Why does it need to validate a cert? How acceptable is it if you get it wrong? Depending on the answer, perhaps "have a more reliable clock" is the right answer (plenty of embedded devices certainly have a decent idea of what time it is, and if it's already big enough to validate TLS). It seems reasonably probable that the NTP server stops being available for a reasonable amount of time before you have no idea what time it is anymore and can no longer validate certificates; so depending on the device, telemetry might be a good idea too.
It doesn't sound like a reason to give up, though :)
- Device is rebooted
- Can't reach NTP, no RTC or dead RTC battery, happy that time is January 1st, 1970
- HTTPS breaks
If your system can't handle that, a few options: - put a clock in your embedded element - Pin certs - Use a frontend, embedded only connects to authenticated embedded system (say, with ssh Port forwarding). Frontend does connection correctly.
> What time is it?
Jan 2nd, 2017
> Sorry, your certificate is expired. Access Denied.
Wait, I wrote the wrong date, it's Jan 2nd, 2016
> Ok. AuthorizedAtleast I can't think of a better way to get time from a server with a cert.