Certificate errors and how to fix them
Because every identity on Blacksands — human, device, or agent — is certificate-based, certificate errors are one of the more common things you'll troubleshoot. The good news is that the most common cause has a straightforward fix.
The most common cause: expired or revoked certificates
The overwhelming majority of certificate errors trace back to one of two things:
- An expired certificate — certificates are issued with a limited lifetime by design (this is part of what makes certificate-based identity more secure than a long-lived static credential). If a certificate has simply reached its expiration date, the identity it represents will start failing authentication.
- A revoked certificate — if an administrator has revoked the certificate (for example, as part of offboarding a device or an agent — see Granting and revoking access), it will no longer authenticate, even if its original expiration date hasn't passed.
The fix: re-issue a fresh certificate identity
In almost every case, the fix is to re-issue a fresh certificate identity through the console. From the relevant identity's entry in your organization's console (device, user, or agent), you can trigger re-issuance, which generates a new certificate and supersedes the old one. Once re-issued, the identity should authenticate normally on its next connection attempt.
For agent identities specifically, this may mean re-running the installation/authentication flow described in Installing the MCP client so the agent picks up its new certificate rather than continuing to present the expired or revoked one.
Other things to check
If re-issuance doesn't resolve the error, check:
- Clock skew — certificate validity is time-bound, and a device or server with a significantly incorrect system clock can cause a valid certificate to appear expired (or not-yet-valid) to the validating side.
- Wrong organization context — if you belong to more than one Blacksands organization, confirm the certificate was issued under the organization you expect to be authenticating against.
- Intermediate revocation propagation — revocation is designed to propagate in seconds, but if you revoked and immediately re-issued in very quick succession, allow a brief moment for the change to settle before retrying.
Still stuck?
If you've re-issued the certificate and confirmed the clock and organization context are correct but the error persists, see Connection denied — what it means for the broader fail-closed model, or Contact support.
