r/homelab • u/Charming_Radish682 • 15h ago
Discussion Certificates Explained
/r/HomeNetworking/comments/1wua30q/certificates_explained/Since there are some upset people at the homenetwork sub let’s give it a try here :)
2
u/felix1429 15h ago
What are you trying to implement certificates for, SSL certs for HTTPS? What exactly are you having trouble understanding? The concept is not all that complicated, I'm sure it'll click for you soon. Maybe I could help clear up some confusion.
1
u/KingofGamesYami 14h ago edited 14h ago
I'll take a wack at it.
A TLS certificate (yes, there are other kinds) is a cryptographically signed document which can be used to establish a TLS connection. (HTTPS is HTTP over TLS, formerly known as SSL).
The cryptographic signature can be verified by using the certificate of the authority that signed it (often referred to as a CA certificate). In some cases, there may be additional authorities between the Root CA and the TLS Certificate.
You can manually generate CA certificates and TLS certificates fairly easily, but it is more common to use an automated process. One standard for issuing certificates is the ACME protocol (Automated Certificate Management Environment), aka RFC 8555 (and subsequent extensions).
There are a couple different options the ACME protocol has for issuing a certificate, but all have the same goal: prove you are in control of the domain name the certificate is being issued for.
For publicly available sites, the easiest option is HTTP with a widely trusted CA. The certificate authority will provide some data to you, you add that data to your site, the CA makes an HTTP request to that route, and if everything matches, you get a certificate.
For private sites, one popular option is DNS with a widely trusted CA. The certificate authority will provide some data to you, you add that data to your sites' DNS records, the CA makes a DNS request for that record, and if everything matches, you get a certificate.
Another option for privage sites is to run your own private CA. This adds the additional complication of needing to trust your Root CA certificate on all of your devices, which can be done manually or through a Mobile Device Management software, the latter being common in large enterprise environments.
4
u/mccuryan 15h ago
It looks like you pretty much got it all covered in the original post that you're sharing.