Certificate Validation Explained: CRL, OCSP and Stapling for Security+
Certificate validation is what a client does in the moment between receiving a server's certificate and deciding whether to trust it. The Security+ exam tests it as a decision process, and the most reliable way to answer those questions is to know the checks in order. The chain of trust A certificate is trusted because something you already trust vouches for it. That chain has three links. Root CA. A self-signed certificate that sits in your operating system's or browser's trust store. It is trusted by declaration, not by any signature above it. Intermediate CA. Signed by the root, and used to sign end-entity certificates. Roots stay offline for safety, so intermediates do the day-to-day signing. If an intermediate is compromised, only its branch has to be revoked. End-entity certificate. The one presented by the server, signed by an intermediate. Validation walks that chain upward until it reaches a certificate in the local trust store. If the walk cannot reach a ...