The system checks basic constraints prior to checking the certificates. Ensure the CA field is True for every root and intermediate certificate in the certificate chain, including older certificates. If the CA field is False for the root certificate in the certificate chain, RESTCONF TLS server state is down.