Why it matters
Hostname mismatch matters because teams need a precise shared meaning for when a certificate does not cover the hostname being visited. Vague language turns incidents into arguments about words instead of fixes.
When everyone uses the same definition, alerts, status updates, and post-incident reviews stay aligned.
How it works
In practice, when a certificate does not cover the hostname being visited shows up as a concrete signal you can measure or communicate. Operators define what good looks like, watch for deviations, and record what happened when expectations break.
The useful version of hostname mismatch is operational: it changes who gets notified, what customers see, or which metric a team reviews after an incident.
Practical example
Imagine a team operating around certificate for example.com served on api.example.com. When observed behavior stops matching the definition of hostname mismatch, the team treats that change as a reliability event with a clear owner and next step.
Common misconception
Mismatch is the same as expiration
That reading usually collapses distinct ideas into one slogan. Keep hostname mismatch tied to observable behavior so the definition stays useful under pressure.
How Fajita handles this
Match certificate names to every hostname customers use, including www and api hosts.