Security Scan reported as Vulnerability Detected for SSL Certificate - Invalid Maximum Validity Date in StorageGRID
Applies to
- StorageGRID
- Vulnerability Security Scan
Issue
A vulnerability scan reported that a certificate on the StorageGRID system had a validity period exceeding the recommended maximum duration. Below is the log output from the vulnerability scan:
Vulnerability Title: SSL Certificate - Invalid Maximum Validity Date Detected
Threat: Subscriber Certificates issued on or after 1 September 2020 SHOULD NOT have a Validity Period greater than 397 days and MUST NOT have a Validity Period greater than 398 days (13 months).
Impact: By exploiting this vulnerability, an attacker can launch a man-in-the-middle attack.
Auditor Recommendation: Please install a server certificate with the recommended maximum validity.