SECURITY / A CONCEPT NOTE

Certificates & PKI

why browsers trust anyone

~70 sec read

Overview · mechanism
pitfall · examples

01 / THE SHORT VERSION

The idea in a few sentences.

Public Key Infrastructure (PKI) manages certificates. A Certificate Authority (CA) signs your public key, confirming your ownership of a domain so browsers trust your site's HTTPS connection.

02 / FOLLOW THE MECHANISM

How certificate validation flows

  1. CSR Generation

    web server generates a certificate request (CSR) containing its public key.

  2. CA Sign

    trusted Certificate Authority signs the certificate, verifying domain ownership.

  3. Browser check

    user opens site; browser validates certificate signature against its built-in pool of root CAs.

04 / COMMAND NOTES

Read the command, then the result.

Inspect the flags and arguments before trying an example. Snippets can need local setup, replacement values, or resources in your own environment.

EXAMPLE 01 · REFERENCE

inspect certificate fields, domain, and expiration dates

openssl x509 -in cert.pem -text -noout

Explore command anatomy in the CLI lab