Quick troubleshooting view
The browsers report that the TLS certificate of the site is not no longer valid….
- Check dates
- Control renewal.
- Check DNS.
- Renew the certificate.
- Correct the ACME challenge.
- ,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,, ,, ,,,,,,,
Contextual technician plan
Check the certificate actually presented by the server.
“Check dates” should produce an observation that clearly confirms or rules out “Automatic failure renewal.”.
If the observation is normal, lower “Automatic failure renewal.” in the ranking and continue with the next distinct check.
If the observation is abnormal, keep the evidence and investigate “Automatic failure renewal.” first. Related action: Renew the certificate.
Reel the logs, encrypt/ACME or the host interface.
The exact failing name should resolve through the expected DNS server to the expected record without timeout.
If the exact name resolves correctly, compare application cache, suffix/search domain and the client or network where the failure remains.
If resolution fails or returns the wrong record, keep the queried server and answer and correct the resolver, zone/record or DNS path that is actually wrong.
The domain must point correctly to the expected service.
The exact failing name should resolve through the expected DNS server to the expected record without timeout.
If the exact name resolves correctly, compare application cache, suffix/search domain and the client or network where the failure remains.
If resolution fails or returns the wrong record, keep the queried server and answer and correct the resolver, zone/record or DNS path that is actually wrong.
In a cluster or proxy, all frontals must present the right certificate.
“Check all nodes.” should produce an observation that clearly confirms or rules out “Certificate installed on the wrong service.”.
If the observation is normal, lower “Certificate installed on the wrong service.” in the ranking and continue with the next distinct check.
If the observation is abnormal, keep the evidence and investigate “Certificate installed on the wrong service.” first.
Repeat the same validation test after the correction and confirm the original symptom is gone. Validate stability before closing the incident.
Before changing configuration, record the current value and a way back.
Ecstasy the supplier if the certificate is automatically managed by its platform and no longer renews.
The browsers report that the TLS certificate of the site is not no longer valid.
Causes probables
- Automatic failure renewal.
- DNS/HTTP cannot be validated.
- Improper certificate configuration.
- Certificate installed on the wrong service.
Diagnostic étape par étape
- 1
Check dates
Check the certificate actually presented by the server.
- 2
Control renewal.
Reel the logs, encrypt/ACME or the host interface.
- 3
Check DNS.
The domain must point correctly to the expected service.
- 4
Check all nodes.
In a cluster or proxy, all frontals must present the right certificate.
Solutions possibles
- Renew the certificate.
- Correct the ACME challenge.
- ,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,, ,, ,,,,,,,
Ecstasy the supplier if the certificate is automatically managed by its platform and no longer renews.