Scenario: "Campina Grande": Give me my cert, Vault
Level: Medium
Type: Fix
Tags: hashicorp vault realistic-interviews
Description: A web application running at https://nginx.example.com has an expired certificate. Issue a new certificate using the Hashicorp Vault running on the server.
The Vault instance is already unsealed and initialized, and you have full admin access with the admin user.
Root (sudo) Access: True
Test: Running curl https://nginx.example.com returns Hello!.
The certificate presented by Nginx is issued by the Vault PKI (check using openssl verify -CAfile /usr/local/share/ca-certificates/vault-pki-ca.crt /etc/nginx/ssl/cert.pem).
The "Check My Solution" button runs the script /home/admin/agent/check.sh, which you can see and execute.
Time to Solve: 15 minutes.