Scenario
A CA renewal appears complete, yet new certificate issuance begins failing for previously healthy templates.
Recommended Resolution Path
- Review CA service state, chain trust, and template publication after the renewal.
- Confirm clients trust the renewed chain and that CRLs are updated.
- Test one low-risk template issuance before assuming the CA is fully healthy.
- Capture the renewal sequence for future maintenance documentation.
Technician Notes
Capture the exact scope of impact, confirm which dependency failed first, and document whether the issue reflects broader domain or server drift.
- Log in to post comments