About this interactive
Public key infrastructure applies hierarchy trust to certificates: trust starts at the top and is passed down, one certificate to the next.
The root certificate sits at the top and is the anchor of trust that proves everything else. Its public key is already installed on your computer, so the website never has to send it. Because so much depends on it, certificate authorities put safeguards around it, and one of those is creating intermediate certificates beneath it.
An intermediate certificate is issued to an intermediate, or subordinate, certificate authority, which keeps its own private key. It adds a layer of security, and it lets a CA pass some of its trust to another entity, though it can also be the same CA. There can be more than one intermediate level, so a chain can be longer than three certificates.
The end-entity certificate is the one used on the service: techknowsurge.com's own certificate, which the site got by submitting a CSR. The site installs it together with the intermediate certificate, and your computer downloads both when it connects.
Verification runs down the chain. The root certificate's public key decrypts the fingerprint on the intermediate certificate; if it checks out, the intermediate is valid. The intermediate certificate's public key then decrypts the fingerprint on the end-entity certificate. If that checks out too, the site's certificate is verified.
About TechKnowSurge
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →