Establishing trust.
WHAT A CERTIFICATE CONTAINS
A public key The names it is valid for Validity dates The issuer A signature from that issuer
WHAT A CERTIFICATE AUTHORITY IS
An organisation trusted by browsers and systems to issue certificates.
WHAT THE CHAIN OF TRUST IS
Your certificate signed by an intermediate, signed by a root held in the trust store.
WHAT MUST BE SERVED
Your certificate and every intermediate.
WHAT HAPPENS IF INTERMEDIATES ARE OMITTED
Some clients fail, and others succeed, which makes it confusing to diagnose.
WHAT THE VALIDATION LEVELS ARE
- Domain validated: control of the name proven
- Organisation validated: the organisation verified
- Extended validation: stricter verification
WHAT BROWSERS NOW DISPLAY
Effectively the same for all of them.
WHAT THAT MEANS COMMERCIALLY
The higher levels provide little practical benefit for most sites.
WHAT WILDCARD CERTIFICATES COVER
One level of subdomain.
WHAT THEY RISK
One key protecting many services.
WHAT TO PREFER WHERE PRACTICAL
Separate certificates per service.
WHAT TO MONITOR
Expiry, independently of the issuing system.