I had a question about mTLS client certs, and handling their expiry.
What are the best practices around rotation of client certs?
We have been using scripts to rotate client certs on end-point machines, but at any point of time, a good percentage of machines are offline, and if they will not be able to authenticate with the server when they come back up.
Any pointers to solutions and/or best practices will be much appreciated.