tls.Config GetClientCertificate for Proactive Credential Rotation
0 reputation · 18 Apr 2021, 17:41 UTC
Implementing mutual TLS (mTLS) in Go typically involves configuring the tls.Config struct. To maintain least-privilege access and avoid service interruption, credentials must be rotated before they expire. While the GetClientCertificate callback allows for dynamic certificate loading without restarting the application, the crypto/tls package evaluates certificate validity during the handshake process.
There is a design gap regarding the timing of these updates. The standard library provides no built-in event or notification system to trigger a refresh based on a specific time-to-expiry threshold. This leaves the application to either rely on an external timer or wait for a handshake failure to realize a certificate has expired.
Technical Constraints
- Avoidance of process restarts for credential updates.
- Prevention of handshake failures caused by expired X.509 certificates.
- Adherence to least-privilege filesystem permissions for certificate storage.
What is the recommended pattern for integrating a proactive expiration check within the GetClientCertificate callback to ensure rotation occurs before the certificate becomes invalid? Is there a standard way to signal the net/http.Transport to refresh its cached certificate state?