About this interactive
Public key infrastructure is everything that goes into managing digital certificates: the standards, the processes, the servers and the applications. Its job is to let you trust a site you have never visited before, by having a third party you already trust vouch for it.
Getting a certificate. The site owner generates a key pair, a private key and a public key. The public key goes into a certificate signing request, or CSR. The CSR is turned in to a registration authority (RA), often built into the certificate authority, which checks that the requester really owns the domain: not just anybody can claim to be techknowsurge.com. Once the domain is verified, the certificate authority (CA) generates the certificate, with the site's URL, information about the CA and the site's public key. It hashes all of that into a fingerprint, encrypts the fingerprint with the CA's own private key, and puts the encrypted fingerprint on the certificate. The certificate goes back to the owner and is installed on the server.
Checking a certificate. When you connect, your computer downloads the certificate. A certificate from the root certificate authority is already on your machine, holding the CA's public key. Your computer decrypts the fingerprint on the site's certificate with that public key, hashes the certificate itself, and compares the two. If they match, the certificate was signed by the CA's private key and has not been changed, so it can be trusted.
One rule holds it all together: the site's private key stays private. Anyone who gets it could set up a copy of the site that passes the same check.
About TechKnowSurge
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →