MCPP-TRN03: TLS certificate invalid or expiring¶
| Family | Transport |
| Default severity | high |
| Confidence | high |
| Mode | passive (default scan) |
| Spec revisions | all |
Why it matters¶
Clients must validate the server certificate (RFC 9728 §7.3, RFC 8414 §6). An invalid certificate forces clients to disable validation or fail; an expiring one is an outage waiting to happen.
Remediation¶
Serve a certificate from a publicly trusted CA that matches the hostname, and automate renewal (ACME).
References¶
Suppressing¶
# .mcp-posture-ignore
[[ignore]]
check = "MCPP-TRN03"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31