Certificates
In short: A certificate is a digital ID. It links a public key to an identity (website, person, company) and is signed by a trusted body.
In more detail: The word stands for several kinds. The basic idea is always the same: a certificate authority (CA) confirms that the key really belongs to the name.
In Depth
- TLS certificate: for websites and the connection via HTTPS, see certificates in web development.
- Email certificate (S/MIME): for signing and encrypting email.
- Code signing: proves who a program comes from and that it is unchanged.
- Client certificate: login for people or devices without a password.
- Qualification certificates: in everyday life also documents such as school or chamber-of-commerce certificates. Same word for “proof”, but technically something entirely different.
How the check works
The device contains a list of trusted root certificates. A certificate is valid if its chain leads there, it is not expired or revoked, and the name matches. The mathematics behind it is asymmetric encryption.
See also: certificate, TLS