# Mapper.ntppool.org cert expired

**URL:** <https://community.ntppool.org/t/mapper-ntppool-org-cert-expired/4049>\
**Category:** Pool Development\
**Created:** [August 26, 2025, 4:08pm UTC](https://community.ntppool.org/t/mapper-ntppool-org-cert-expired/4049 "2025-08-26T16:08:40Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![ehemmete](https://sea2.discourse-cdn.com/flex016/user_avatar/community.ntppool.org/ehemmete/32/1927_2.png) [@ehemmete](https://community.ntppool.org/u/ehemmete)\
**Post date:** [August 26, 2025, 4:08pm UTC](https://community.ntppool.org/t/mapper-ntppool-org-cert-expired/4049/1 "2025-08-26T16:08:40Z")

</div>

I’m not sure if there is a better place to report this.  
The TLS certificate for [mapper.ntppool.org](http://mapper.ntppool.org) expired Aug 24th, 2025.

 ![Screenshot 2025-08-26 at 11.07.17 AM](https://us1.discourse-cdn.com/flex016/uploads/ntppool/original/2X/0/0754152e1089c76518b254edd2c38b2e98d43da1.png)

---

<div class="post-metadata">

**Author:** ![ask](https://sea2.discourse-cdn.com/flex016/user_avatar/community.ntppool.org/ask/32/907_2.png) [@ask](https://community.ntppool.org/u/ask)\
**Post date:** [August 27, 2025, 12:26am UTC](https://community.ntppool.org/t/mapper-ntppool-org-cert-expired/4049/2 "2025-08-27T00:26:59Z")

</div>

Doh, fixing it now. (And I need to make the alert for this more insistent / prominent!)

---

<div class="post-metadata">

**Author:** ![marco.davids](https://sea2.discourse-cdn.com/flex016/user_avatar/community.ntppool.org/marco.davids/32/767_2.png) [@marco.davids](https://community.ntppool.org/u/marco.davids)\
**Post date:** [August 28, 2025, 7:08am UTC](https://community.ntppool.org/t/mapper-ntppool-org-cert-expired/4049/3 "2025-08-28T07:08:54Z")

</div>

Too bad the name servers for [mapper.ntppool.org](http://mapper.ntppool.org) ([m1.ntpppool.org](http://m1.ntpppool.org) and [m2.ntppool.org](http://m2.ntppool.org)) only have IPv4 addresses and no AAAA records.

Is there a specific reason for that?

---

<div class="post-metadata">

**Author:** ![Bas](https://sea2.discourse-cdn.com/flex016/user_avatar/community.ntppool.org/bas/32/465_2.png) [@Bas](https://community.ntppool.org/u/Bas)\
**Post date:** [August 28, 2025, 1:59pm UTC](https://community.ntppool.org/t/mapper-ntppool-org-cert-expired/4049/4 "2025-08-28T13:59:27Z")

</div>

He has to pay extra for AAAA instead of one A 🤣

---

<div class="post-metadata">

**Author:** ![avij](https://sea2.discourse-cdn.com/flex016/user_avatar/community.ntppool.org/avij/32/197_2.png) [@avij](https://community.ntppool.org/u/avij)\
**Post date:** [September 14, 2026, 4:19pm UTC](https://community.ntppool.org/t/mapper-ntppool-org-cert-expired/4049/5 "2026-09-14T16:19:16Z")

</div>

Hi @ask, [www.mapper.ntppool.org](http://www.mapper.ntppool.org) cert has expired again.

---

<div class="post-metadata">

**Author:** ![ethonbrooks0707](https://sea2.discourse-cdn.com/flex016/user_avatar/community.ntppool.org/ethonbrooks0707/32/2730_2.png) [@ethonbrooks0707](https://community.ntppool.org/u/ethonbrooks0707)\
**Post date:** [September 18, 2026, 7:15pm UTC](https://community.ntppool.org/t/mapper-ntppool-org-cert-expired/4049/6 "2026-09-18T19:15:28Z")

</div>

**Scott Aerators said:** Certificate expiration issues can sometimes go unnoticed until they affect a specific service or connection. Keeping certificates monitored and renewed before the expiration date is a simple way to avoid unexpected interruptions.

---

<div class="post-metadata">

**Author:** ![ask](https://sea2.discourse-cdn.com/flex016/user_avatar/community.ntppool.org/ask/32/907_2.png) [@ask](https://community.ntppool.org/u/ask)\
**Post date:** [September 22, 2026, 5:06am UTC](https://community.ntppool.org/t/mapper-ntppool-org-cert-expired/4049/7 "2026-09-22T05:06:20Z")

</div>

Oof – we’re just getting finishing getting monitoring bits properly in order since the infrastructure move in the spring; but really this should have been setup better long ago! I will see if @gfk or @MagicNTP can help fix it better than I’ve done. 🙂

---

<div class="post-metadata">

**Author:** ![gfk](https://sea2.discourse-cdn.com/flex016/user_avatar/community.ntppool.org/gfk/32/1479_2.png) [@gfk](https://community.ntppool.org/u/gfk)\
**Post date:** [September 29, 2026, 1:59pm UTC](https://community.ntppool.org/t/mapper-ntppool-org-cert-expired/4049/8 "2026-09-29T13:59:09Z")

</div>

This shouldn’t be a problem anymore, as we’ve received a generous sponsorship from the [SSLMate Cert Spotter](https://sslmate.com/certspotter/) service.

A bit of backstory: I’ve been using SSLMate’s Cert Spotter at my day job since they started offering that service. Over the years, [Andrew Ayer](https://www.agwa.name/), who runs SSLMate, has always been very responsive, and a few times he even added features after we discussed our needs with him. So when the certificate expiry problem came up here, I thought of contacting him. I wrote to ask whether SSLMate would consider sponsoring the project, and he immediately offered a free Cert Spotter subscription for the pool’s domains.

It’s now set up: it watches Certificate Transparency logs for our domains, checks the certificates we actually serve, and sends expiry alerts to several volunteers, so a failed renewal shouldn’t go unnoticed again. It’ll also come in handy as we’re in the process of rolling out authoritative DNS over TLS (ADoT) on the name servers, which adds more certificates to keep track of.

Thank you, Andrew and SSLMate, for the generous support!
