TLS and Certificate Chain
43 incident problems about TLS and Certificate Chain. Start with the reviewed ones.
Read first
How to split IAM, TLS, and WAF failures into a security operations flowAn InfraTree guide that lays out the first signals to check, the CLI verification order, common misdiagnoses, and a safe recovery path when authentication, authorization, certificate, WAF, and audit log signals mix together and look like a single access failure.Security3 min readHow to isolate an mTLS trust bundle mismatchAn InfraTree guide that lays out the first signals to check, the CLI verification order, common misdiagnoses, and a safe recovery path when the client certificate, server certificate, CA bundle, and sidecar reload timing differ and the handshake fails.Security3 min readHow to safely diagnose a WAF 403 false positiveAn InfraTree guide that lays out the first signals to check, the CLI verification order, common misdiagnoses, and a safe recovery path when it looks like a permissions problem but a specific header, payload, or rule group is blocking legitimate requests.Security3 min read
Recommended problems
Reviewed problems first, then problems with detailed scenarios.
SECURITY-025Locked-down file permission hides SSH authorized_keys from user sessionLocked-down file permission hides SSH authorized_keys from user session is a hands-on troubleshooting drill. The authorized key exists, but the home directory ownership or mode makes the SSH daemon ignore it. Identity and Access Management needs to be checked by narrowing scop...ReviewedSecurityBeginner14 minFreeSECURITY-034TLS renewal updates the leaf certificate but leaves the intermediate chain staleModern browsers appear fine on one path, yet API clients and internal services fail because the server still presents an incomplete chain after renewal.ReviewedSecurityIntermediate21 minFreeLet's Encrypt auto-renewal kept failing until the certificate expiredLet's Encrypt auto-renewal kept failing until the certificate expired is a hands-on troubleshooting drill. Find why ACME HTTP-01 renewals failed silently and fix the challenge path and monitoring. TLS and Certificate Chain needs to be checked by narrowing scope, recent change,...ReviewedSecurityIntermediate16 minFreeNET::ERR_CERT_DATE_INVALID: every visitor sees a certificate warningNET::ERR_CERT_DATE_INVALID: every visitor sees a certificate warning is a hands-on troubleshooting drill. Check the certificate's expiry date against the current time. TLS and Certificate Chain needs to be checked by narrowing scope, recent change, and the current live signal...ReviewedSecurityBeginner3 minFreeSECURITY-002An intermediate certificate chain problem that fails only on certain clientsThe latest browsers connect fine, but some clients fail TLS verification because the server does not send the complete certificate chain.SecurityIntermediate21 minPro
All problems (43)
NET::ERR_CERT_DATE_INVALID: every visitor sees a certificate warningNET::ERR_CERT_DATE_INVALID: every visitor sees a certificate warning is a hands-on troubleshooting drill. Check the certificate's expiry date against the current time. TLS and Certificate Chain needs to be checked by narrowing scope, recent change, and the current live signal...ReviewedSecurityBeginner3 minFreeSECURITY-034TLS renewal updates the leaf certificate but leaves the intermediate chain staleModern browsers appear fine on one path, yet API clients and internal services fail because the server still presents an incomplete chain after renewal.ReviewedSecurityIntermediate21 minFreeSECURITY-025Locked-down file permission hides SSH authorized_keys from user sessionLocked-down file permission hides SSH authorized_keys from user session is a hands-on troubleshooting drill. The authorized key exists, but the home directory ownership or mode makes the SSH daemon ignore it. Identity and Access Management needs to be checked by narrowing scop...ReviewedSecurityBeginner14 minFreeLet's Encrypt auto-renewal kept failing until the certificate expiredLet's Encrypt auto-renewal kept failing until the certificate expired is a hands-on troubleshooting drill. Find why ACME HTTP-01 renewals failed silently and fix the challenge path and monitoring. TLS and Certificate Chain needs to be checked by narrowing scope, recent change,...ReviewedSecurityIntermediate16 minFreeSECURITY-052ACME HTTP-01 renewal failsTLS