Case F2A59C · Cryptography · L3 Applied
TLS Private Key on GitHub
Practise as: Incident drill · Interview
Live alertAt 09:40 secret scanning flags a public commit containing the PEM private key for the wildcard cert *.shop.example.com, pushed 3 days ago.
Interview questionA production TLS private key was committed to a public repo. What do you do?
- 01 What happened?
- 02 What is the impact?
- 03 What do you do?
What a strong answer covers
Try it out loud first. Then check yourself:
- Treat the key as compromised: generate a new key pair and CSR, reissue the cert and deploy to every endpoint and LB.
- Revoke the old cert (keyCompromise) once the new one is live; if anyone reports the key, the CA must revoke in 24h.
- Purge from git history (filter-repo), but assume forks and caches exist; history rewrite is not remediation.
- Assess impact: was static RSA key exchange enabled? If ECDHE only, past traffic stays safe; watch for impersonation.
- Check CT logs and DNS for rogue hosts; add pre-commit secret scanning and store keys in a KMS/HSM.
If the interviewer pushes back
- The same wildcard cert is on 40 hosts including third-party CDNs. How do you sequence rotation without an outage?
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.