An mTLS certificate chain validates and backend auth still fails
Transport trust succeeds, but revocation and downstream identity wiring no longer agree.
SecurityIntermediate
An mTLS chain validates and backend auth still fails
Transport trust succeeds, but one downstream identity hop still follows the previous header contract.
SecurityAdvanced
mTLS rotation looks complete but one gateway still fails
Certificates were replaced successfully, yet one path still breaks because its trust store still assumes the old chain layout.
SecurityIntermediate
A SAML logout works on the main domain and loops on the callback path
Login succeeds, yet logout or callback validation fails on one route because the service provider reconstructs a different external URL than the browser used.