Why does it need to validate a cert? How acceptable is it if you get it wrong? Depending on the answer, perhaps "have a more reliable clock" is the right answer (plenty of embedded devices certainly have a decent idea of what time it is, and if it's already big enough to validate TLS). It seems reasonably probable that the NTP server stops being available for a reasonable amount of time before you have no idea what time it is anymore and can no longer validate certificates; so depending on the device, telemetry might be a good idea too.
It doesn't sound like a reason to give up, though :)
If your system can't handle that, a few options:
- put a clock in your embedded element
- Pin certs
- Use a frontend, embedded only connects to authenticated embedded system (say, with ssh Port forwarding). Frontend does connection correctly.
> What time is it?
Jan 2nd, 2017
> Sorry, your certificate is expired. Access Denied.
Wait, I wrote the wrong date, it's Jan 2nd, 2016
> Ok. Authorized