Suppose certifier.com creates a certificate for foo.com. Typically, the entire certificate would be encrypted with certifier.com’s public key. True or False? Briefly explain your answer.
Try an answer before revealing the guidance below.
Key Concepts
- Certificate authority
- Private key
- Public key
- Digital signature
- Verification
Answer Approach
- Decide whether a certificate is encrypted or signed.
- Identify which CA key performs signing and which verifies it.
- Explain why encrypting with the CA’s public key would be useless to clients.
Full Answer
Answer status: Verified against study notes. Revision notes, not an official marking scheme.
False. A certificate authority signs certificate information using its private key. A client uses the authority’s public key to verify that signature and thereby check the certificate’s authenticity and integrity. The entire certificate is not normally encrypted with the authority’s public key.
Shortcuts: K concepts · A approach · F answer · R reviewed · B bookmark · ← / → previous / next