"Salzburg": The TLS key that still matches
Scenario: "Salzburg": The TLS key that still matches
Level: Medium
Type: Fix
Access: Email
Description: The Salzburg Festival box-office site should be served over HTTPS on port :443. The certificate expired, and nginx will not start.
We still have the public key at /home/admin/festival.pub. A key-archive cleanup left many leftover private keys under /opt/festival/keys. Find the private key that matches that public key and copy it to /home/admin/festival.key. Issue a new certificate for the same host using that same key (do not generate a new key pair) and get the site serving HTTPS again.
There is a short handover note in /home/admin/HANDOVER.txt.
Root (sudo) Access: True
Test: /home/admin/festival.key and /home/admin/festival.pub are a matching key pair.
curl -k https://127.0.0.1/ returns the box-office page.
The certificate presented on :443 is not expired, its subject is the original festival host, and it was issued with the same key as /home/admin/festival.pub.
The "Check My Solution" button runs the script /home/admin/agent/check.sh, which you can see and execute.
Time to Solve: 20 minutes.