Identify the certificate
Start by defining exactly what is failing, which server is affected and whether the problem affects one client or multiple systems.
Check expiration
Check the local configuration that controls the operation. Compare it with a known-good server or client where possible.
Validate trust chain
Run a direct test for the dependency. Capture the exact result so you can distinguish configuration, connectivity and application failures.
Check private key
Review the relevant server-side configuration and logs. Look for timestamps that match the reported failure.
Review service binding
Validate security, permissions and service state before changing production configuration.
Test the application endpoint
After the fix, repeat the original test and document the working configuration so the procedure can be reused.
Useful commands
Run these checks from an elevated PowerShell session where appropriate. Replace example names with your environment.
Certificate inventory
Get-ChildItem Cert:\LocalMachine\My | Select Subject,Issuer,NotAfter,ThumbprintCheck expiration
Get-ChildItem Cert:\LocalMachine\My | Where-Object {$_.NotAfter -lt (Get-Date).AddDays(30)} | Select Subject,NotAfter,ThumbprintQuick troubleshooting path
Use this sequence to isolate the failing dependency before changing production configuration.
Need more infrastructure resources?
Browse free TechRunbook guides, checklists and scripts.
Browse free IT resources →