Skip to main content

Troubleshooting

Sectigo Edge reports problems with a precise error code instead of a generic failure. API errors look like this:

{
"error": {
"code": "step_up_required",
"message": "This action requires an MFA-authenticated privileged session issued within the last ten minutes",
"request_id": "c0f3…"
}
}

Search this page for the code. When you contact support, include the request_id.

First checks​

CheckHow
Is issuance paused?The top bar shows issuance paused. Errors return HTTP 423 with issuance_paused.
Are enough nodes healthy?ConsoleIncidents, Quorum capacity, or the Healthy nodes metric on Trust health
Is your MFA fresh?Privileged actions need MFA from the last ten minutes. Sign out and in again.
What does the node say?Run sectigo-edge status and sectigo-edge integrations on the node. See CLI reference.

Sign-up and sign-in​

Symptom / codeCauseFix
registration_email_invalidThe email address is not on the domain you are registering.Use a work address on that domain.
registration_domain_invalidThe domain is not a registrable enterprise DNS domain.Enter your organization's registrable domain, for example example.com.
challenge_failedThe bot-protection challenge failed or expired.Reload the page and submit again.
registration_rate_limitedToo many registration attempts.Wait, then try again.
verification_email_unavailableThe verification email could not be sent.Try again in a few minutes.
email_verification_requiredYou tried domain verification before confirming your email.Open the link in the verification email first.
domain_challenge_not_foundThe DNS TXT record was not found.Publish the exact record name and value shown, wait for DNS to propagate, then select Verify DNS record.
domain_verification_rate_limitedToo many DNS checks.Wait before retrying.
registration_expiredThe registration is older than its validity window.Start a new registration.
Sign-in says Your credentials are valid. Complete email and domain verification, then wait for workspace approval.The workspace is not approved yet (pending_workspace).Finish verification and wait for approval. See Workspace approval.
invalid_credentialsWrong email or password.Retry, or use Forgot password.
login_rate_limited / account_temporarily_lockedToo many failed attempts.Wait, then try again.
account_not_activeThe account has been deactivated.Ask a tenant administrator.
mfa_code_invalidThe authenticator code is wrong.Check that your device clock is correct, then use the current code.
mfa_code_replayedThat code has already been used.Wait for the next code.
mfa_attempts_exceededToo many wrong codes.Sign in again from the start.
password_reset_invalidThe reset link is invalid or expired. Links last 15 minutes.Request a new link.
password_policy_failedThe password must be 12–128 characters.Choose a longer password or passphrase.
password_reuse_rejectedYou used this password recently.Choose a different one.
session_expired / session_revokedThe session ended, or was signed out elsewhere.Sign in again.
tenant_scope_mismatchYour session is not authorized for this tenant.Sign in to the right workspace.
step_up_requiredThe action needs MFA from the last ten minutes.Sign in again, then retry.
phishing_resistant_step_up_requiredThe action needs a recent passkey or phishing-resistant enterprise MFA.Sign in with your passkey or security key.
last_required_passkeyYou tried to revoke your last required passkey.Enrol another passkey first.

See also First login and MFA.

Mesh nodes and enrollment​

Symptom / codeCauseFix
The installer stops before starting the serviceSignature, schema, path, platform, expiry, TLS, trust or permission check failed.Read the installer message. Nothing was changed on the host. Fix the input and rerun.
enrollment_token_replayedThe enrollment package was already used, or has expired. Packages last at most one hour.Create a new package. Never copy or edit an old one.
enrollment_scope_mismatchThe package is for a different node name or platform.Create a package for this exact node and platform.
hardware_node_key_required / node_attestation_requiredThe tenant requires a hardware-protected key (TPM 2.0 or Windows CNG) with attestation.Install on a host with TPM 2.0 (Linux) or the Microsoft Platform Crypto Provider (Windows).
"This host is already enrolled; rerun with --upgrade and no bootstrap package"You ran a fresh install on an enrolled host.Use upgrade mode. See Upgrades.
node_mtls_binding_mismatch / node_mtls_binding_reusedThe node's client certificate does not match its enrollment, or belongs to another node.Use one client identity per node. Restore the original material, or re-enroll.
node_signature_expiredThe node's request time is outside the permitted window.Fix time synchronization (NTP) on the host.
node_disabled / unknown_nodeThe node is disabled, or not enrolled in this tenant.Check ConsoleMesh nodes. Re-enroll if required.
Node shows offlineThe node has stopped reporting.Check the service (systemctl status edgepki-node, or the SectigoEdgeMeshNode Windows service) and outbound HTTPS.
customer_quorum_unavailable / customer_node_unavailableToo few healthy, eligible nodes to approve.Bring nodes back online, or enrol more. Check the eligible approval nodes in the profile.
Node status: degradedThe OTLP exporter or dependency discovery is failing.Check the integrations and dependency_discovery fields in sectigo-edge status.
audit_customer_witness_pending during evidence exportNot enough nodes have witnessed the latest checkpoint.Keep the eligible nodes connected, then retry.

