惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 叶小钗
Microsoft Azure Blog
Microsoft Azure Blog
Stack Overflow Blog
Stack Overflow Blog
Jina AI
Jina AI
Vercel News
Vercel News
H
Help Net Security
Martin Fowler
Martin Fowler
美团技术团队
云风的 BLOG
云风的 BLOG
Y
Y Combinator Blog
阮一峰的网络日志
阮一峰的网络日志
MyScale Blog
MyScale Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - 三生石上(FineUI控件)
博客园 - 司徒正美
人人都是产品经理
人人都是产品经理
Engineering at Meta
Engineering at Meta
G
Google Developers Blog
Blog — PlanetScale
Blog — PlanetScale
MongoDB | Blog
MongoDB | Blog
宝玉的分享
宝玉的分享
小众软件
小众软件
T
Tailwind CSS Blog
WordPress大学
WordPress大学

Catchpoint Blog

SRE Report: AI optimism and the economics of effort SRE Report: Why fast is what users trust SRE Report 2026: What surprised us, what didn't, and why the gaps matter most The SRE Report 2026: Defensible Ns Why Synthetic Tracing Delivers Better Data, Not Just More Data A New Chapter: LogicMonitor + Catchpoint – A Personal Note from Mehdi Mezmo + Catchpoint deliver observability SREs can rely on The four pillars holding up your digital business, and what happens when they crumble When payments pause: lessons from a global payments outage Observability 2025 Decoded: What the DZone Report Means for SLO-Driven Ops The next evolution of WebPageTest has arrived, and it’s a game-changer The Monitoring Blind Spot That Could Cost You Black Friday Powering Mexico’s Digital Future: Expanded Internet Observability with Catchpoint The Next Chapter of WebPageTest: Your New Experience Starts Soon SRE Report Retrospectives — Have AIOps Predictions Held Up? When BGP becomes UX: The inside story of a SaaS routing decision gone wrong (or right) Session Replay explained: A guide to seeing digital experience through your user’s eyes Making the invisible visible: Are your cloud firewalls and DDoS protection really working? Why it’s time to move beyond APM: Monitoring from the user’s perspective When metrics mislead: Inside the 2025 Retail Web Performance Benchmark The vendor trap: why your next outage won’t be your fault—but will be your problem LLMs don’t stand still: How to monitor and trust the models powering your AI Semantic Caching: What We Measured, Why It Matters The Annual SRE Survey Is Open—We Want to Hear from You Observability isn’t about the tool. It’s about the truth Invisible dependencies, visible impact: Lessons from the Google Cloud outage Real-time detection of BGP blackholing and prefix hijacks Leading analyst firm reveals the real cost of internet disruptions The Power of Over 3000 Intelligent Observability Agents Monitoring in the Age of Complexity: 5 Assumptions CIOs Need to Rethink
SSL Monitoring, Trust, and McLOVIN
2024-12-10 · via Catchpoint Blog

in this blog post

The recent ServiceNow Secure Sockets Layer (SSL) certificate error disrupted operations for hundreds of organizations causing widespread connectivity failures. IT operations stalled, developers hit roadblocks, and businesses across industries felt the impact. The culprit? An expired SSL certificate.

While these disruptions highlight the importance of SSL monitoring, they point to a deeper issue: trust.

When I asked Google, ‘What is the role of an SSL certificate?’, I received multiple responses. Here are a couple:

An SSL certificate is a digital credential that plays a pivotal role in establishing secure connections over the internet, serving as a trust indicator and ensuring data encryption and authentication during online interactions.” – ServiceNow
An SSL certificate, or Secure Sockets Layer certificate, is a digital object that helps to secure network communications and establish trust between a website and its users.” – Google AI Overview

To confirm how important the idea of trust is, notice how both definitions included that exact word.

What happened?

On September 23, 2024, at approximately 0216 UTC, impact from a management, instrumentation, and discovery (MID) server’s certificate expiration began. And “this issue may be impacting your Integrations, Orchestration, Discovery, and MID Server Script Executions that rely on MID Servers or instance-instance communication, such as Instance Upgrades, Update Set retrieval, AI Search, Virtual Agent, and Cloning between instances” according to their ServiceNow advisory.

This certificate error also comes on the heels of another trust erosion incident in which internal knowledge base (kb) articles could be accessed from an external (read, unauthorized) perspective. While we expect these types of operational incidents organizations of all types and sizes (it’s not a matter if, it’s a matter of when), we also expect learning from them.

What does SSL monitoring have to do with “trust”?

The obvious answer to, ‘Why monitor SSL?’ may be apparent when you read a headline indicating hundreds of organizations and businesses’ operations were disrupted. More importantly, though, it’s about preserving trust.  

In this Forbes article, Catchpoint CEO Mehdi Daoudi explains how trust is ‘the silent commodity that’s bought and sold with every transaction’.  

We trust that when we purchase health and beauty products that we are not smearing damaging products in our hair or skin. We trust when we deposit a mobile check that our money will be deposited safely. And when we can put a name to the companies that sell these products or services, then we can talk about building or preserving reputation.

This is exactly why we built our SSL monitoring to accompany our other suite of critical business capabilities.  

Capabilities like those that can ensure internet network traffic is not hijacked, that can ensure users get their expected results, or that can ensure their information is protected and secured are just such examples.

But what does this have to do with McLOVIN?

What is now considered a meme, when McLOVIN’s Hawaii driver's license was presented, it perfectly illustrates how the store clerk’s trust in its validity was questioned. Think about it: consider an ID issued by an authority. Now consider traveling to a different state or country (as an example). When presenting that ID, people need to be able to trust it is a valid ID even though it was issued by an entity outside of their region.

In this vein, validating an SSL certificate is quite like validating a driver’s license. Both processes involve checking the authenticity and current validity of a credential. When you validate a driver’s license, you check the expiration date, ensure the photo matches the individual, and verify that the license hasn’t been revoked or suspended. This process ensures that the driver is legally allowed to operate a vehicle (or old enough to purchase alcohol!) and that their credentials are up to date.

Similarly, validating an SSL certificate involves checking its expiration date, confirming that it is issued by a trusted Certificate Authority (CA), and ensuring that it hasn’t been revoked. This process ensures that the website can securely encrypt data and that users can trust the site’s identity.

In both cases, the goal is to maintain trust and security. An expired or invalid driver’s license can lead to legal issues and safety concerns, while an expired or invalid SSL certificate can lead to security vulnerabilities, business disruption (as with this ServiceNow incident), loss of user trust, and potential data breaches. Regular SSL monitoring helps prevent these issues by ensuring that the credentials are current and trustworthy.

In summary

Businesses should use SSL monitoring to ensure their certificates don’t expire because expired SSL certificates can lead to security vulnerabilities, loss of customer trust, potential downtime, and damaged reputation. SSL monitoring as part of a larger, comprehensive IPM strategy helps maintain continuous encryption, protecting sensitive data and ensuring a seamless, secure user experience. And while McLOVIN might not appreciate it, this proactive approach safeguards the business’s reputation and prevents costly disruptions.  

Summary

The recent ServiceNow Secure Sockets Layer (SSL) certificate error disrupted operations for hundreds of organizations causing widespread connectivity failures. IT operations stalled, developers hit roadblocks, and businesses across industries felt the impact. The culprit? An expired SSL certificate.

While these disruptions highlight the importance of SSL monitoring, they point to a deeper issue: trust.

When I asked Google, ‘What is the role of an SSL certificate?’, I received multiple responses. Here are a couple:

An SSL certificate is a digital credential that plays a pivotal role in establishing secure connections over the internet, serving as a trust indicator and ensuring data encryption and authentication during online interactions.” – ServiceNow
An SSL certificate, or Secure Sockets Layer certificate, is a digital object that helps to secure network communications and establish trust between a website and its users.” – Google AI Overview

To confirm how important the idea of trust is, notice how both definitions included that exact word.

What happened?

On September 23, 2024, at approximately 0216 UTC, impact from a management, instrumentation, and discovery (MID) server’s certificate expiration began. And “this issue may be impacting your Integrations, Orchestration, Discovery, and MID Server Script Executions that rely on MID Servers or instance-instance communication, such as Instance Upgrades, Update Set retrieval, AI Search, Virtual Agent, and Cloning between instances” according to their ServiceNow advisory.

This certificate error also comes on the heels of another trust erosion incident in which internal knowledge base (kb) articles could be accessed from an external (read, unauthorized) perspective. While we expect these types of operational incidents organizations of all types and sizes (it’s not a matter if, it’s a matter of when), we also expect learning from them.

What does SSL monitoring have to do with “trust”?

The obvious answer to, ‘Why monitor SSL?’ may be apparent when you read a headline indicating hundreds of organizations and businesses’ operations were disrupted. More importantly, though, it’s about preserving trust.  

In this Forbes article, Catchpoint CEO Mehdi Daoudi explains how trust is ‘the silent commodity that’s bought and sold with every transaction’.  

We trust that when we purchase health and beauty products that we are not smearing damaging products in our hair or skin. We trust when we deposit a mobile check that our money will be deposited safely. And when we can put a name to the companies that sell these products or services, then we can talk about building or preserving reputation.

This is exactly why we built our SSL monitoring to accompany our other suite of critical business capabilities.  

Capabilities like those that can ensure internet network traffic is not hijacked, that can ensure users get their expected results, or that can ensure their information is protected and secured are just such examples.

But what does this have to do with McLOVIN?

What is now considered a meme, when McLOVIN’s Hawaii driver's license was presented, it perfectly illustrates how the store clerk’s trust in its validity was questioned. Think about it: consider an ID issued by an authority. Now consider traveling to a different state or country (as an example). When presenting that ID, people need to be able to trust it is a valid ID even though it was issued by an entity outside of their region.

In this vein, validating an SSL certificate is quite like validating a driver’s license. Both processes involve checking the authenticity and current validity of a credential. When you validate a driver’s license, you check the expiration date, ensure the photo matches the individual, and verify that the license hasn’t been revoked or suspended. This process ensures that the driver is legally allowed to operate a vehicle (or old enough to purchase alcohol!) and that their credentials are up to date.

Similarly, validating an SSL certificate involves checking its expiration date, confirming that it is issued by a trusted Certificate Authority (CA), and ensuring that it hasn’t been revoked. This process ensures that the website can securely encrypt data and that users can trust the site’s identity.

In both cases, the goal is to maintain trust and security. An expired or invalid driver’s license can lead to legal issues and safety concerns, while an expired or invalid SSL certificate can lead to security vulnerabilities, business disruption (as with this ServiceNow incident), loss of user trust, and potential data breaches. Regular SSL monitoring helps prevent these issues by ensuring that the credentials are current and trustworthy.

In summary

Businesses should use SSL monitoring to ensure their certificates don’t expire because expired SSL certificates can lead to security vulnerabilities, loss of customer trust, potential downtime, and damaged reputation. SSL monitoring as part of a larger, comprehensive IPM strategy helps maintain continuous encryption, protecting sensitive data and ensuring a seamless, secure user experience. And while McLOVIN might not appreciate it, this proactive approach safeguards the business’s reputation and prevents costly disruptions.  

This is some text inside of a div block.