DevOps Professional · Module 5: Hybrid networks and hard integrations · Lab
Separate the Fault in a Proxy and Certificate Chain
50 min hands-on · Advanced
A local fixture chain (client, proxy, backend) with test certificates from a lab-only CA (short expiry, lab-only names, never trusted outside the lab).
Local guide: run the steps below on your own machine in order, then check the validation list.
Objectives
- Run per-link checks in order from the client inward
- Quote the failing link's evidence and fix exactly it
- Re-verify outward hop by hop
Step 1
Stage the stale chain
Serve a stale intermediate at the proxy while the backend stays healthy. Confirm DNS resolves and the backend answers directly, quoting both.
Step 2
Isolate link by link
Pull the served chain at the proxy and quote the stale element. Name the owning link from evidence before touching anything; no reissuing before isolating.
Step 3
Fix and re-verify outward
Replace the chain at the right link, then re-verify outward hop by hop to the client. Record the four checks with the single fix.
How to confirm it worked
- DNS and direct-backend checks quoted healthy
- Failing link quoted from served-chain evidence
- Single fix at the right link with outward re-verification
- Lab-only CA labeling present