See also Enrollment and Backup & recovery of nodes.

Integrations​

ConsoleIntegrations shows the state and the last error code of each integration. On the node, sectigo-edge integrations shows the local view.

CodeIntegrationCauseFix
pending_node (state)Node adaptersThe node has not acknowledged the current revision.Check the node is online. It polls outbound, so allow time for one poll.
scm_connectivity_not_verifiedSectigo SCMExpected: the cloud SCM integration has no live connectivity test.Confirm SCM by issuing a test certificate. Check the connector's IDs under ConsoleCAs & signing.
scm_connector_not_activeSectigo SCMThe integration needs an active SCM CA connector.Connect and activate the SCM connector first.
adapter_not_installedAnyThe node does not have this adapter enabled locally.Enable the adapter in the node's config.json and restart.
adapter_reference_invalidAnyThe console's adapter reference does not match the node's configured local/... reference.Make the two match exactly.
profile_not_mappedVault, othersThe console profile does not match the node's configured profile ID.Align the profile IDs.
adapter_reference_required / invalid_adapter_referenceAnyThe adapter reference is missing, contains path traversal or looks like a secret.Use a plain local/<name> reference. Secrets stay on the node.
integration_node_required / integration_node_not_enrolledAnyNo target node, or the target is not enrolled.Choose at least one enrolled node.
integration_disabledAnyYou tested a disabled integration.Enable it, then test.
nginx_not_configured, apache_not_configured, java_keystore_not_configured, hashicorp_vault_not_configured, kubernetes_csr_not_configured, spire_not_configured, est_not_configured, adcs_not_configuredThat adapterThe node is assigned the integration but its local configuration is missing.Add the adapter's settings to the node configuration.
nginx_configuration_invalid / apache_configuration_invalidNGINX / ApacheThe expanded server configuration failed validation, or the managed include is not bound.Fix the web server configuration. Check the include path.
nginx_recovery_pending, apache_recovery_pending, java_keystore_recovery_pending, vault_recovery_pendingActivating adaptersA promotion or rollback was interrupted and could not yet be verified.The node retries automatically. Check that the service is up and the health URL answers.
nginx_state_invalid, apache_state_invalid, java_keystore_state_invalid, vault_state_invalid, *_active_pointer_invalid, vault_pointer_invalidActivating adaptersThe node's local generation state or active pointer is not what it expects.Do not edit the managed directory by hand. Check for out-of-band changes, then contact support with the node's status output.
java_keystore_content_invalidJava PKCS#12The keystore content does not match its pinned digest.Check whether something else rewrote the keystore.
vault_unavailableHashiCorp VaultVault is unreachable, or rejected the request. Only this integration is affected.Check the Vault address, token file, TLS trust and network. The node retries every poll.
vault_awaiting_desired_state / vault_bootstrap_failedHashiCorp VaultWaiting for cloud desired state, or the initial import failed.Assign the integration in the console. Check the bootstrap certificate and key files.
<adapter>_integration_unavailableRotation requestThe adapter is not healthy and assigned on this node.Fix the integration until it is healthy.
<adapter>_integration_binding_mismatchRotation requestThe request's adapter reference or profile differs from the active desired state.Use the exact reference and profile from the console.
adcs_integration_not_readyMicrosoft ADCSADCS desired state is not healthy on the initiating node.Check the Windows node's ADCS adapter.

