Posts

Showing posts with the label PKI

Certificate Validation Explained: CRL, OCSP and Stapling for Security+

Certificate validation is what a client does in the moment between receiving a server's certificate and deciding whether to trust it. The Security+ exam tests it as a decision process, and the most reliable way to answer those questions is to know the checks in order. The chain of trust A certificate is trusted because something you already trust vouches for it. That chain has three links. Root CA. A self-signed certificate that sits in your operating system's or browser's trust store. It is trusted by declaration, not by any signature above it. Intermediate CA. Signed by the root, and used to sign end-entity certificates. Roots stay offline for safety, so intermediates do the day-to-day signing. If an intermediate is compromised, only its branch has to be revoked. End-entity certificate. The one presented by the server, signed by an intermediate. Validation walks that chain upward until it reaches a certificate in the local trust store. If the walk cannot reach a ...

Public Key Infrastructure: Certificates, CAs and Revocation

Public key cryptography lets strangers communicate securely, but only if you can answer one question: does this public key really belong to who it claims? PKI is the infrastructure built to answer that question at scale, and nearly every part of it exists to support that single assurance. What a Certificate Is An X.509 certificate binds an identity to a public key, and a certificate authority signs that binding. The fields worth knowing: Subject — who the certificate identifies. Issuer — which CA signed it. Public key — the key being vouched for. Validity period — not-before and not-after dates. Serial number — unique to the issuing CA, and what revocation lists reference. Subject Alternative Name (SAN) — the additional names the certificate covers. Modern browsers validate against SAN, not the common name, so a certificate with the right CN and no matching SAN fails. Key usage and extended key usage — what the key may be use...