SECURITY / A CONCEPT NOTE
Certificates & PKI
why browsers trust anyone
Overview · mechanism
pitfall · examples
01 / THE SHORT VERSION
The idea in a few sentences.
Public Key Infrastructure (PKI) manages certificates. A Certificate Authority (CA) signs your public key, confirming your ownership of a domain so browsers trust your site's HTTPS connection.
02 / FOLLOW THE MECHANISM
How certificate validation flows
CSR Generation
web server generates a certificate request (CSR) containing its public key.
CA Sign
trusted Certificate Authority signs the certificate, verifying domain ownership.
Browser check
user opens site; browser validates certificate signature against its built-in pool of root CAs.
04 / COMMAND NOTES
Read the command, then the result.
Inspect the flags and arguments before trying an example. Snippets can need local setup, replacement values, or resources in your own environment.
inspect certificate fields, domain, and expiration dates
openssl x509 -in cert.pem -text -noout05 / CHECK YOURSELF
Could you explain Certificates & PKI to a teammate?
Try it out loud in two sentences: what it is, and the one detail that changes the picture. If you stall, the gap is the part to reread.
Up next in Security & identityLeast Privilegethe default should be 'no'