A Certificate Says One Narrow Thing, and Almost Every Belief People Hold About It Is a Guess Bolted On to That One Thing
Last timeWho You Are Talking To
What a certificate actually is, how the chain to a root is checked, and the precise claim it makes. The claim is smaller than the padlock implies and smaller than most designs assume.
What signing means
A signature here is not a picture of a name. It is a value computed from a
document and a private key, with the property that anybody holding the matching
public key can check it and nobody without the private key could have produced
it.
The asymmetry is the whole point. Producing requires a secret. Checking does
not. That is what makes it usable between strangers: a reader who has never
met the signer, and who shares nothing with them, can still verify the
statement.
subject name: www.rfc-editor.org
also valid for: rfc-editor.org
public key: a 256 bit curve point, 65 bytes
valid from: 2026-07-14
valid until: 2026-10-12
issued by: a named intermediate authority
key may be used for: server identity, key agreement
log entries: two public append-only logs, with timestamps
signature: a value over everything above, made with
the private key of the issuing intermediate
the reader checks the signature using the public key of
that intermediate, which arrives in its own certificateWalking up to a root
The server certificate is signed by an intermediate, the intermediate by
another or by a root, and the root is one the reader already has. That last
step is where trust actually enters, and it did not come from the conversation.
| step | level | what it says | signed by | checked how | what happened |
|---|---|---|---|---|---|
| 1 | the server | this key goes with this name | an intermediate | with the intermediate public key | Arrives in the handshake along with the key share. Everything about it is public and anybody can read it. |
| 2 | an intermediate | this intermediate key may issue certific | a root | with the root public key | Intermediates exist so the root private key can stay offline in a vault. If an intermediate is compromised it can be revoked without replacing the root on every machine in the world. |
| 3 | a root | this is a trusted issuer | itself | not checked, it is simply trusted | Self-signed, which proves nothing. Its authority comes entirely from being in a list on the reader machine, and that list is the real decision. |
| 4 | the reader store | these hundred or so parties are trusted | nobody | shipped with the software | The reader almost never looks at this list and has usually never heard of most of the parties in it. This is where the trust in the whole system is actually located. |
The narrow claim
Here is the exact statement a valid certificate supports, worth reading twice
because almost every misuse comes from reading more into it.
At the time of issue, the issuer carried out a check and concluded that the
holder of this private key controls this name. That is all.
The lesson stops here
3 more paragraphs to go
You have read the opening. The rest of the argument, the problems that check whether it landed, and the lines worth keeping at the end all come with a plan.
The first lesson of every course in the library reads the whole way through, free, so you can see exactly what the rest of them are.
See the planThe contentsThis is the reading half
Starting the course gives you your own copy of it. Every idea on every page has problems standing under it, marked with a reason rather than a tick, and any sentence you do not believe can be opened and argued with. None of that can happen on a page nobody owns.
The contents