TLS certificate issuance and renewal checks
A valid certificate needs the correct names, a trusted chain and a working renewal process. HTTPS protects the connection; it does not prove that the application itself is free of vulnerabilities. Identify who manages certificate renewal for each endpoint.
If issuance or renewal fails
- Check the hostname, DNS records, expiration date and the exact validation error.
- Identify whether validation uses an HTTP challenge or DNS records, and verify the required path or DNS changes.
- Check load balancers, proxies and multiple backend nodes that may answer validation requests.
- Confirm that the renewed certificate is deployed to the actual public endpoint, then test it externally.
Do not send private keys in tickets. Provide the public hostname and a redacted error instead. DNS validation credentials should have only the permissions required. Ask for a supported renewal design before changing certificate lifetimes or validation methods.
Further reading: Let’s Encrypt: validation challenges