NOTE

1.6 Digital Signature

Digital signatures, certificates, and CA trust chains.

SecurityCreated Updated 1 min readhistorical

This is a historical learning note and may contain outdated or incomplete understanding.

1. Digital Signature

1.1. What Is a Digital Signature

1.2. Digital Signature Properties

Integrity + authentication + non-repudiation.

1.3. Digital Signature Process

2. Digital Certificate

2.1. What Is a Digital Certificate

  • A certificate issued by a CA to a server.
    • A CA is like a public-security authority, and a certificate is like an identity card.

2.2. Why Digital Certificates Are Needed

  • Solve the problem of public-key transmission in asymmetric encryption and prevent man-in-the-middle attacks.

2.3. How Digital Certificates Work

  1. The server sends its public key to the CA.
  2. The CA uses its own private key to generate a certificate for the server’s public key.
  3. The CA issues the certificate to the server.
  4. The client requests the server.
  5. The server returns the certificate.
  6. The client verifies with the CA whether the certificate is valid.

3. CA Trust Chain

3.1. What Is a CA Trust Chain

  • CA0 issues a certificate to CA1, CA1 issues a certificate to CA2, CA2 issues a certificate to CA3, and so on, forming a trust chain.
  • CA0 is the root certificate and is preinstalled in the operating system.

3.2. Why a CA Trust Chain Is Needed

  • To prevent the CA from being forged.

Discussion

Sign in with GitHub to comment. Discussions are stored as GitHub Issues.View on GitHub