Every request through the proxy was refused by the backend, which read as the certificate never arriving and hid behind the authority's refusal — until the second authority issued one and the request behind the handshake still failed.