Issuance​

CodeCauseFix
issuance_paused (HTTP 423)The kill switch is active.Resume with two people. See Incident response.
customer_quorum_required / dual_approval_requiredNot enough distinct node approvals, or one trust domain did not approve.Check that the policy's quorum can be met by healthy, eligible nodes.
policy_not_configuredThe tenant has no active policy.Activate a first policy version.
platform_policy_not_configuredThe Sectigo platform baseline is missing or not valid. Issuance stays closed.This is on the Sectigo side. Contact support.
ca_not_configured / ca_not_activeNo active production CA connector.Connect and activate a CA under ConsoleCAs & signing.
remote_signer_not_configured / signer_transport_not_configuredThe protected signing service is not configured for this deployment.Contact support.
remote_signer_failedThe protected signer rejected the operation.Retry once. If the signer could not tell whether the CA acted, it refuses retries of that exact request (idempotency_outcome_uncertain) until the outcome is reconciled. Do not resubmit in a loop. Contact support with the request_id.
workload_profile_denied / workload_san_denied / workload_scope_deniedThe workload's identity token does not allow this profile, DNS name or operation.Fix the workload's token claims, or the profile's allowed identities and DNS names.
workload_mtls_required / workload_token_not_sender_constrainedCloud fallback needs a valid client certificate that is bound to the token.Present the workload's client certificate. Check that the token's cnf thumbprint matches it.
issuance_risk_evidence_missingThe request was created before guardrail evaluation existed.Resubmit the request.
Request denied with a guardrail signalAn enforcing issuance guardrail blocked it.Review the finding under ConsoleIncidents. Adjust the guardrail through a policy change if it is legitimate.
rotation_policy_requiredThe adapter needs an explicit signed dual-slot rotation policy.Add a rotation block to the profile.
automatic_promotion_forbiddenThe workload asked to auto-promote under a manual profile.Promote from ConsoleRotation, or change the profile's promotion setting.
promotion_health_url_forbidden / promotion_health_url_invalidThe health URL host is not in the SANs, or the URL is not plain HTTPS.Use https://<covered-host>/health, with no credentials and no fragment.
standby_not_staged / standby_not_healthyThere is no standby, or it is not healthy.Stage the standby again.
promotion_adapter_requiredConsole promotion needs an activating adapter.Use NGINX, Apache, Java PKCS#12 or Vault, or promote on the node.

Revocation​

Symptom / codeCauseFix
CRL URL returns 503The latest CRL is within five minutes of nextUpdate, or has expired (crl_expired).Select Publish new CRL, then check that the CA connector is healthy.
OCSP returns tryLaterThe certificate is known, but no fresh verified response is published yet.Wait for the retry, or select Refresh under ConsoleRevocation.
OCSP returns malformedRequestThe client sent a nonce, a signature, several CertIDs or extensions.Disable OCSP nonces for this responder.
OCSP returns unauthorizedThe certificate or issuer is unknown to this responder.Check that the client is using the right issuer and responder URL.
Status stays pending after revokingPublication failed and is being retried (1 minute, then every 5 minutes).Normal during short outages. If it persists, check the CA under ConsoleCAs & signing.
Status externalMicrosoft ADCS: the local CA has not produced an accepted artifact yet.Check the assigned Windows node and the Online Responder.
certificate_not_revocableThe certificate is not in the issued state.It may already be revoked. Refresh the list.
crl_context_requiredThe CA has not issued anything yet.Issue one certificate first.

Policies and migrations​

CodeFix
policy_impact_changedThe original proposer selects Refresh estate impact.
policy_impact_blockedResolve the missing, stale, unassigned, ambiguous, unverified or incompatible endpoints.
policy_separation_of_duties / migration_separation_of_dutiesHave a different person approve.
migration_*_changedSomething drifted after planning. Create a new plan.
migration_outside_windowStart inside the maintenance window.
migration_recovery_restage_requiredRe-stage the exact target on the assigned node.

More detail: Policy changes & approvals and Cryptographic migrations.

Break-glass and incidents​

CodeCauseFix
resume_requires_dual_approvalYou tried to unpause through the kill switch.Use Request guarded resume, then have a second person approve.
break_glass_self_approvalThe requester tried to approve.A different person must approve.
break_glass_expiredMore than ten minutes have passed since the request.Create a new request.
break_glass_generation_staleIssuance was paused again after the request.Create a new request for the current pause.
break_glass_already_pendingA request is already waiting.Approve or let that request expire.
break_glass_reason_invalidThe reason must be 16–1,000 characters.Write a fuller reason.
confirmation_requiredThe confirmation text is not exact.Type the phrase exactly, for example PAUSE ISSUANCE.

Trust events and audit​

Code / symptomFix
HTTP 410 / trust_event_cursor_expiredThe cursor is older than the retained window. Resynchronize deliberately, and do not reset the cursor automatically.
trust_event_topic_invalidUse only the published topics. See Monitoring & alerts.
Audit chain could not be verifiedRefresh. If the label persists, export a proof and treat it as a potential incident.
otlp_audit_* in node healthSee Monitoring & alerts.