# Tls: failed to verify certificate: x

**URL:** <https://linkerd.buoyant.io/t/tls-failed-to-verify-certificate-x/446>\
**Category:** Linkerd General Discussion\
**Tags:** certificates\
**Created:** [April 18, 2024, 12:40pm UTC](https://linkerd.buoyant.io/t/tls-failed-to-verify-certificate-x/446 "2024-04-18T12:40:25Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![mclanem](https://yyz1.discourse-cdn.com/flex029/user_avatar/linkerd.buoyant.io/mclanem/32/161_2.png) [@mclanem](https://linkerd.buoyant.io/u/mclanem)\
**Post date:** [April 18, 2024, 12:40pm UTC](https://linkerd.buoyant.io/t/tls-failed-to-verify-certificate-x/446/1 "2024-04-18T12:40:25Z")

</div>

I just got LinkerD installed on our Dev cluster. It looks like everything is setup and working. I was able to add a few things to the mesh. I don’t see any errors in the linkerd-proxy container. But when I look at the pod in the linkerd dashboard I see the following error in the bottom left corner. It’s not a single steady error but instead it flashes by repeatedly. Any ideas on what this might be?

 ![image](https://canada1.discourse-cdn.com/flex029/uploads/buoyant1/original/1X/fd3027d31f8c4c8cc984f21261146913167900e2.png)

---

<div class="post-metadata">

**Author:** ![mclanem](https://yyz1.discourse-cdn.com/flex029/user_avatar/linkerd.buoyant.io/mclanem/32/161_2.png) [@mclanem](https://linkerd.buoyant.io/u/mclanem)\
**Post date:** [April 18, 2024, 12:45pm UTC](https://linkerd.buoyant.io/t/tls-failed-to-verify-certificate-x/446/2 "2024-04-18T12:45:32Z")

</div>

I am guessing it has something to do with the live calls. I don’t see any data in that section.

---

<div class="post-metadata">

**Author:** ![mclanem](https://yyz1.discourse-cdn.com/flex029/user_avatar/linkerd.buoyant.io/mclanem/32/161_2.png) [@mclanem](https://linkerd.buoyant.io/u/mclanem)\
**Post date:** [April 18, 2024, 12:51pm UTC](https://linkerd.buoyant.io/t/tls-failed-to-verify-certificate-x/446/3 "2024-04-18T12:51:36Z")

</div>

Ah… I found something.  
× tap API server has valid cert  
cert is not issued by the trust anchor: x509: certificate is valid for tap.linkerd-viz.svc, not tap.linkerd.svc  
see [Linkerd Check Redirection](https://linkerd.io/2/checks/#l5d-tap-cert-valid) for hints

So when I installed linkerd-viz I put it in the same namespace as linkerd (linkerd instead of linkerd-viz). I just didn’t want to have everything separated out. So the certificate is there as is the service account but not in the linkerd-viz namespace. How can I adjust that in the helm chart so that the cert becomes valid?

---

<div class="post-metadata">

**Author:** ![mclanem](https://yyz1.discourse-cdn.com/flex029/user_avatar/linkerd.buoyant.io/mclanem/32/161_2.png) [@mclanem](https://linkerd.buoyant.io/u/mclanem)\
**Post date:** [April 18, 2024, 2:32pm UTC](https://linkerd.buoyant.io/t/tls-failed-to-verify-certificate-x/446/4 "2024-04-18T14:32:07Z")

</div>

I sorted it out.

I had to update the tap and linkerd-tap-injector certificates because I hadn’t change the commonName or dnsNames when I changed the namespace.
