You are a security administrator managing your organization's Public Key Infrastructure (PKI). Several certificate-related issues have been reported across the network: 1. Web server SSL/TLS certificates showing browser warnings 2. VPN authentication failures 3. Email encryption problems 4. Code signing verification errors Your task is to: - Review each digital certificate - Identify the security issue or misconfiguration - Select the appropriate remediation action - Understand PKI best practices and certificate lifecycle management Organization Details: - Internal CA: dc01.company.local - External web services: *.company.com - Valid certificate authorities: DigiCert, Let's Encrypt, Internal CA - Certificate validity period policy: Maximum 13 months for web certificates
Instructions: Examine each certificate carefully. Identify the problem and select the correct remediation action based on PKI best practices and security standards.
www.company.com
Self-Signed
Public-facing web server
2022-01-01
2027-01-01
vpn.company.com
CN=DigiCert SHA2 Secure Server CA
VPN gateway
2023-01-15
2024-01-14
John Smith
CN=company.local-CA
S/MIME email encryption
2023-06-01
2025-06-01
company-codesign
CN=DigiCert Code Signing CA
Software code signing
2021-03-10
2024-03-10
*.company.com
CN=Let's Encrypt Authority X3
Wildcard certificate for multiple subdomains
2024-01-01
2025-07-01