Case AB5E99 · Cryptography · L3 Applied
Cert Chain Breaks at Midnight
Practise as: Incident drill
Live alertAt 00:05 mobile clients and a partner API start failing TLS with "unable to get local issuer certificate"; desktop browsers still load the site fine.
- 01 What happened?
- 02 What is the impact?
- 03 What do you do?
What a strong answer covers
Try it out loud first. Then check yourself:
- Suspect chain issues: expired or missing intermediate, or a cross-signed root expiring on older trust stores.
- Inspect with openssl s_client -showcerts and check each cert notAfter and issuer; browsers hide gaps via AIA fetching.
- Fix by serving the full correct chain (leaf + intermediates, never the root) on every LB and origin.
- Clients with pinned certs or old trust stores may need app updates; communicate to partners.
- Prevent: automate renewal (ACME), monitor expiry of every chain element, and alert 30 days out.
If the interviewer pushes back
- How did the 2021 Let's Encrypt DST Root CA X3 expiry break older clients even though the leaf was valid?
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.