index.docker.io was serving an expired certificate
index.docker.io
index.docker.io
[1] http://exchange.nagios.org/directory/Plugins/Network-Protoco...
[2] http://exchange.nagios.org/directory/Plugins/Network-Protoco...
[3] https://github.com/sensu/sensu-community-plugins/tree/master...
[4] http://exchange.nagios.org/directory/Plugins/Internet-Domain...
[5] https://github.com/sensu/sensu-community-plugins/tree/master...
If the old certificate was also a wildcard certificate, it stands to reason that even if the CA sent a reminder email, this particular front end could have been overlooked.
http://www.poweradmin.com/help/sm_5_7/monitor_web_page.aspx
There really is no reason to be surprised by an expiring cert any more.
:~ $ sudo docker pull debian Pulling repository debian 2015/03/20 23:42:18 Get https://index.docker.io/v1/repositories/debian/images: x509: certificate has expired or is not yet valid
Thankfully it's a Friday night, so I'm taking this as a hint to start my weekend :)
Sending build context to Docker daemon
Step 0 : FROM ubuntu:trusty
511136ea3c5a: Pull complete
This is a wildcard cert for .docker.io.
In addition, Chromium tells me that "Your connection to docker.io is encrypted with obsolete cryptography" (although that may just be a result of the expired certificate?).
How did no one responsible for this get notified prior to the certificate expiring? Presumably, that's something they (Docker) will shortly be adding to their monitoring system.
ETA: I'm no expert but after looking at the Qualys SSL Labs report [0], it would appear that the warning is simply due to the certificate having expired.
[0]: https://www.ssllabs.com/ssltest/analyze.html?d=docker.io&lat...
But there's no reason why a rote task like renewing a certificate should be left to humans. It should be automated, which is what my startup, https://sslmate.com/, is doing.
sudo date --set="Sat Mar 20 00:01:01 EDT 2015"
If you want immutable deploys, what you actually want is a hash over the content.
When you embed a hash over the content in your deploy script, you guarantee true immutable deploys: everything will be exactly what you ask for, forever. You're not beholden to SSL for security; you're not beholden to anyone maintaining the servers to "be a good citizen". You just have guarantees.
Use a hash over your content.
It has everything, however, to do with all of the images served from that domain which people use to execute software on their machines.