Symptom67 problems· 7 reviewed

Certificate Trust Failure

67 incident problems that show up as “Certificate Trust Failure”.

All problems (67)

SECURITY-159The mTLS certificate chain validates externally, but the internal proxy strips the client certificate header on HTTP/2 upgrade and backend auth fails only thereTransport security is intact, yet identity propagation across layers is not.SecurityAdvanced17 minProSECURITY-324A mutual TLS path validates at the edge while revocation checks or identity forwarding fail later in the request chain during a failover rehearsalTransport setup succeeds and the secure identity contract breaks farther downstream. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-107mTLS client identity maps to the wrong tenantCertificates are valid, yet authorization fails because the parser extracts a different identity field than the policy engine expects.SecurityAdvanced18 minProSECURITY-094mTLS handshake succeeds to the proxy but upstream certificate pinning breaks only on one pathThe edge trust path looks correct, yet the service still fails because an internal hop enforces a different certificate identity contract.SecurityAdvanced18 minProSECURITY-099Security group egress hardening blocks the OCSP responder and only strict TLS clients fail validationCertificates are current, yet a subset of clients fail because the server-side environment can no longer complete revocation checks through the hardened egress policy.SecurityAdvanced18 minProSECURITY-088Mutual TLS is enabled but the CRL endpoint is unreachable and only strict clients reject the serverCertificates are otherwise valid, but some clients fail because they require revocation checking and the CRL distribution path is no longer reachable.SecurityAdvanced19 minProSECURITY-066JWKS cache on the API gateway stays stale after OIDC signing key rotationThe identity provider is healthy and publishes the new key, but valid tokens still fail because the gateway never refreshed its cached trust material in time.SecurityAdvanced20 minProCICD-099Image signing succeeds in CI but the admission policy rejects the signature issuer after root rotationThe build publishes a signed image, yet cluster admission fails because the verifier still trusts the old signing root only.CI/CDAdvanced21 minProK8S-081Readiness passes but Envoy sidecar cannot reach the control plane after a trust bundle splitThe app container is healthy, yet traffic still fails because the sidecar lost trust in the mesh control plane after the certificate bundle changed unevenly.KubernetesAdvanced21 minProSECURITY-057Certificate pinning fails only on the guest network after SSL inspection is enabledThe app works on trusted networks, but mobile users on the guest path fail because the intercepted certificate no longer matches the pinned expectation.SecurityAdvanced22 minProK8S-087OIDC provider issuer URL rotates and every projected token verifier in the cluster rejects new tokensToken projection still works, but consumers fail because the issuer trust path and JWKS discovery URL changed underneath long-lived verifiers.KubernetesAdvanced22 minProSECURITY-051JWKS key rotation reaches the web tier but one API pod still caches the old signerLogin works on some paths, yet token validation fails intermittently because one long-lived process never refreshed the current signing keys.SecurityAdvanced24 minProSECURITY-009Mutual TLS works on primary path but fails after east-west failoverCertificates and policies look valid, but the fallback service path presents a different trust context and breaks authentication.SecurityAdvanced29 minProNETWORK-139A CAPWAP access point reaches the controller, but DTLS setup failsLayer-3 reachability is fine, yet management onboarding stalls on the trust layer.NetworkIntermediate16 minProLINUX-155A chrony source remains reachable through an ACL exception, but NTS validation breaks after the host trust store drops the old rootTime sync traffic still flows, yet secure validation now fails for one trust-specific reason.LinuxAdvanced16 minProSECURITY-120The reverse proxy strips HSTS on 304 responses and scanners report an intermittent downgrade riskMost requests include the header, but cache validation paths omit it and some scanners correctly flag the inconsistent transport posture.SecurityAdvanced16 minProK8S-131A NetworkPolicy allows the outbound proxy but still blocks OCSP and CRL endpoints, so strict clients fail external TLS validationEgress seems mostly open, yet revocation checks cannot complete because only the primary proxy path was modeled.KubernetesAdvanced17 minProSECURITY-293A new certificate chain validates while one appliance still pins the previous intermediate or key hash and rejects the same service after a maintenance template changeThe chain is globally right and one trust consumer is still anchored to the past. The path looked healthy before the template changed, but one inherited assumption no longer matches the live environment.SecurityAdvanced17 minProSECURITY-297A new certificate chain validates while one appliance still pins the previous intermediate or key hash and rejects the same service after a retention policy refreshThe chain is globally right and one trust consumer is still anchored to the past. The operational object still exists somewhere in the system, but the lifecycle policy around its supporting state no longer matches reality.SecurityAdvanced17 minProSECURITY-295A new certificate chain validates while one appliance still pins the previous intermediate or key hash and rejects the same service after an environment identity renameThe chain is globally right and one trust consumer is still anchored to the past. The functional path still exists, but one identity, namespace, or naming assumption still points at the previous environment contract.SecurityAdvanced17 minPro