---
title: "Two Customers Blamed for a Setup Error That Was an Expired Certificate"
canonical: https://dxdev.com/blog/2026-09-15_support-diagnosis-wrong-setup-vs-state/
datePublished: 2026-09-15
---
Two customer websites showed a security error in the browser, and the first thing I did was check what the customers had set up.

Some background. Our platform lets a league or club point its own web address at the pages we host for it. For that address to load with the padlock, a certificate has to be issued for it. A certificate is a small digital credential that proves the site is who it says it is, and it expires. A message from our support staff said two of these addresses were failing, and the error pointed at an insecure connection. That looked like a DNS problem, the kind where the customer entered the wrong record. DNS is the address book that tells the internet where a web address lives.

So I went down that road. I had an AI agent pull the records for both domains and compare them to what our instructions tell customers to enter. That work started at 8:48 AM.

It found nothing wrong. Both domains were set up correctly. I kept treating each clean result as a puzzle about what the customer had done, when it was evidence that the customer had done nothing wrong. The session ran two and a half hours and closed with a different answer. The two failures were expired certificates, not setup errors.

The certificates had expired while the domains were still waiting to be pointed at us, and nothing on our side renewed them once the records were finally right. The credential had died in the gap.

## What the detour cost

The direct cost was the morning, spent auditing the work of people who had done it correctly. If I had emailed either customer during that stretch, I would have told them to fix something that was not broken.

The bigger cost was what it hid. Once I asked what state each certificate was actually in, instead of what the customer had configured, the agent checked every custom domain we host. It found 72 more hostnames in the same limbo. 36 of them had an expired certificate and the other 36 were stuck in a separate pending-validation state. None of them was named in the report. Two domains had been reported, and 72 more were on the way.

We reissued all of them: the two from the ticket plus the 72. I closed the ticket and filed a follow-up, because the real gap was that our system had no step that noticed an expired certificate and retried.

## The same mistake on our own screen

That afternoon the same pattern came up in our own tools. The staff page was showing "Awaiting DNS" for domains that were live and serving customers. It was reading a stale label instead of checking what the domain was doing right now. Three hotfixes and a scan deploy later, two customer domains flipped to "Secure" on production.

An automatic check over client-managed domains had also marked about 32 of them as gone when they were only at risk. Same family of error: a label describing what we assumed. I shipped that fix as a hotfix and checked it live on two domains.

Then a sweep of every active domain turned up 30 customers whose sites were still offline after we had retired an old server. Nobody had reported that one either.

## What I ask first now

When something fails for a customer, my first request to the agent is no longer "check their setup". It is "tell me the current condition of the thing, measured right now": is the certificate valid today, when does it expire, does the address resolve, does the page load. Only when that looks healthy do we read the customer's setup.

A setup check can only tell you whether the customer followed the instructions. It cannot tell you whether the thing works. For two and a half hours I asked a question I could answer instead of the question that mattered.

The two certificates from the ticket are reissued. The other 72 are reissued too, but 69 hostnames stay in pending validation until their customers point DNS at us, so I cannot call those valid yet. The 30 offline customers are the next fix, and I am starting that one by asking whether their sites load.
