Likely causes
- Expired device certificate
- Wrong CA chain
- Clock skew on the device
- Policy or thing registration mismatch
- OTA rotation job failed
Quick checks
- Check certificate validity dates
- Confirm the device clock
- Validate the CA chain
- Compare device identity and policy in the cloud console
- Test one pilot device before fleet rollout
Step-by-step fix
Identify the affected certificate and device group
Issue the replacement certificate
Test mutual TLS from one pilot device
Deploy rotation through a controlled OTA job
Monitor reconnect and error rates
Revoke the old certificate after the rollout