Code RoomCertificate verify failed
HardPrep Room Coding #4568

Certificate verify failed

On-callReliability & on-callSenior–Staff~40 min

At 11:20 a subset of your B2B partners — about 30% of inbound API traffic — start failing all calls with 'unable to get local issuer certificate' / 'certificate verify failed'. Your own leaf cert was renewed two weeks ago and shows 300+ days remaining; openssl s_client from your bastion validates the full chain fine. Dashboards: TLS handshake failures spiked only on connections from partners running older pinned trust stores; modern browsers and your monitoring probes are unaffected. The only recent change is that your ACME automation rotated the certificate yesterday during the normal renewal window. How do you triage and mitigate?

What a strong answer looks like

Stop the bleeding first (mitigate), then form hypotheses from real signals. Separate root cause from symptom, communicate status as you go, and close with what prevents a repeat.

0:00 of about 40 min
Which questions mattered is sealed until you submit. Telling you now would just be handing over the edge cases.