A digital certificate proves that a public key belongs to a specific entity. It contains the public key, the identity of the owner, the validity period, and the digital signature of a certificate authority. When your browser connects to a website, the server presents its certificate. The browser checks the signature against its list of trusted CAs. If the signature is valid and the domain matches, the connection proceeds. If not, the browser warns you.
Certificates use the X.509 standard. They are used for HTTPS, email encryption, code signing, and client authentication. The certificate itself is not secret. It is public by design. The security comes from the CA's signature, which is hard to forge. Certificates expire. Short lifetimes limit the damage if a private key is compromised. Let's Encrypt issues free certificates valid for 90 days and automates renewal. That automation pushed HTTPS adoption from about half of web traffic to over 90 percent. The system works when it is easy. When it is not, people skip it.
Certificate contents
- Public key — the key being certified
- Subject — the identity of the owner
- Issuer — the certificate authority
- Validity period — start and expiration dates
- Signature — the CA's cryptographic endorsement
A certificate is a passport for a public key. It says who the key belongs to and who vouches for that claim.
Comments
No comments yet. Be the first to share a thought.
Leave a comment