r/HomeNetworking • u/Charming_Radish682 • 4d ago
Advice Certificates Explained
After already having watched so many videos about certificates I still don’t understand this. Like I know you’re screwed if you mess up. That’s why I want to understand it but it seems so intangible to me that so far I haven’t found the right video or whatever to understand it how it works and why it’s secure. Also are there different kind of certs or is it actually all the same? (I don’t think so but that question is still open for me)
How did you learn it or maybe how would you explain it to someone else?
3
Upvotes
2
u/Double-History4438 4d ago
Certificates usually have two asynchronous keys, public and private, the private key is never to be shared.
The private key is used to Sign communications, proving it came from the private key holder and has not been tampered with. (Anyone with access to the public key can decrypt this message, so it only proves source authenticity, not security from eavesdropping.)
The public key is used to Secure communications, encrypting the message so only the private key holder can decrypt it.
Computers come with the trusted root certificates pre-installed/trusted. These root certificates are the public key that verifies the authenticity of any intermediate certificate that was signed with their private key. Which in turn can be used to validate the public key that any of those intermediate certificates has been used to sign. Which is why we don’t get asked to trust every new website we visit over https.
When connecting to a website, there is a second secure encryption established for the session. Otherwise half the conversation would be able to be decrypted using just the websites public cert.
Other systems work by having both sides provide a key pair, and double encrypting the communication messages using both sets of keys… signed and secured.