SKNS
v2.0
Skans Docs/How-tos/Renew a certificate after a device's address changes
How-tos

Renew a certificate after a device's address changes

A Skans-issued device certificate names the device by address. When the device moves to a new address (a DHCP lease changed, or someone re-addressed it), the certificate still names the old one and TLS to the new address fails until the certificate is re-issued. Skans detects this and re-issues it for you, with the limits below.

What Skans does #

  1. Detects it. The reachability sweep reads the certificate the device serves. If Skans issued it, it has at least one name in it, and none of those names is the device’s current IP address or its verified DNS name, the device is marked Address changed (“Address changed - certificate no longer matches”). A certificate with no names at all is not marked, because there is nothing to compare.
  2. Re-issues it overnight. The nightly certificate renewal treats an Address changed device the way the Renew certificate button does: it re-issues whatever the days left, instead of waiting until the certificate is near expiry. Each automatic re-issue is written to the audit log as cert-address-renew by system.
  3. Names the new address. The new certificate carries the current IP address. It carries a DNS name only when that name is a fully qualified domain name and forward-resolves to the device’s enrolled IP. If the DNS lookup gives no answer at all (as opposed to answering “not this address”), and the certificate the device serves has a DNS name, the renewal is deferred to the next cycle instead of dropping the name. It proceeds IP-only when the certificate is within 3 days of expiry.

It uses the pins you already have #

The automatic re-issue never trusts whatever answers at the new address.

  • It uses only the TLS and SSH pins already stored for the device. It does not capture a new pin at the new address.
  • A device with neither pin is not renewed. It is reported as failed with the reason, and you pin the device yourself first.
  • A device whose pin you forgot is skipped, without a failed row each night. Forgetting a pin is your decision, and the sweep does not override it.

Avoid it: reserve the address #

A certified device on a dynamic lease from this appliance’s own DHCP server shows a warning on its detail page: “This address is assigned by DHCP and has no reservation. If it changes, the certificate stops matching the device until it is reissued.” The Devices page shows a count of such devices.

Add a DHCP reservation for the device. The warning appears only for an address this appliance’s DHCP server currently holds an active lease for. A static address, a lease from another DHCP server, or a DHCP role Skans cannot read gives no warning, which means unknown, not safe.

Do it now #

Open the device and choose Renew certificate. It re-issues immediately and does not wait for the overnight run.

Next #