Security & Continuity
Certificates Troubleshooting
Browse issue-specific guidance for Certificates.
- ACME challenge path accessible publicly but renewal validation still fails
- ACME renewal works on standby node not active node
- Browser shows certificate warning on internal appliance
- Browser trust warning appears only on mobile devices
- Certificate auto-renewal failed silently on appliance
- Certificate chain valid on Windows not on macOS
- Certificate private key present on server but export option unavailable
- Certificate revocation check slows VPN login from remote regions
- Certificates alerts indicate success while end-user experience never changes
- Certificates configuration survives testing but resets after restart or sync
- Certificates credential or certificate rotation breaks an existing integration
- Certificates feature works in web app but fails in desktop client
- Certificates healthy dashboard status masks a failing production workflow
- Certificates logging shows delivery yet the target workflow never completes
- Certificates new deployment works for pilot group but not for production rollout
- Certificates policy change applies in admin console but target users never receive it
- Certificates quarantine or protection action triggers but recovery workflow fails
- Certificates workflow succeeds for one account but fails for shared or delegated access
- Code signing certificate installed but build agent cannot use it
- Code signing certificate installed but signing pipeline cannot locate thumbprint
- CSR generated with wrong SAN list for customer portal migration
- Internal CA template changed and autoenrollment stalls
- Internal PKI issues certificate correctly yet auto-enrollment ignores new template
- Let’s Encrypt renewal succeeds but web service never reloads new certificate
- RADIUS certificate valid in store but NPS still presents old chain
- Reverse proxy imports PFX but private key unusable
- SAML app metadata imported but app still trusts old signing cert
- TLS inspection appliance resigns traffic with untrusted root on kiosks
- Wildcard certificate renewed but old cert still served
- Wildcard certificate renewed but one subdomain continues serving expired cert