Skip to content

MCPP-TRN03: TLS certificate invalid or expiring

Family Transport
Default severity high
Confidence high
Mode passive (default scan)
Spec revisions all

Why it matters

Clients must validate the server certificate (RFC 9728 §7.3, RFC 8414 §6). An invalid certificate forces clients to disable validation or fail; an expiring one is an outage waiting to happen.

Remediation

Serve a certificate from a publicly trusted CA that matches the hostname, and automate renewal (ACME).

References

Suppressing

# .mcp-posture-ignore
[[ignore]]
check = "MCPP-TRN03"
target = "https://mcp.example.com/*"
justification = "Why this is acceptable here"
expires = 2026-12-31