Hi Malzaar,
Based on your description, an expired root, intermediate, or service certificate is a very plausible cause of the 503 errors, especially if your applications rely on HTTPS and mutual TLS authentication between servers. The first step is to verify the certificate chains on the affected servers by reviewing the certificates in the Local Computer certificate store and checking the expiration dates of the server, intermediate, and root CA certificates. You should also review the System, Application, and Schannel event logs, as TLS trust failures are often recorded there and can help pinpoint the exact certificate that is failing validation.
For AD CS-issued certificates, you can force certificate renewal through the Certificate MMC snap-in or by triggering enrollment against Active Directory Certificate Services. If updated root or intermediate CA certificates need to be distributed, Group Policy is usually the preferred approach. After updating the certificate stores, run a Group Policy refresh and verify that the new CA chain is visible on the affected servers before testing application connectivity.
To restore communication without a full reboot, restart the affected application pools, IIS services, or application services that maintain TLS sessions and certificate caches. In many cases, services must be restarted before they begin using newly issued certificates or updated trust chains. I also recommend validating the TLS handshake from both sides of the connection to confirm that the correct certificate chain is being presented and trusted.
As a best practice, implement certificate expiration monitoring and alerts well before certificates reach their expiration dates. This can prevent unexpected service interruptions and give enough time for renewal and deployment.
I hope the response provided some helpful insight. If you find this answer useful, please hit “accept answer” so I know it addressed your concern.
Jason