PKI Certificate Management & Troubleshooting

PBQ 6: PKI & Certificate Troubleshooting

Scenario
PKI Infrastructure Management

You are a security administrator managing your organization's Public Key Infrastructure (PKI). Several certificate-related issues have been reported across the network: 1. Web server SSL/TLS certificates showing browser warnings 2. VPN authentication failures 3. Email encryption problems 4. Code signing verification errors Your task is to: - Review each digital certificate - Identify the security issue or misconfiguration - Select the appropriate remediation action - Understand PKI best practices and certificate lifecycle management Organization Details: - Internal CA: dc01.company.local - External web services: *.company.com - Valid certificate authorities: DigiCert, Let's Encrypt, Internal CA - Certificate validity period policy: Maximum 13 months for web certificates

Instructions: Examine each certificate carefully. Identify the problem and select the correct remediation action based on PKI best practices and security standards.

Issue 1
www.company.com
Browsers show "Not Secure" warning - Untrusted certificate authority
Self-Signed

www.company.com

Self-Signed

Public-facing web server

2022-01-01

2027-01-01

Digital Signature
Key Encipherment
Server Authentication
www.company.com
company.com
Issue 2
vpn.company.com
VPN clients cannot connect - Certificate validation failure
Expired

vpn.company.com

CN=DigiCert SHA2 Secure Server CA

VPN gateway

2023-01-15

2024-01-14

Digital Signature
Key Encipherment
Server Authentication
Client Authentication
vpn.company.com
Issue 3
John Smith
Email encryption fails - Certificate not trusted
Revoked

John Smith

CN=company.local-CA

S/MIME email encryption

2023-06-01

2025-06-01

Digital Signature
Key Encipherment
Data Encipherment
Email Protection
Client Authentication
Issue 4
company-codesign
Code signing warnings appear during software installation
Valid

company-codesign

CN=DigiCert Code Signing CA

Software code signing

2021-03-10

2024-03-10

Digital Signature
Code Signing
Issue 5
*.company.com
Certificate violates policy - exceeds maximum validity period
Valid

*.company.com

CN=Let's Encrypt Authority X3

Wildcard certificate for multiple subdomains

2024-01-01

2025-07-01

Digital Signature
Key Encipherment
Server Authentication
*.company.com
company.com
www.company.com