ContentsThe library

How a Message Stays Private

A Certificate Says One Narrow Thing, and Almost Every Belief People Hold About It Is a Guess Bolted On to That One Thing

Last timeWho You Are Talking To

What a certificate actually is, how the chain to a root is checked, and the precise claim it makes. The claim is smaller than the padlock implies and smaller than most designs assume.

What signing means

A signature here is not a picture of a name. It is a value computed from a

document and a private key, with the property that anybody holding the matching

public key can check it and nobody without the private key could have produced

it.

The asymmetry is the whole point. Producing requires a secret. Checking does

not. That is what makes it usable between strangers: a reader who has never

met the signer, and who shares nothing with them, can still verify the

statement.

FIG 1The contents of a server certificate, in plain terms
plaintext
subject name: www.rfc-editor.org
also valid for: rfc-editor.org
public key: a 256 bit curve point, 65 bytes
valid from: 2026-07-14
valid until: 2026-10-12
issued by: a named intermediate authority
key may be used for: server identity, key agreement
log entries: two public append-only logs, with timestamps
signature: a value over everything above, made with
  the private key of the issuing intermediate

the reader checks the signature using the public key of
that intermediate, which arrives in its own certificate
Read the list and notice what is absent: no company registration, no address, no statement about conduct, no indication of what happens to data sent to this server. The document binds a key to a name for a period, and the signature is a statement by the issuer that it checked that binding on the date shown.

Walking up to a root

The server certificate is signed by an intermediate, the intermediate by

another or by a root, and the root is one the reader already has. That last

step is where trust actually enters, and it did not come from the conversation.

FIG 2Validating a chain
Six checks and the connection proceeds only if all pass. Note the last box: possession of the private key is what connects this document to this conversation, and without it anybody could copy a certificate off the wire and present it as their own.
FIG 3One chain, checked step by step
steplevelwhat it sayssigned bychecked howwhat happened
1the serverthis key goes with this namean intermediatewith the intermediate public keyArrives in the handshake along with the key share. Everything about it is public and anybody can read it.
2an intermediatethis intermediate key may issue certifica rootwith the root public keyIntermediates exist so the root private key can stay offline in a vault. If an intermediate is compromised it can be revoked without replacing the root on every machine in the world.
3a rootthis is a trusted issueritselfnot checked, it is simply trustedSelf-signed, which proves nothing. Its authority comes entirely from being in a list on the reader machine, and that list is the real decision.
4the reader storethese hundred or so parties are trustednobodyshipped with the softwareThe reader almost never looks at this list and has usually never heard of most of the parties in it. This is where the trust in the whole system is actually located.
4 steps
Follow the fourth column upwards and the checking stops at the top, because it has to stop somewhere. Every chain ends in something taken on faith, and here it is a list the reader did not compile and has not read.

The narrow claim

Here is the exact statement a valid certificate supports, worth reading twice

because almost every misuse comes from reading more into it.

At the time of issue, the issuer carried out a check and concluded that the

holder of this private key controls this name. That is all.

The lesson stops here

3 more paragraphs to go

You have read the opening. The rest of the argument, the problems that check whether it landed, and the lines worth keeping at the end all come with a plan.

The first lesson of every course in the library reads the whole way through, free, so you can see exactly what the rest of them are.

See the planThe contents

This is the reading half

Starting the course gives you your own copy of it. Every idea on every page has problems standing under it, marked with a reason rather than a tick, and any sentence you do not believe can be opened and argued with. None of that can happen on a page nobody owns.

The contents

The rest of this course

  1. 01Everything Is Encrypted and Somebody on the Wire Can Still Tell Which Page You Opened and Roughly What You Typed
  2. 02Two Strangers Shout Numbers at Each Other Across a Crowded Room and Walk Away Sharing a Secret Nobody Else Heardopening only
  3. 03Hiding the Message Is the Easy Half, and a System That Only Hides It Can Be Taken Apart by an Attacker Who Never Reads a Wordopening only
  4. 04You Have a Perfect Unbreakable Secret Channel to Somebody, and Nothing So Far Has Said a Single Word About Whoopening only
  5. 05A Certificate Says One Narrow Thing, and Almost Every Belief People Hold About It Is a Guess Bolted On to That One Thingyou are here
  6. 06Five Lessons of Separate Machinery Turn Out to Be One Conversation That Takes Two Messages and Is Over Before the Page Is Requestedopening only
  7. 07Somebody Is Recording Your Traffic Today in the Hope of Stealing a Key in 2031, and the Fix Is to Throw the Key Away Before They Get Thereopening only
  8. 08The Handshake Was Correct, the Cipher Is Sound, the Certificate Checked Out, and Your Data Is on Sale by Fridayopening only

Read alongside