SECURITY / A CONCEPT NOTE
Public-key Cryptography
the math behind SSH and TLS
Overview · mechanism
pitfall · examples
01 / THE SHORT VERSION
The idea in a few sentences.
A cryptographic model using a public key (shareable) to encrypt data and a private key (secret) to decrypt it. Data encrypted with your public key can only be decrypted by your private key.
02 / FOLLOW THE MECHANISM
How asymmetric key crypto works
Key pair generation
user runs algorithm generating public and private key files.
Encryption
sender uses recipient's public key to encrypt a secret message.
Decryption
recipient uses their secret private key to decrypt the ciphertext back to plaintext.
04 / COMMAND NOTES
Read the command, then the result.
Inspect the flags and arguments before trying an example. Snippets can need local setup, replacement values, or resources in your own environment.
generate a secure public/private key pair
ssh-keygen -t rsa -b 409605 / CHECK YOURSELF
Could you explain Public-key Cryptography to a teammate?
Try it out loud in two sentences: what it is, and the one detail that changes the picture. If you stall, the gap is the part to reread.
Up next in Security & identitySSH Keys & Agentspasswordless, but safe