More Info:

The client-side SSL certificates used by your Amazon API Gateway REST APIs for secure authentication at the API integration endpoint level should be rotated before their expiration date

Risk Level

Medium

Address

Security

Compliance Standards

GDPR

Triage and Remediation

Check Cause

  1. Sign in to the AWS Management Console and open the API Gateway console at https://console.aws.amazon.com/apigateway/.

  2. In the navigation pane, choose ‘APIs’.

  3. In the APIs pane, choose the API you want to check.

  4. In the API details pane, choose ‘Client Certificates’.

  5. In the Client Certificates pane, you can see the expiration date of the SSL client certificate. If the certificate is about to expire, it indicates a misconfiguration.

Additional Reading: