When the certificate on a login, API, or patch server expires or is missing its intermediate certificate, every client that connects from that moment on fails the TLS connection.
Why The certificate is past its validity period, the server sends it without the intermediate certificate, or the date and time on the player’s device are wrong → Effect The client fails certificate validation and drops the TLS connection → On screen Can’t connect / infinite loading at the login or patch step, or only HTTPS features such as the store fail. Players already connected are usually fine
Right after login or maintenance, During specific actions
Owner
Primary owner Infra team (Network infrastructure) · Also Infra team (Server infrastructure), Game team (Client development)
Game team action items
Log certificate errors under an error code distinct from other connection failures and show a message, if the date is wrong tell players to set their device’s date and time automatically, if you use certificate pinning include a backup key and coordinate the certificate rotation schedule with the infra team.
Infra team action items
Network: when TLS terminates at the load balancer or CDN, alert on managed certificate auto-renewal status and days remaining (DaysToExpiry on ACM), keep the validation DNS records in place. Servers/OS: when TLS terminates on the servers, automate renewal and reload the config after renewal, configure the full chain including intermediate certificates, check the remaining validity of every login, API, and patch address from outside on a schedule and alert on it.
Ballpark numbers
Let’s Encrypt certificates last 90 days and renewal every 60 days is recommended; AWS Certificate Manager checks DNS-validated certificates 45 days before expiry and renews them automatically. If automatic renewal fails silently, new connections are all blocked at exactly the expiry time.
On the graph
Mass disconnect · Successful logins, TLS handshake errors
Where to look
openssl s_client -connect HOST:443 -showcerts to see the certificate list the server actually sends, then each certificate’s expiry date (notAfter) with openssl x509 -noout -enddate. If TLS terminates at the load balancer, TLS negotiation error count (ClientTLSNegotiationErrorCount on AWS ALB and NLB) and successful logins
Confirmed if
The expiry date has passed or the intermediate certificate is missing from the list the server sends, and errors started rising at the expiry time or when the certificate was changed
Ruled out if
Certificate list and expiry date are fine but only some players fail: check the date and time on those players’ devices or the root certificate list of an old OS
Check with
Infra tools (no game code needed)
Learn more
A config missing the intermediate certificate can look fine when you open it in a desktop browser. Browsers remember intermediate certificates picked up from other sites and fill the gap, but clients without that memory, such as Android apps, fail. Validity periods are also getting shorter. Let’s Encrypt plans to cut the default validity to 64 days in 2027 and 45 days in 2028, so a setup hard-coded to renew every 60 days leaves only four days of margin with a 64-day certificate and runs past expiry with a 45-day one. AWS Certificate Manager also doesn’t auto-renew imported certificates, and renewal fails if you delete the validation DNS record. Blocked logins look similar to “DNS failures and delays,” but a certificate problem fails at the TLS handshake after the server address has been resolved, and it starts at the expiry time or when the certificate was changed.
FAQLet's Encrypt Default certificate lifetime of 90 days, renewal every 60 days recommended
Decreasing Certificate Lifetimes to 45 DaysLet's Encrypt Default lifetime cut to 64 days in February 2027 and 45 days in February 2028; a fixed 60-day renewal interval will no longer be enough, so renewal at about two-thirds of the lifetime is recommended
Renewal for domains validated by DNSAWS 45 days before expiry, checks whether the certificate is in use by an AWS service and whether the validation CNAME record exists, then renews automatically; if it can’t validate, sends notices 30, 15, 7, 3, and 1 days before expiry
Supported CloudWatch metricsAWS DaysToExpiry: days left until the certificate expires, published twice a day until expiry
Security with network protocolsAndroid (Google) If the server omits the intermediate certificate, Android apps fail with SSLHandshakeException, while desktop browsers may fill it in from cached intermediates and show no error; check the chain the server sends with openssl s_client
Network security configurationAndroid (Google) With certificate pinning, you must include backup keys to prepare for key rotation or CA changes; otherwise connections break until the app is updated
openssl-s_clientOpenSSL -showcerts: shows the certificates the server sent, in the order it sent them (not a validated chain)
openssl-x509OpenSSL -enddate: prints the certificate’s expiry date (notAfter); -checkend: checks whether it expires within the given number of seconds
CloudWatch metrics for your Application Load BalancerAWS ClientTLSNegotiationErrorCount: number of connections that failed to establish a TLS session, for example because the client dropped the connection after failing to validate the server certificate