TechKnowSurge
CompTIA Security+ 1.4 ISC2 CISSP 3.6 NIST 800-53 SC-13 EC-Council CEH 9.1 ISC2 CC 5.1 CompTIA SecurityX 2.2 NIST 800-53 SC-17
InteractiveSecurityFree

Check the Signature

Susan signs, David checks. Predict what David can conclude when something goes right, or wrong.

⚑ Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

When Susan sends David an important message, a legal document for example, David wants to know two things: that it has not changed (integrity) and that it really came from Susan (authenticity). A digital signature gives him both. Susan hashes the document to make a fingerprint, then signs that hash with her private key. She sends the document and the signature to David, along with her digital certificate, which carries her public key. David runs the document through the same hashing algorithm to get his own fingerprint. He then uses Susan's public key to check her signature against that fingerprint. If it verifies, the document has not changed since she signed it, and it was signed with the private key that matches her public key. The video describes signing as encrypting the hash with the private key, and checking as decrypting it with the public key. That is a common way to picture RSA signatures, but signing is not encryption: nothing is made secret, and algorithms such as ECDSA sign without encrypting anything. The private key signs; the public key verifies. The check is only as good as the public key. If anyone could hand David a key and call it Susan's, a valid signature would prove nothing about Susan. So David relies on public key infrastructure: a certificate authority both sides trust has validated that the certificate, and the public key in it, belong to Susan. A signature does not hide the document. The document travels as it is, readable by anyone who intercepts it.

What you'll learn

Aligned to

CompTIA Security+
1.4 Explain the importance of using appropriate cryptographic solutions.
ISC2 CISSP
3.6 Select and determine cryptographic solutions
NIST 800-53
SC-13 Cryptographic Protection
SC-17 Public Key Infrastructure Certificates
EC-Council CEH
9.1 Cryptography
ISC2 CC
5.1 Understand data security
CompTIA SecurityX
2.2 Given a scenario, implement appropriate PKI infrastructure solutions.

Key terms

Digital Signature
A cryptographic mechanism used to verify the authenticity and integrity of a digital message or document.
Hash Function
A mathematical algorithm that converts input data of any size into a fixed-size output value used to verify data integrity.
Private Key
A secret cryptographic key used in asymmetric encryption to decrypt data or create digital signatures.
Public Key
A cryptographic key that can be shared openly and is used to encrypt data or verify digital signatures.
Digital Certificate
An electronic document that uses a digital signature to bind a public key with an identity.
Certificate Authority
CA
A trusted entity that issues digital certificates used to verify the identity of individuals, organizations, or devices.
Integrity
The assurance that data has not been tampered with and remains accurate and complete.
Authenticity
The assurance that information or a communication originates from the claimed source and has not been fabricated or impersonated. Digital signatures and certificates are common mechanisms for establishing authenticity.
Public Key Infrastructure
PKI
A framework of hardware, software, policies, and standards used to create, manage, and distribute digital certificates.
Confidentiality
The principle that information is accessible only to those authorized to access it.

Topics

Digital Signature Public Key Infrastructure Integrity Interactive Predict

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →