Report each server certificate against the config that loaded it (#4664)
`tls_server_cert_serial` reports whichever certificate OpenSSL gave the lower slot index, not the one in `tls-cert-file`. Slot order is by key algorithm, so with an RSA and an ECDSA certificate configured, swapping the two config values produces identical INFO output. Anyone alerting on `tls_server_cert_expires_in_seconds` silently starts watching a different file the moment they add an alt certificate. This captures each certificate's serial and expiry while the context is being built, which is the last point where the file it came from is known, and carries those with the context. This was generated by AI but verified, with love, by a human. --------- Signed-off-by: Madelyn Olson <madelyneolson@gmail.com>
M
Madelyn Olson committed
3f9062ed54d56ec0e6b0cfb0037cebbd3726acdc
Parent: d265ca9
Committed by GitHub <noreply@github.com>
on 9/16/2026, 6:07:13 AM