Symptom67 problems· 7 reviewed

Certificate Trust Failure

67 incident problems that show up as “Certificate Trust Failure”.

All problems (67)

CICD-157A package signing key rotates in the build stage, but the downstream install test still trusts only the old fingerprint and rejects the freshly built repositoryThe package was published correctly, yet the validation environment pins a previous trust root.CI/CDAdvanced17 minProSECURITY-136A truststore update keeps the same certificate subject but a new public key, and one mTLS client still pins the old key hashEverything looks like the same identity, yet a deeper trust assumption at the client breaks connectivity.SecurityAdvanced17 minProCICD-132An ephemeral runner image misses the internal CA root and only private registry pulls fail after autoscaling adds new workersLegacy workers continue working, but new ones cannot trust the organization registry chain.CI/CDAdvanced17 minProSECURITY-129OCSP stapling is healthy at the edge, but the origin health checker trusts only the leaf and marks the backend down on the renewed chainCustomers see a good certificate path, yet the internal monitor fails because its trust assumption is narrower.SecurityAdvanced17 minProCICD-330A container build uses one CA bundle during image creation while the runtime base layer refreshes and trusts a different internal PKI root during a failover rehearsalThe built image and the later-executed image lineage no longer share the same trust store assumptions. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.CI/CDAdvanced18 minProSECURITY-252A mutual TLS path validates client chains while one outbound proxy segment blocks CRL or OCSP fetches during a failover rehearsalThe certificate looks correct and revocation checks quietly fail on one leg of the journey. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-296A new certificate chain validates while one appliance still pins the previous intermediate or key hash and rejects the same service after a control-plane upgradeThe chain is globally right and one trust consumer is still anchored to the past. The workload or policy had been stable, but the upgraded control layer now interprets one dependency differently.SecurityAdvanced18 minProSECURITY-294A new certificate chain validates while one appliance still pins the previous intermediate or key hash and rejects the same service during a failover rehearsalThe chain is globally right and one trust consumer is still anchored to the past. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-298A new certificate chain validates while one appliance still pins the previous intermediate or key hash and rejects the same service during a rollback rehearsalThe chain is globally right and one trust consumer is still anchored to the past. The steady path hides the problem until the system is asked to move backward through the dependency chain.SecurityAdvanced18 minProSECURITY-153A PKI automation job renews the leaf certificate first, but the pinned intermediate bundle on one appliance is refreshed only the next day and outbound trust breaks overnightThe chain is valid globally, yet one dependent appliance still pins the previous chain layout.SecurityAdvanced18 minProSECURITY-113A renewed intermediate certificate is deployed, but the CRL distribution point still serves the expired issuer chainThe visible cert chain looks modern, yet some clients reject it because revocation infrastructure still references the old issuing hierarchy.SecurityAdvanced18 minProSECURITY-147A trust bundle update reaches the API tier, but the sidecar envoy still pins the old bundle hash and east-west mTLS fails only thereCertificate distribution was mostly successful, yet one data-plane component still enforces the previous trust set.SecurityAdvanced18 minProK8S-112HorizontalPodAutoscaler sees the custom metric intermittentlyAutoscaling seems random because the adapter is reachable, yet TLS validation fails sporadically between control plane components.KubernetesAdvanced18 minProSECURITY-198An updated trust bundle reaches the app while the sidecar or proxy path still pins the previous set during a failover rehearsalThe main process trusts the new chain and an adjacent component still rejects it. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced19 minProK8S-092Projected CA bundle on one namespace lags and only that team's jobs fail outbound TLS validationCluster TLS trust is mostly healthy, but one namespace still mounts an older CA bundle and its jobs reject the new upstream certificate path.KubernetesAdvanced19 minProLINUX-067chrony source priority drift pushes one site out of acceptable Kerberos time skewNTP is technically running everywhere, but one location follows a lower-quality source and drifts just far enough to break time-sensitive authentication.LinuxAdvanced21 minProLINUX-007TLS verification intermittently failing due to system time driftCovers a system-time problem where the application is fine but certificate validity-time checks drift.LinuxAdvanced23 minProCICD-023Artifact signing step succeeds locally but fails in CI runnersThe same signing command works on a developer machine but breaks in ephemeral runners because the key material and trust chain differ.CI/CDAdvanced27 minProK8S-035Validating webhook rejects new workloads after certificate rotationThe webhook service is reachable, but admissions fail because the CABundle in the configuration no longer matches the serving certificate chain.KubernetesAdvanced27 minProNETWORK-147A stack member replacement preserves the running config, but the trust device list for MACsec was stored in startup only and secure links never return after rebootOperations seem fine until the mandatory reboot reveals that a security dependency was not restored in both config states.NetworkIntermediate16 minPro