worked yesterday, but automated renewal now fails because the well-known challenge route is treated like an untrusted request pattern by the current edge policy.SecurityIntermediate20 minFreeSECURITY-082TLS offload proxy re-encrypts with a deprecated cipher set and only one partner API rejects itClient-facing certificates look modern, but one partner integration breaks because the upstream re-encryption profile still uses a weaker legacy policy.SecurityIntermediate17 minFreeSECURITY-073mTLS client authentication failsThe certificate is valid and trusted, but client auth still fails because the service enforces a SAN type that the issued cert never included.SecurityIntermediate18 minFreeSECURITY-067Certificate transparency alert points to a legacy SAN certificate still trusted by one proxy pathThe newly issued certificate is intentional, but one forgotten proxy still trusts the older SAN chain and continues to present the unexpected path.SecurityIntermediate19 minFreeSECURITY-007Fail2ban blocks internal health checks after noisy auth failuresA brute-force defense rule works, but its source grouping catches internal monitoring traffic by mistake.SecurityBeginner15 minFreeSECURITY-013Security group allows HTTPS but blocks OCSP responder pathThe application endpoint is reachable, yet revocation or trust verification fails because outbound checks cannot complete.SecurityBeginner15 minFreeSECURITY-022TLS redirect loop created by mixed secure proxy headersTLS redirect loop created by mixed secure proxy headers is a hands-on troubleshooting drill. Security hardening intends to force HTTPS, but conflicting proxy headers produce an endless redirect path. TLS and Certificate Chain needs to be checked by narrowing scope, recent chan...SecurityBeginner15 minFreeSECURITY-002An intermediate certificate chain problem that fails only on certain clientsThe latest browsers connect fine, but some clients fail TLS verification because the server does not send the complete certificate chain.SecurityIntermediate21 minProSECURITY-357A certificate replacement installs the right chainA certificate replacement installs the right chain focuses on TLS and Certificate Chain and asks the reader to isolate Certificate Trust Failure in NGINX. 실무에서는 certificate-trust-failure 경보만 보는 대신 자산 범위, 권한 변경 이력, 인증서나 정책 만료, 우회 경로 존재 여부를 같이 확인해야 대응 우선순위를 제대로 잡을 수 있습니다. TLS 관점...SecurityAdvanced17 minProSECURITY-387A mutual TLS edge validates the client certificateA mutual TLS edge validates the client certificate focuses on TLS and Certificate Chain and asks the reader to isolate Certificate Trust Failure in NGINX. 실무에서는 auth-and-session-failure 경보만 보는 대신 자산 범위, 권한 변경 이력, 인증서나 정책 만료, 우회 경로 존재 여부를 같이 확인해야 대응 우선순위를 제대로 잡을 수 있습니다. TLS 관점의...SecurityAdvanced17 minProSECURITY-159The mTLS certificate chain validates externally, but the internal proxy strips the client certificate header on HTTP/2 upgrade and backend auth fails only thereTransport security is intact, yet identity propagation across layers is not.SecurityAdvanced17 minProSECURITY-324A mutual TLS path validates at the edge while revocation checks or identity forwarding fail later in the request chain during a failover rehearsalTransport setup succeeds and the secure identity contract breaks farther downstream. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-107mTLS client identity maps to the wrong tenantCertificates are valid, yet authorization fails because the parser extracts a different identity field than the policy engine expects.SecurityAdvanced18 minProSECURITY-094mTLS handshake succeeds to the proxy but upstream certificate pinning breaks only on one pathThe edge trust path looks correct, yet the service still fails because an internal hop enforces a different certificate identity contract.SecurityAdvanced18 minProSECURITY-099Security group egress hardening blocks the OCSP responder and only strict TLS clients fail validationCertificates are current, yet a subset of clients fail because the server-side environment can no longer complete revocation checks through the hardened egress policy.SecurityAdvanced18 minProSECURITY-085Session revocation works centrally but one edge node continues accepting the old JWT until its cache expiresThe revoke event is recorded correctly, yet some requests still succeed because one verifier node has not refreshed its token or key cache.SecurityAdvanced18 minPro