Symptom67 problems· 7 reviewed

Certificate Trust Failure

67 incident problems that show up as “Certificate Trust Failure”.

Read first

Recommended problems

Reviewed problems first, then problems with detailed scenarios.

LINUX-096NTP is synchronized but the hardware clock drifts back after every reboot and breaks certificatesThe running host time looks correct, but restarts reintroduce skew because the persistent hardware clock was never aligned.ReviewedLinuxIntermediate14 minFreeNETWORK-009An SNI routing problem where the TLS handshake fails only on certain domainsA situation where the certificate is valid but SNI routing is wrong, so only some domains fail.ReviewedNetworkAdvanced24 minProNETWORK-020The CDN cache is fine, but a TLS version difference with the origin fails only miss requestsA situation where most requests are cache hits and look fine, but origin communication breaks only in the cache-miss segment.ReviewedNetworkIntermediate24 minProSECURITY-025Locked-down file permission hides SSH authorized_keys from user sessionLocked-down file permission hides SSH authorized_keys from user session is a hands-on troubleshooting drill. The authorized key exists, but the home directory ownership or mode makes the SSH daemon ignore it. Identity and Access Management needs to be checked by narrowing scop...ReviewedSecurityBeginner14 minFreeSECURITY-034TLS renewal updates the leaf certificate but leaves the intermediate chain staleModern browsers appear fine on one path, yet API clients and internal services fail because the server still presents an incomplete chain after renewal.ReviewedSecurityIntermediate21 minFreeLet's Encrypt auto-renewal kept failing until the certificate expiredLet's Encrypt auto-renewal kept failing until the certificate expired is a hands-on troubleshooting drill. Find why ACME HTTP-01 renewals failed silently and fix the challenge path and monitoring. TLS and Certificate Chain needs to be checked by narrowing scope, recent change,...ReviewedSecurityIntermediate16 minFree

All problems (67)

NET::ERR_CERT_DATE_INVALID: every visitor sees a certificate warningNET::ERR_CERT_DATE_INVALID: every visitor sees a certificate warning is a hands-on troubleshooting drill. Check the certificate's expiry date against the current time. TLS and Certificate Chain needs to be checked by narrowing scope, recent change, and the current live signal...ReviewedSecurityBeginner3 minFreeSECURITY-034TLS renewal updates the leaf certificate but leaves the intermediate chain staleModern browsers appear fine on one path, yet API clients and internal services fail because the server still presents an incomplete chain after renewal.ReviewedSecurityIntermediate21 minFreeLINUX-096NTP is synchronized but the hardware clock drifts back after every reboot and breaks certificatesThe running host time looks correct, but restarts reintroduce skew because the persistent hardware clock was never aligned.ReviewedLinuxIntermediate14 minFreeSECURITY-025Locked-down file permission hides SSH authorized_keys from user sessionLocked-down file permission hides SSH authorized_keys from user session is a hands-on troubleshooting drill. The authorized key exists, but the home directory ownership or mode makes the SSH daemon ignore it. Identity and Access Management needs to be checked by narrowing scop...ReviewedSecurityBeginner14 minFreeLet's Encrypt auto-renewal kept failing until the certificate expiredLet's Encrypt auto-renewal kept failing until the certificate expired is a hands-on troubleshooting drill. Find why ACME HTTP-01 renewals failed silently and fix the challenge path and monitoring. TLS and Certificate Chain needs to be checked by narrowing scope, recent change,...ReviewedSecurityIntermediate16 minFreeSECURITY-052ACME HTTP-01 renewal failsTLS worked yesterday, but automated renewal now fails because the well-known challenge route is treated like an untrusted request pattern by the current edge policy.SecurityIntermediate20 minFreeLINUX-089rsync backup over SSH stallsNetwork reachability is fine, but the batch backup never starts because the negotiated SSH crypto overlap disappeared during a hardening change.LinuxIntermediate16 minFreeSECURITY-082TLS offload proxy re-encrypts with a deprecated cipher set and only one partner API rejects itClient-facing certificates look modern, but one partner integration breaks because the upstream re-encryption profile still uses a weaker legacy policy.SecurityIntermediate17 minFreeSECURITY-073mTLS client authentication failsThe certificate is valid and trusted, but client auth still fails because the service enforces a SAN type that the issued cert never included.SecurityIntermediate18 minFreeSECURITY-067Certificate transparency alert points to a legacy SAN certificate still trusted by one proxy pathThe newly issued certificate is intentional, but one forgotten proxy still trusts the older SAN chain and continues to present the unexpected path.SecurityIntermediate19 minFreeSECURITY-007Fail2ban blocks internal health checks after noisy auth failuresA brute-force defense rule works, but its source grouping catches internal monitoring traffic by mistake.SecurityBeginner15 minFreeCICD-077GitHub Actions artifact download fails on self-hosted runnersThe workflow is correct, but only one runner cannot fetch artifacts because its local time drift makes a short-lived signed URL look expired immediately.CI/CDIntermediate17 minFreeK8S-038Private registry pull failsThe imagePullSecret is correct, but the runtime on each node still rejects the registry because the certificate authority was never trusted at the container runtime layer.KubernetesIntermediate23 minFreeSECURITY-013Security group allows HTTPS but blocks OCSP responder pathThe application endpoint is reachable, yet revocation or trust verification fails because outbound checks cannot complete.SecurityBeginner15 minFreeSECURITY-022TLS redirect loop created by mixed secure proxy headersTLS redirect loop created by mixed secure proxy headers is a hands-on troubleshooting drill. Security hardening intends to force HTTPS, but conflicting proxy headers produce an endless redirect path. TLS and Certificate Chain needs to be checked by narrowing scope, recent chan...SecurityBeginner15 minFreeNETWORK-009An SNI routing problem where the TLS handshake fails only on certain domainsA situation where the certificate is valid but SNI routing is wrong, so only some domains fail.ReviewedNetworkAdvanced24 minProNETWORK-020The CDN cache is fine, but a TLS version difference with the origin fails only miss requestsA situation where most requests are cache hits and look fine, but origin communication breaks only in the cache-miss segment.ReviewedNetworkIntermediate24 minProSECURITY-002An intermediate certificate chain problem that fails only on certain clientsThe latest browsers connect fine, but some clients fail TLS verification because the server does not send the complete certificate chain.SecurityIntermediate21 minProSECURITY-357A certificate replacement installs the right chainA certificate replacement installs the right chain focuses on TLS and Certificate Chain and asks the reader to isolate Certificate Trust Failure in NGINX. 실무에서는 certificate-trust-failure 경보만 보는 대신 자산 범위, 권한 변경 이력, 인증서나 정책 만료, 우회 경로 존재 여부를 같이 확인해야 대응 우선순위를 제대로 잡을 수 있습니다. TLS 관점...SecurityAdvanced17 minProSECURITY-387A mutual TLS edge validates the client certificateA mutual TLS edge validates the client certificate focuses on TLS and Certificate Chain and asks the reader to isolate Certificate Trust Failure in NGINX. 실무에서는 auth-and-session-failure 경보만 보는 대신 자산 범위, 권한 변경 이력, 인증서나 정책 만료, 우회 경로 존재 여부를 같이 확인해야 대응 우선순위를 제대로 잡을 수 있습니다. TLS 관점의...SecurityAdvanced17 minPro