Skip to main content

FAQ

Short answers to the questions operators ask most often. Each one links to the full runbook.

Availability​

If the Sectigo Edge cloud is unreachable, do my services go down?​

No. Certificates that are already deployed keep serving. New issuance fails closed, because it needs both your Mesh Node and Sectigo to approve each transaction. Approved requests that could not be delivered wait in the node's durable outbox and are replayed. See Backup & recovery of nodes.

What happens if a Mesh Node goes offline?​

The console shows it as offline and marks the tenant Degraded. Issuance continues as long as enough other healthy nodes can meet your approval quorum. Otherwise it fails with customer_quorum_unavailable. Run more nodes than your quorum requires. See Backup & recovery of nodes.

Do I need to open inbound firewall ports?​

No. Mesh Nodes connect outbound to Sectigo Edge and receive commands, such as promotions and migration waves, over that authenticated channel.

Rotation and revocation​

Can a failed rotation take my service down?​

It is designed not to. The new certificate is staged next to the active one and is promoted only after the node proves your service presents the exact new certificate. A failed health check restores the previous generation automatically within the rollback window. See Zero-downtime rotation.

Why can't I select "Automatic after exact health" in the policy editor?​

Automatic promotion needs an activating adapter: NGINX, Apache, Java PKCS#12 or HashiCorp Vault. Allow one of those deployment paths in the profile first.

Can I undo a revocation?​

No. Revocation is permanent, including the Certificate hold reason. Issue a new certificate instead. If the set has a healthy standby, keep Promote healthy standby first selected so the service keeps running.

How quickly do relying parties see a revocation?​

New OCSP revoked responses and a new CRL generation are requested immediately. If publication fails, the certificate stays revoked and publication is retried after 1 minute, then every 5 minutes. CRL responses may be cached for up to one hour, and OCSP caching follows each response's nextUpdate. See Revocation & CRL/OCSP.

My OCSP client gets malformedRequest. Why?​

The responder serves pre-produced responses and rejects nonces, signed requests, multiple CertIDs and extensions. Turn off the client's OCSP nonce, for example with openssl ocsp -no_nonce.

Approvals and change control​

Why can't I approve my own change?​

Policy activation, migration approval, migration recovery and issuance resume all require a different enterprise identity from the person who requested them. Separation of duties uses the immutable identity from your identity provider, not the email address, so a second email address for the same person does not help.

Why did my approved policy fail to activate with policy_impact_changed?​

Something in the estate changed after the proposal was reviewed: a new endpoint, expired capability evidence, a new dependency edge, a profile mapping, or the Sectigo platform baseline. The original proposer must select Refresh estate impact, and then it can be approved again. See Policy changes & approvals.

Can I make the Sectigo platform baseline less strict?​

No. The baseline is enforced independently, and your enterprise policy and profiles can only narrow it.

Why does every privileged action ask me to sign in again?​

Privileged actions need MFA completed within the last ten minutes (step_up_required). Some tenants also require a passkey or phishing-resistant MFA (phishing_resistant_step_up_required).

Can one person pause issuance?​

Yes. Pausing removes authority, so one authorized Break-glass Operator can do it immediately. Resuming restores authority, so it always needs two people within a ten-minute window. See Incident response & break-glass.

Migrations​

Can I resume a migration that rolled back?​

No. A rolled-back plan stays locked. You record a remediation, have a second person approve the recovery evidence, and then create a successor plan that is rebuilt from current state. See Cryptographic migrations.

Why can't I disable automatic rollback for a migration?​

It is mandatory for every migration. A target that fails health restores its exact source certificate. So does every target already promoted in the same wave.

Audit and evidence​

How does an auditor know the evidence was not altered?​

The exported proof is verified offline with sharppki-verify, against public keys the auditor pinned independently. The verifier never trusts the keys inside the bundle. The proof is anchored in an audit checkpoint that your own Mesh Nodes witnessed. See Audit & evidence export.

Why is evidence export waiting?​

Export waits until enough of your Mesh Nodes have witnessed the latest checkpoint (audit_customer_witness_pending). Keep eligible nodes connected and retry.

Can a trust event or an OTLP collector approve anything?​

No. Trust events and OTLP exports are low-authority deliveries. They can tell your automation to refresh, but every privileged action still goes through the normal authenticated and approved API.

Integrations​

Why does my Sectigo SCM integration show degraded right after I save it?​

The SCM integration runs in the cloud and has no live connectivity check, so Sectigo Edge records scm_connectivity_not_verified instead of claiming that it is healthy. Issue a test certificate to confirm connectivity.

Where are my Vault tokens, PKCS#11 PINs and keystore passwords stored?​

On the Mesh Node, in files you control. The console only stores a non-secret local/... adapter reference, and the node resolves it locally. Secrets are never part of the cloud configuration.