TechKnowSurge
CompTIA Security+ 1.4 CompTIA SecurityX 2.2 NIST 800-53 SC-17 NIST 800-53 SC-12 ISC2 CISSP 3.6 Cisco CyberOps Associate 2.10 Cisco CCST Cybersecurity 1.4
InteractiveSecurityFree

How a Site Gets and Proves Its Certificate

Type the missing word at each step of getting a certificate and checking one: CSR, registration authority, fingerprint, and whose key does what.

⚑ Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

Public key infrastructure is everything that goes into managing digital certificates: the standards, the processes, the servers and the applications. Its job is to let you trust a site you have never visited before, by having a third party you already trust vouch for it. Getting a certificate. The site owner generates a key pair, a private key and a public key. The public key goes into a certificate signing request, or CSR. The CSR is turned in to a registration authority (RA), often built into the certificate authority, which checks that the requester really owns the domain: not just anybody can claim to be techknowsurge.com. Once the domain is verified, the certificate authority (CA) generates the certificate, with the site's URL, information about the CA and the site's public key. It hashes all of that into a fingerprint, encrypts the fingerprint with the CA's own private key, and puts the encrypted fingerprint on the certificate. The certificate goes back to the owner and is installed on the server. Checking a certificate. When you connect, your computer downloads the certificate. A certificate from the root certificate authority is already on your machine, holding the CA's public key. Your computer decrypts the fingerprint on the site's certificate with that public key, hashes the certificate itself, and compares the two. If they match, the certificate was signed by the CA's private key and has not been changed, so it can be trusted. One rule holds it all together: the site's private key stays private. Anyone who gets it could set up a copy of the site that passes the same check.

What you'll learn

Aligned to

CompTIA Security+
1.4 Explain the importance of using appropriate cryptographic solutions.
CompTIA SecurityX
2.2 Given a scenario, implement appropriate PKI infrastructure solutions.
NIST 800-53
SC-17 Public Key Infrastructure Certificates
SC-12 Cryptographic Key Establishment and Management
ISC2 CISSP
3.6 Select and determine cryptographic solutions
Cisco CyberOps Associate
2.10 Describe the impact of certificates on security
Cisco CCST Cybersecurity
1.4 Explain encryption methods and applications

Key terms

Public Key Infrastructure
PKI
A framework of hardware, software, policies, and standards used to create, manage, and distribute digital certificates.
Certificate Signing Request
CSR
A Certificate Signing Request is a block of encoded text containing an applicant's public key and identity information, submitted to a Certificate Authority to request a signed digital certificate.
Certificate Authority
CA
A trusted entity that issues digital certificates used to verify the identity of individuals, organizations, or devices.
Digital Certificate
An electronic document that uses a digital signature to bind a public key with an identity.
Private Key
A secret cryptographic key used in asymmetric encryption to decrypt data or create digital signatures.
Public Key
A cryptographic key that can be shared openly and is used to encrypt data or verify digital signatures.
Hash Function
A mathematical algorithm that converts input data of any size into a fixed-size output value used to verify data integrity.
Third-Party Trust
A trust model in which a mutually trusted third party, such as a certificate authority, vouches for and extends trust to other entities.

Topics

Public Key Infrastructure Digital Certificates Certificate Authority Interactive Fill In

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →