TechKnowSurge
CompTIA Security+ 1.4 CompTIA SecurityX 2.2 Cisco CyberOps Associate 2.10 CompTIA Tech+ 3.5
InteractiveSecurityFree

Standard, Wildcard or Self-Signed?

Sort each situation or trait to the certificate it fits: a standard certificate for one name, a wildcard, or a self-signed certificate.

⚑ Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

A standard certificate is issued for one name. techknowsurge.com's main site and its courses site are different names, so even on the same server they need two different certificates. The owner submits a CSR for each, proves they own the domain, and gets each certificate from a certificate authority. A wildcard certificate has an asterisk at the start of its name: *.techknowsurge.com. One certificate then covers www.techknowsurge.com, courses.techknowsurge.com and other names in the domain. The catch is the private key. There is one public key in the certificate, so every server using it holds the same private key. If one of those servers is compromised and the key leaks, every service has to get new keys and a new certificate. And if a site is hosted by someone else, you would not hand them that private key; you would get a separate certificate for that site instead. A self-signed certificate is generated on the device itself, with no CSR, no domain check and no certificate authority. It still encrypts the traffic, which is often all an admin wants when connecting to a switch. But it verifies nobody, so browsers show a warning, and the only way through is to accept the risk. That is fine for an admin team who know exactly which device they are connecting to. It is dangerous for end users, because it trains them to click past security warnings, which they will then do on sites that really are fake.

What you'll learn

Aligned to

CompTIA Security+
1.4 Explain the importance of using appropriate cryptographic solutions.
CompTIA SecurityX
2.2 Given a scenario, implement appropriate PKI infrastructure solutions.
Cisco CyberOps Associate
2.10 Describe the impact of certificates on security
CompTIA Tech+
3.5 Given a scenario, configure and use web browsers.

Key terms

Wildcard Certificate
A digital certificate that uses an asterisk in the domain field to secure a domain and all of its subdomains under a single certificate and private key.
Self-Signed Certificate
A digital certificate signed by the entity that created it rather than a trusted certificate authority, providing encryption without third-party identity verification.
Digital Certificate
An electronic document that uses a digital signature to bind a public key with an identity.
Certificate Signing Request
CSR
A Certificate Signing Request is a block of encoded text containing an applicant's public key and identity information, submitted to a Certificate Authority to request a signed digital certificate.
Private Key
A secret cryptographic key used in asymmetric encryption to decrypt data or create digital signatures.
Certificate Authority
CA
A trusted entity that issues digital certificates used to verify the identity of individuals, organizations, or devices.

Topics

Digital Certificates Wildcard Certificates Self Signed Certificates Interactive Categorize

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →