Open cardosec

Case F2A59C · Cryptography · L3 Applied

TLS Private Key on GitHub

Practise as: Incident drill · Interview

Live alertAt 09:40 secret scanning flags a public commit containing the PEM private key for the wildcard cert *.shop.example.com, pushed 3 days ago.

Interview questionA production TLS private key was committed to a public repo. What do you do?

  1. 01 What happened?
  2. 02 What is the impact?
  3. 03 What do you do?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Treat the key as compromised: generate a new key pair and CSR, reissue the cert and deploy to every endpoint and LB.
  2. Revoke the old cert (keyCompromise) once the new one is live; if anyone reports the key, the CA must revoke in 24h.
  3. Purge from git history (filter-repo), but assume forks and caches exist; history rewrite is not remediation.
  4. Assess impact: was static RSA key exchange enabled? If ECDHE only, past traffic stays safe; watch for impersonation.
  5. Check CT logs and DNS for rogue hosts; add pre-commit secret scanning and store keys in a KMS/HSM.

If the interviewer pushes back

  • The same wildcard cert is on 40 hosts including third-party CDNs. How do you sequence rotation without an outage?

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.