Common Reasons for Revocation
- Device fingerprint drift or mismatch
- Tunnel inactivity beyond entropy threshold (30–45 days)
- Jurisdiction breach flagged by routing audit
- Manual deactivation from Tier 3 oversight
Reissue Eligibility
- Active sponsor slot or referral glyph logic must be present
- Device must align with device match threshold
- Region must be cleared for routing — Green or Yellow Zone only
Reissue Procedure
If your configuration is no longer viable:
- Navigate to
/client/config-reissue.html - Submit device and location verification details
- Wait for Tier 3 sponsor validation and issuance window
Post-Reissue Behaviour
- New `.conf` file and QR code are generated
- Old tunnel endpoints are retired with an entry in your audit trail
- Slot trust logic is updated to reflect the issuance pathway
Best Practices for Config Longevity
- Use tunnels at least once every 30 days to preserve handshake freshness
- Avoid reusing slots across multiple jurisdictions unless sponsor-approved
- Keep fingerprint consistent unless revalidated via glyph update
- Monitor `/status` endpoint to confirm tunnel health and expiry risk
“Each config reissue is a renewal of encrypted promise - not just access, but alignment.”