한국어English日本語简体中文繁體中文DeutschไทยTiếng ViệtРусскийPortuguês (Brasil)EspañolBahasa Indonesia

Game Lag White Paper › L13 Server architecture and operations

Expired or misconfigured TLS certificate TLS certificate expiry / misconfiguration

Cause ID in-cert · Primary owner Infra team (Network infrastructure) · Also Infra team (Server infrastructure), Game team (Client development)

Open the interactive card with figures and simulations →

When the certificate on a login, API, or patch server expires or is missing its intermediate certificate, every client that connects from that moment on fails the TLS connection.

Why The certificate is past its validity period, the server sends it without the intermediate certificate, or the date and time on the player’s device are wrong → Effect The client fails certificate validation and drops the TLS connection → On screen Can’t connect / infinite loading at the login or patch step, or only HTTPS features such as the store fail. Players already connected are usually fine

Symptoms
Can’t connect / infinite loading, Dropped action / rollback
Factors
Stall
Who’s affected
Whole server, One feature only, Just me
When
Right after login or maintenance, During specific actions
Owner
Primary owner Infra team (Network infrastructure) · Also Infra team (Server infrastructure), Game team (Client development)
Game team action items
Log certificate errors under an error code distinct from other connection failures and show a message, if the date is wrong tell players to set their device’s date and time automatically, if you use certificate pinning include a backup key and coordinate the certificate rotation schedule with the infra team.
Infra team action items
Network: when TLS terminates at the load balancer or CDN, alert on managed certificate auto-renewal status and days remaining (DaysToExpiry on ACM), keep the validation DNS records in place. Servers/OS: when TLS terminates on the servers, automate renewal and reload the config after renewal, configure the full chain including intermediate certificates, check the remaining validity of every login, API, and patch address from outside on a schedule and alert on it.
Ballpark numbers
Let’s Encrypt certificates last 90 days and renewal every 60 days is recommended; AWS Certificate Manager checks DNS-validated certificates 45 days before expiry and renews them automatically. If automatic renewal fails silently, new connections are all blocked at exactly the expiry time.
On the graph
Mass disconnect · Successful logins, TLS handshake errors
Where to look
openssl s_client -connect HOST:443 -showcerts to see the certificate list the server actually sends, then each certificate’s expiry date (notAfter) with openssl x509 -noout -enddate. If TLS terminates at the load balancer, TLS negotiation error count (ClientTLSNegotiationErrorCount on AWS ALB and NLB) and successful logins
Confirmed if
The expiry date has passed or the intermediate certificate is missing from the list the server sends, and errors started rising at the expiry time or when the certificate was changed
Ruled out if
Certificate list and expiry date are fine but only some players fail: check the date and time on those players’ devices or the root certificate list of an old OS
Check with
Infra tools (no game code needed)
Learn more
A config missing the intermediate certificate can look fine when you open it in a desktop browser. Browsers remember intermediate certificates picked up from other sites and fill the gap, but clients without that memory, such as Android apps, fail. Validity periods are also getting shorter. Let’s Encrypt plans to cut the default validity to 64 days in 2027 and 45 days in 2028, so a setup hard-coded to renew every 60 days leaves only four days of margin with a 64-day certificate and runs past expiry with a 45-day one. AWS Certificate Manager also doesn’t auto-renew imported certificates, and renewal fails if you delete the validation DNS record. Blocked logins look similar to “DNS failures and delays,” but a certificate problem fails at the TLS handshake after the server address has been resolved, and it starts at the expiry time or when the certificate was changed.

Sources

  1. RFC 5280: Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile IETF
    A certificate is valid from notBefore to notAfter; path validation checks that the current time falls within the validity period of every certificate in the chain (it fails if the validating side’s clock is wrong)
  2. FAQ Let's Encrypt
    Default certificate lifetime of 90 days, renewal every 60 days recommended
  3. Decreasing Certificate Lifetimes to 45 Days Let's Encrypt
    Default lifetime cut to 64 days in February 2027 and 45 days in February 2028; a fixed 60-day renewal interval will no longer be enough, so renewal at about two-thirds of the lifetime is recommended
  4. Renewal for domains validated by DNS AWS
    45 days before expiry, checks whether the certificate is in use by an AWS service and whether the validation CNAME record exists, then renews automatically; if it can’t validate, sends notices 30, 15, 7, 3, and 1 days before expiry
  5. Managed certificate renewal in AWS Certificate Manager AWS
    Imported certificates and certificates that have already expired are not eligible for automatic renewal
  6. Supported CloudWatch metrics AWS
    DaysToExpiry: days left until the certificate expires, published twice a day until expiry
  7. Security with network protocols Android (Google)
    If the server omits the intermediate certificate, Android apps fail with SSLHandshakeException, while desktop browsers may fill it in from cached intermediates and show no error; check the chain the server sends with openssl s_client
  8. Network security configuration Android (Google)
    With certificate pinning, you must include backup keys to prepare for key rotation or CA changes; otherwise connections break until the app is updated
  9. openssl-s_client OpenSSL
    -showcerts: shows the certificates the server sent, in the order it sent them (not a validated chain)
  10. openssl-x509 OpenSSL
    -enddate: prints the certificate’s expiry date (notAfter); -checkend: checks whether it expires within the given number of seconds
  11. CloudWatch metrics for your Application Load Balancer AWS
    ClientTLSNegotiationErrorCount: number of connections that failed to establish a TLS session, for example because the client dropped the connection after failing to validate the server certificate
  12. CloudWatch metrics for your Network Load Balancer AWS
    ClientTLSNegotiationErrorCount: number of TLS handshakes that failed during negotiation between a client and a TLS listener

See also

Same layer: L13 Server architecture and operations

Same symptom (Can’t connect / infinite loading), other layers

View the interactive card with figures and simulations