# 129 — diagnosis *2026-09-30, from the workstation the issue was opened on.* ## Still live, and reproduced exactly The certificate is genuine, the authority is the mesh's, and nothing on the machine trusts it: ``` $ openssl s_client -connect keycloak.novox.internal:443 -servername keycloak.novox.internal subject=CN=keycloak.novox.internal issuer=O=Mesh Internal CA, CN=Mesh Internal CA Intermediate CA Verify return code: 20 (unable to get local issuer certificate) $ curl https://keycloak.novox.internal/ curl: (60) SSL certificate OpenSSL verify result: unable to get local issuer certificate (20) ``` `trust list` holds no entry for the mesh. The anchors present are two `mkcert` development roots and the predecessor's lab root — the report's account of the trust store is unchanged. The public name on the same proxy verifies cleanly (`CN=keycloak.novox.be`, Let's Encrypt, return code 0), which places the fault exactly where the report puts it: not in the proxy, not in the authority, and not in the certificate. **The name matters, and the report's "every HTTPS name the mesh serves internally" is too broad.** The served internal name is `