A TLS certificate is a small file that proves a website or server really is who it says it is, and lets your connection to it be encrypted so others cannot read the traffic. TLS is the technology behind the padlock in your browser.
These posts cover working with TLS certificates day to day: how the trust chain fits together, running your own certificate authority, using ACME and Let’s Encrypt to get certificates for free, renewing them automatically, and fixing common certificate errors.
Webex 46.8.0.35631 on Fedora 44 sits behind a yellow banner reading “Offline - No internet connection” while every other program on the machine reaches the internet without complaint. It stopped the VoIP line dead. The network was never the problem: Cisco bundle their own fork of OpenSSL and built it with OPENSSLDIR set to /workspace/.conan2/p/b/cisco8ee8b59cf93de/p/ssl, a directory that exists on a build container and nowhere else, so it loads no trust anchors and every handshake fails. The post runs in order: what the broken state actually is, asking the shipped library where it thinks its certificates live, reproducing the exact error code outside Webex, why nothing warns you, the two fixes that do not work and why, and the one that does. Then the build process: they used $ORIGIN for the code and left three data paths absolute, the RPM header names a container ID so the container was already in the pipeline and never used to run the result, the package requires a glibc from 2018 because they will not link statically, 2.2 GB is shipped twice, and it carries no documentation and no file marked as configuration. Then how it should have been built, the six fixes and the one-line check that catches it. And finally the cross-check: Cisco hold 98 entries in CISA’s known-exploited catalogue, second only to Microsoft, and a trust path nobody checked and a bypass nobody checked are the same failure at different stakes.