj.de/sneak/dnswatcher/issues/18 asked for. The rule: each TLS check sends at most one expiry warning per hostname and address while the certificate is in the warning window, and the decision does not compare wall-clock times against the interval. The README keeps its wording; the test runs successive checks on certificate data built in the test, with gaps shorter and longer than the interval, and expects one warning per check. Model: opus-5-5
Author
Collaborator

Built in #208: every TLS check warns once per hostname and address while the certificate is within the warning period, with no comparison against the TLS interval. A target listed twice now gets two warnings per check: #207.

Model: opus-5-5

Built in https://git.eeqj.de/sneak/dnswatcher/pulls/208: every TLS check warns once per hostname and address while the certificate is within the warning period, with no comparison against the TLS interval. A target listed twice now gets two warnings per check: https://git.eeqj.de/sneak/dnswatcher/issues/207. Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/dnswatcher#204