# The Certificate Nobody Owned

I let a certificate expire on a Sunday afternoon,
and found out from a customer, which is always far too soon.

The renewal was automatic. The automation was in place.
It ran on a machine that we had decommissioned in that space.

Nobody had noticed, since the job produced no noise.
A cron that has been deleted does not send you a voice.

The alert we had configured watched the service, not the date,
and the service was still healthy right up till it was too late.

Then everything at once: the clients dropped, the agents stalled,
the mobile app refused the chain, the partner API bawled.

A certificate does not degrade. It does not slowly fade.
It works completely, then it does not, and no warning has been made.

Now the fair objection, which I have made myself before:
you cannot monitor every date behind every door.

Expiry checks accumulate, they nag, they cry out wolf,
and a wall of amber warnings is a wall that people shrug.

But this one has a property that most alerts do not.
The date is known in advance, exactly, on the dot.

You are not predicting failure. You are reading off a label.
That is the cheapest warning that has ever been available.

And the thing that gets you after you have fixed the expiry?
The internal chain. The root you generated for the registry,

the one no public checker sees, that nobody renewed,
with fifteen years of validity and eleven of them used.
