Open cardosec

Case AB5E99 · Cryptography · L3 Applied

Cert Chain Breaks at Midnight

Practise as: Incident drill

Live alertAt 00:05 mobile clients and a partner API start failing TLS with "unable to get local issuer certificate"; desktop browsers still load the site fine.

  1. 01 What happened?
  2. 02 What is the impact?
  3. 03 What do you do?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Suspect chain issues: expired or missing intermediate, or a cross-signed root expiring on older trust stores.
  2. Inspect with openssl s_client -showcerts and check each cert notAfter and issuer; browsers hide gaps via AIA fetching.
  3. Fix by serving the full correct chain (leaf + intermediates, never the root) on every LB and origin.
  4. Clients with pinned certs or old trust stores may need app updates; communicate to partners.
  5. Prevent: automate renewal (ACME), monitor expiry of every chain element, and alert 30 days out.

If the interviewer pushes back

  • How did the 2021 Let's Encrypt DST Root CA X3 expiry break older clients even though the leaf was valid?

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.