Lawliet LAWLIET
Book a demo

Certificate and licence health

Two things stop a working installation without touching its data: the TLS certificate expiring or not naming the address agents use, and the licence running out. Both are shown in the console, announced in the notification bell once per change, and reported by /health/ready. Changes are still made on the server with ./lawliet.

The certificate card

Settings > Platform, for users who can manage settings. It shows:

The card is read-only. The backend reads the certificate nginx actually serves with a TLS handshake, and is never given the private key.

Coverage follows the rules browsers and agents apply: an IP address is covered only by an IP: entry, a name only by a DNS: entry, a wildcard covers exactly one leftmost label and never an IP address, and the subject CN is not used.

Findings and fixes

ConditionSeverityFix shown
Under 30 days leftwarningSelf-signed: sudo ./lawliet tls repair, then sudo ./lawliet tls --export for agent hosts. CA-issued: renew from your CA, then sudo ./lawliet tls.
Under 7 days left, or expiredcriticalAs above
Not valid yetcriticalCheck the server clock (timedatectl)
An address in use is not namedcriticalSelf-signed: sudo ./lawliet tls repair, then sudo ./lawliet tls --export. CA-issued: a certificate from your CA that names it, then sudo ./lawliet tls.
No subjectAltName at allcriticalAs above

Licence health

Settings > Platform and the activation screen show:

"The licence is not valid yet"

A licence whose start date is after the server's clock is refused (NOT_YET_VALID). That is almost always a server clock that is behind. The activation screen, the console and ./lawliet licence then show the server's current time in UTC next to the licence's start time, and how to fix the clock on the host (containers use the host's clock):

timedatectl                                   # what the host believes the time is
# with a time server: set NTP=<server> in /etc/systemd/timesyncd.conf, then
sudo systemctl restart systemd-timesyncd
sudo timedatectl set-ntp true
# with none (air-gapped, no time source):
sudo timedatectl set-time 'YYYY-MM-DD HH:MM:SS'

Then install the licence again.

Notifications and health checks

A background check runs every 15 minutes. Each state is announced in the bell once: the licence at 30 days, 7 days and expired; agents at 90% and 100%; and each certificate finding. A restart does not repeat an announcement, and a new state (7 days after 30, a different uncovered address, a replaced certificate) is announced again. Announcements also go to the webhook and email channels when those are configured.

/health/ready reports checks.license.expiry and checks.certificate.status. Neither makes the backend "not ready": an expiring certificate or licence is for the operator to fix, not a reason to refuse traffic.