Topic43 problems· 4 reviewed

TLS and Certificate Chain

43 incident problems about TLS and Certificate Chain. Start with the reviewed ones.

All problems (43)

SECURITY-088Mutual TLS is enabled but the CRL endpoint is unreachable and only strict clients reject the serverCertificates are otherwise valid, but some clients fail because they require revocation checking and the CRL distribution path is no longer reachable.SecurityAdvanced19 minProSECURITY-066JWKS cache on the API gateway stays stale after OIDC signing key rotationThe identity provider is healthy and publishes the new key, but valid tokens still fail because the gateway never refreshed its cached trust material in time.SecurityAdvanced20 minProSECURITY-057Certificate pinning fails only on the guest network after SSL inspection is enabledThe app works on trusted networks, but mobile users on the guest path fail because the intercepted certificate no longer matches the pinned expectation.SecurityAdvanced22 minProSECURITY-051JWKS key rotation reaches the web tier but one API pod still caches the old signerLogin works on some paths, yet token validation fails intermittently because one long-lived process never refreshed the current signing keys.SecurityAdvanced24 minProSECURITY-032KMS alias resolves correctly but decrypt still fails for the app roleThe application can discover the key alias and reach KMS, yet decrypt operations fail because the key policy and IAM policy do not grant the same effective path.SecurityAdvanced26 minProSECURITY-009Mutual TLS works on primary path but fails after east-west failoverCertificates and policies look valid, but the fallback service path presents a different trust context and breaks authentication.SecurityAdvanced29 minProSECURITY-120The reverse proxy strips HSTS on 304 responses and scanners report an intermittent downgrade riskMost requests include the header, but cache validation paths omit it and some scanners correctly flag the inconsistent transport posture.SecurityAdvanced16 minProSECURITY-293A new certificate chain validates while one appliance still pins the previous intermediate or key hash and rejects the same service after a maintenance template changeThe chain is globally right and one trust consumer is still anchored to the past. The path looked healthy before the template changed, but one inherited assumption no longer matches the live environment.SecurityAdvanced17 minProSECURITY-297A new certificate chain validates while one appliance still pins the previous intermediate or key hash and rejects the same service after a retention policy refreshThe chain is globally right and one trust consumer is still anchored to the past. The operational object still exists somewhere in the system, but the lifecycle policy around its supporting state no longer matches reality.SecurityAdvanced17 minProSECURITY-295A new certificate chain validates while one appliance still pins the previous intermediate or key hash and rejects the same service after an environment identity renameThe chain is globally right and one trust consumer is still anchored to the past. The functional path still exists, but one identity, namespace, or naming assumption still points at the previous environment contract.SecurityAdvanced17 minProSECURITY-136A truststore update keeps the same certificate subject but a new public key, and one mTLS client still pins the old key hashEverything looks like the same identity, yet a deeper trust assumption at the client breaks connectivity.SecurityAdvanced17 minProSECURITY-129OCSP stapling is healthy at the edge, but the origin health checker trusts only the leaf and marks the backend down on the renewed chainCustomers see a good certificate path, yet the internal monitor fails because its trust assumption is narrower.SecurityAdvanced17 minProSECURITY-252A mutual TLS path validates client chains while one outbound proxy segment blocks CRL or OCSP fetches during a failover rehearsalThe certificate looks correct and revocation checks quietly fail on one leg of the journey. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-296A new certificate chain validates while one appliance still pins the previous intermediate or key hash and rejects the same service after a control-plane upgradeThe chain is globally right and one trust consumer is still anchored to the past. The workload or policy had been stable, but the upgraded control layer now interprets one dependency differently.SecurityAdvanced18 minProSECURITY-294A new certificate chain validates while one appliance still pins the previous intermediate or key hash and rejects the same service during a failover rehearsalThe chain is globally right and one trust consumer is still anchored to the past. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-298A new certificate chain validates while one appliance still pins the previous intermediate or key hash and rejects the same service during a rollback rehearsalThe chain is globally right and one trust consumer is still anchored to the past. The steady path hides the problem until the system is asked to move backward through the dependency chain.SecurityAdvanced18 minProSECURITY-153A PKI automation job renews the leaf certificate first, but the pinned intermediate bundle on one appliance is refreshed only the next day and outbound trust breaks overnightThe chain is valid globally, yet one dependent appliance still pins the previous chain layout.SecurityAdvanced18 minProSECURITY-113A renewed intermediate certificate is deployed, but the CRL distribution point still serves the expired issuer chainThe visible cert chain looks modern, yet some clients reject it because revocation infrastructure still references the old issuing hierarchy.SecurityAdvanced18 minProSECURITY-147A trust bundle update reaches the API tier, but the sidecar envoy still pins the old bundle hash and east-west mTLS fails only thereCertificate distribution was mostly successful, yet one data-plane component still enforces the previous trust set.SecurityAdvanced18 minProSECURITY-198An updated trust bundle reaches the app while the sidecar or proxy path still pins the previous set during a failover rehearsalThe main process trusts the new chain and an adjacent component still rejects it. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced19 minPro