What is a digital certificate?
A digital certificate ties a public key to a name, and a trusted authority signs it. What is inside one, who vouches for it, and why it expires.
A digital certificate is a small data file that says “this public key belongs to this name”, signed by an organisation that other people trust. It lets a device confirm that it is dealing with the real owner of a name before it sends anything.
The problem it solves
A public key can be handed to anyone, but nothing in the key says whose it is. An impostor could offer their own key and claim to be your bank. A certificate closes that gap. A certification authority (CA) signs a statement that binds the key to the name, and anyone who trusts the CA can check the signature and rely on it.
A passport works in a similar way. You accept it because of who issued it, it carries an expiry date, and it can be cancelled.
What is inside
- The subject: the name the certificate was issued to, such as the name of a server.
- The subject’s public key.
- The issuer: the CA that signed it.
- The validity period: a start date and an end date.
- A serial number, which identifies the certificate if it ever has to be cancelled.
- The CA’s signature over all of the above.
The certificate is public and is shown to anyone who connects. The private key that matches it is the secret part, and it must stay under the sole control of the certificate’s owner.
Who vouches for the authority
A device trusts a CA because it already holds that CA’s key. Web browsers each keep a list of the CAs they trust, and mail servers keep one too. Often the certificate a server presents was signed by one CA whose own certificate was signed by another, so the device follows the chain until it reaches a CA on its list. If the chain does not end there, a browser shows a warning and will not connect until the user accepts the risk.
To get a certificate from a public CA, the applicant has to show that it controls the name. A business can also run its own internal CA for systems that only its own devices use, provided those devices are set up to trust it.
Why certificates expire and get revoked
Every certificate has a limited life, written into it. After the end date devices stop accepting it, and people see errors until a new one is installed. The Australian Signals Directorate recommends automating renewal so that expiry does not cause an outage.
A certificate can also be revoked before its end date, for example when its private key has been stolen. The CA publishes a signed list of the serial numbers it has revoked, and devices check against it.
What to do
- Keep a list of the certificates your business depends on: the name, the CA that issued it and the end date.
- Turn on automatic renewal where it is offered. Where it is not, put the date in a shared calendar.
- Know who holds the login for the account that issues them.
The free domain and certificate expiry check shows when the certificate on your domain runs out. If you would like renewals looked after for you, see network services.
Sources
- RFC 5280: Internet X.509 public key infrastructure certificate and certificate revocation list (CRL) profile (IETF) rfc-editor.org
- Glossary: public key certificate (NIST Computer Security Resource Center) csrc.nist.gov
- Implementing certificates, TLS, HTTPS and opportunistic TLS (Australian Signals Directorate) cyber.gov.au
- Using TLS to protect data (UK National Cyber Security Centre) ncsc.gov.uk