Certificate and licence health
Two things stop a working installation without touching its data: the TLS certificate expiring or not naming the address agents use, and the licence running out. Both are shown in the console, announced in the notification bell once per change, and reported by /health/ready. Changes are still made on the server with ./lawliet.
The certificate card
Settings > Platform, for users who can manage settings. It shows:
- a status: Valid, Expiring soon (under 30 days), Action needed (under 7 days, expired, not valid yet, or an address in use the certificate does not name), No TLS or Could not read;
- subject, issuer (marked when self-signed), key type and size, and a validity bar with the days left;
- the names in the certificate (
DNS:andIP:entries); - the addresses this server is reached by, each marked covered or not covered, and where it is known from: this browser, the trusted hosts, or the public address. Loopback addresses never raise a finding;
- the SHA-256 fingerprint, with a copy button, to compare with what an agent host or a browser shows;
- the commands for the server:
sudo ./lawliet tls repair,sudo ./lawliet tlsandsudo ./lawliet tls --export.
The card is read-only. The backend reads the certificate nginx actually serves with a TLS handshake, and is never given the private key.
Coverage follows the rules browsers and agents apply: an IP address is covered only by an IP: entry, a name only by a DNS: entry, a wildcard covers exactly one leftmost label and never an IP address, and the subject CN is not used.
Findings and fixes
| Condition | Severity | Fix shown |
|---|---|---|
| Under 30 days left | warning | Self-signed: sudo ./lawliet tls repair, then sudo ./lawliet tls --export for agent hosts. CA-issued: renew from your CA, then sudo ./lawliet tls. |
| Under 7 days left, or expired | critical | As above |
| Not valid yet | critical | Check the server clock (timedatectl) |
| An address in use is not named | critical | Self-signed: sudo ./lawliet tls repair, then sudo ./lawliet tls --export. CA-issued: a certificate from your CA that names it, then sudo ./lawliet tls. |
| No subjectAltName at all | critical | As above |
Licence health
Settings > Platform and the activation screen show:
- the licence status and the days left: under 30 days is a warning, under 7 days or expired is critical;
- agent usage, "N of M agents", with a warning from 90% and critical at 100%, when the next enrolment is refused;
- the installation fingerprint and a ready-to-send licence request with the version, the address the console is opened at and the date, each with a copy button;
- the steps: send the request, receive a key file, install it with
sudo ./lawliet licence <file>or paste the key in the console.
"The licence is not valid yet"
A licence whose start date is after the server's clock is refused (NOT_YET_VALID). That is almost always a server clock that is behind. The activation screen, the console and ./lawliet licence then show the server's current time in UTC next to the licence's start time, and how to fix the clock on the host (containers use the host's clock):
timedatectl # what the host believes the time is
# with a time server: set NTP=<server> in /etc/systemd/timesyncd.conf, then
sudo systemctl restart systemd-timesyncd
sudo timedatectl set-ntp true
# with none (air-gapped, no time source):
sudo timedatectl set-time 'YYYY-MM-DD HH:MM:SS'
Then install the licence again.
Notifications and health checks
A background check runs every 15 minutes. Each state is announced in the bell once: the licence at 30 days, 7 days and expired; agents at 90% and 100%; and each certificate finding. A restart does not repeat an announcement, and a new state (7 days after 30, a different uncovered address, a replaced certificate) is announced again. Announcements also go to the webhook and email channels when those are configured.
/health/ready reports checks.license.expiry and checks.certificate.status. Neither makes the backend "not ready": an expiring certificate or licence is for the operator to fix, not a reason to refuse traffic.

