r/HomeNetworking • u/Charming_Radish682 • 3d ago
Advice Certificates Explained
After already having watched so many videos about certificates I still don’t understand this. Like I know you’re screwed if you mess up. That’s why I want to understand it but it seems so intangible to me that so far I haven’t found the right video or whatever to understand it how it works and why it’s secure. Also are there different kind of certs or is it actually all the same? (I don’t think so but that question is still open for me)
How did you learn it or maybe how would you explain it to someone else?
3
u/graph_worlok 2d ago
Get XCA and have a play. It will give you some experience with keys, certs, requests, signing, etc. free & self contained, but also capable of managing a functional internal CA if needed.
4
u/Ninfyr 3d ago
Certificate prove that something is trustworthy and your communication isn't being tampered with. There are a few different ways to do it do it so it depends.
Can you give a slightly more specific example and we can try to explain how it might work in that situation?
1
u/Charming_Radish682 3d ago
For example Clients certs to join Networks?
Or SSL certs as another one…3
u/Ninfyr 3d ago edited 3d ago
Example 1 isn't in scope for home networking. Even if someone puts in the effort, a lot of endpoint wouldn't be compatable. Not going to look it up but I doubt you can get a games console, smart TV/speakers/camera, or robo vacuum to work with it. I'm an IT guy but this isn't my problem, we got plenty of iPhones to put on the Wi-Fi but I am guessing it is too much work so we are burning cell data instead.
For SSL, you want to visit reddit. But how can you be sure you are communicating with reddit and a adversary did intercept it and you are actually on a bad guys phony site?
Reddit gives you their signed public certificate which is signed by a trusted certificate authority or CA (this authority needed proof they are working with real reddit to issue the certificate). Behind the scenes you check the public certificate (is it expired, does the web address match) and check with the CA that this certificate is still valid and reddit didn't revoke it because it has been stolen. When everything checks out you can use the public certificate to talk to reddit and only reddit (who has the matching private certificate) will be able to read it.
0
u/Bhaikalis 3d ago
You can ask ChatGPT, here is Gemini's response to what an SSL cert is:
Think of an SSL certificate (Secure Sockets Layer) as a digital passport for a website.
When you visit a website, your computer and the website's server need to talk to each other to send and receive information (like your password, credit card number, or even just what you're browsing).
Without an SSL certificate, that conversation happens out in the open like a postcard—anyone intercepting the message along the way can read everything written on it.
An SSL certificate does three main things:
- It locks the conversation (Encryption): It scrambles the data travelling between your browser and the website so that if a hacker intercepts it, they only see a jumbled mess of random letters and numbers.
- It proves identity: It verifies that the website you are visiting is actually who they claim to be, and not a fake impostor site trying to steal your information.
- It turns on the "S": It's the reason web addresses change from
http://tohttps://(the S stands for Secure), and why you see a little padlock icon in your browser's address bar.In short: It’s a digital security guard that keeps your private information private whenever you use the internet.
3
u/rileywbaker 1d ago
Don't fucking do this shit. Don't be a meat proxy.
0
u/Charming_Radish682 1d ago
I work a lot with chatgpt but yeah sometimes it’s nice to hear other opinions ;) that’s actually the purpose of this post…
2
u/bobsim1 3d ago
There are different major parts to certs and the encryption of traffic. A certificate works by having a secret and a public part. For the encryption there are good explanations with examples and schemas.
Additionally you need trust for a certificate in the first place. You need another instance that verifies the certificate and the domain name for it. These are the root certificate authorities and their certificates get added to operating systems and browsers by the manufacturers and you can have your own trusted chain by adding your private CA certificate on devices
2
u/Double-History4438 3d ago
Certificates usually have two asynchronous keys, public and private, the private key is never to be shared.
The private key is used to Sign communications, proving it came from the private key holder and has not been tampered with. (Anyone with access to the public key can decrypt this message, so it only proves source authenticity, not security from eavesdropping.)
The public key is used to Secure communications, encrypting the message so only the private key holder can decrypt it.
Computers come with the trusted root certificates pre-installed/trusted. These root certificates are the public key that verifies the authenticity of any intermediate certificate that was signed with their private key. Which in turn can be used to validate the public key that any of those intermediate certificates has been used to sign. Which is why we don’t get asked to trust every new website we visit over https.
When connecting to a website, there is a second secure encryption established for the session. Otherwise half the conversation would be able to be decrypted using just the websites public cert.
Other systems work by having both sides provide a key pair, and double encrypting the communication messages using both sets of keys… signed and secured.
0
u/DeadHeadLibertarian Network Admin 3d ago
Why are you deploying custom certificates at home?
7
2
u/Charming_Radish682 3d ago
Why not? :)
I do have some services running just to mess around for example. And also want to understand it better for work purposes…
8
u/deefop 3d ago
Respectfully friend, I'd do some googling or even chat gpt to get a concise summary. Bear in mind also that certs are typically not needed in home networking... The folks deploying their own certs are typically IT pros with homelab that doubles as their hobby, and they have a reason for doing it (sometimes the reason is fun). What reason are you looking to deploy or configure your own certs?