{"id":1554,"date":"2017-10-20T02:55:34","date_gmt":"2017-10-20T10:55:34","guid":{"rendered":"https:\/\/www.cloudinsidr.com\/content\/?p=1554"},"modified":"2017-10-22T03:50:10","modified_gmt":"2017-10-22T11:50:10","slug":"ssl-tls-encryption-ssltls-certificates","status":"publish","type":"post","link":"https:\/\/www.cloudinsidr.com\/content\/ssl-tls-encryption-ssltls-certificates\/","title":{"rendered":"A quick introduction to SSL\/TLS encryption: understanding certificates and key pairs"},"content":{"rendered":"<p>Confused about SSL\/TLS certificates? Here is a quick and dirty introduction to SSL\/TLS encryption.<\/p>\n<p><!--more--><\/p>\n<p>Secure Sockets Layer\/Transport Layer Security (SSL\/TLS) serves two purposes:<\/p>\n<ul>\n<li>securing network communications between two parties<\/li>\n<li>establishing the identity of the party which serves the other party a certificate.<\/li>\n<\/ul>\n<p>SSL\/TLS connections rely on the existence of a key pair.<\/p>\n<h3>SSL\/TLS keys<\/h3>\n<p>An SSL\/TLS key pair consists of a private key and a public key. These two keys are related to one another by means of a cryptographic algorithm. The private key is &#8220;private&#8221; to the server which receives the incoming SSL\/TLS connection and must be kept secret. The server introduces itself to the client by handing over its certificate.\u00a0The certificate is a signed (&#8220;certified&#8221;) container that includes the server&#8217;s public key.<\/p>\n<h3>SSL\/TLS certificates<\/h3>\n<p>In order to ensure the authenticity of the public key that is contained in a certificate, the key must be signed by a trustworthy 3rd party party, a Certificate Authority (CA for short).<\/p>\n<p>SSL\/TLS certificates fall into one of two categories:<\/p>\n<ul>\n<li>PFX (.pfx) certificates and<\/li>\n<li>.cert certificates (.cert, .cer or .crt).<\/li>\n<\/ul>\n<p>A .pfx file is a PKCS#12 archive.\u00a0 A .pfx file typically contains a certificate (possibly with additional CA certificates) alongside the corresponding private key.\u00a0It can also contain additional objects and offers an optional password protection. You would typically extract the certificate and the private key into separate files to use as needed.<\/p>\n<p>A .cert (or .cer or .crt) file usually contains a single certificate, alone and without any wrapping (no private key, just the certificate); it also lacks password protection because there is nothing to protect (the public key does not need protecting).<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Confused about SSL\/TLS certificates? Here is a quick and dirty introduction to SSL\/TLS encryption.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_genesis_hide_title":false,"_genesis_hide_breadcrumbs":false,"_genesis_hide_singular_image":false,"_genesis_hide_footer_widgets":false,"_genesis_custom_body_class":"","_genesis_custom_post_class":"","_genesis_layout":"","footnotes":""},"categories":[33,111,1],"tags":[113,38,37],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v14.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>A quick introduction to SSL\/TLS encryption: understanding certificates and key pairs - CloudInsidr<\/title>\n<meta name=\"robots\" content=\"index, follow\" \/>\n<meta name=\"googlebot\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<meta name=\"bingbot\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.cloudinsidr.com\/content\/ssl-tls-encryption-ssltls-certificates\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"A quick introduction to SSL\/TLS encryption: understanding certificates and key pairs - CloudInsidr\" \/>\n<meta property=\"og:description\" content=\"Confused about SSL\/TLS certificates? Here is a quick and dirty introduction to SSL\/TLS encryption.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.cloudinsidr.com\/content\/ssl-tls-encryption-ssltls-certificates\/\" \/>\n<meta property=\"og:site_name\" content=\"CloudInsidr\" \/>\n<meta property=\"article:published_time\" content=\"2017-10-20T10:55:34+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2017-10-22T11:50:10+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.cloudinsidr.com\/content\/#website\",\"url\":\"https:\/\/www.cloudinsidr.com\/content\/\",\"name\":\"CloudInsidr\",\"description\":\"Cyber security, infotech\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":\"https:\/\/www.cloudinsidr.com\/content\/?s={search_term_string}\",\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.cloudinsidr.com\/content\/ssl-tls-encryption-ssltls-certificates\/#webpage\",\"url\":\"https:\/\/www.cloudinsidr.com\/content\/ssl-tls-encryption-ssltls-certificates\/\",\"name\":\"A quick introduction to SSL\/TLS encryption: understanding certificates and key pairs - CloudInsidr\",\"isPartOf\":{\"@id\":\"https:\/\/www.cloudinsidr.com\/content\/#website\"},\"datePublished\":\"2017-10-20T10:55:34+00:00\",\"dateModified\":\"2017-10-22T11:50:10+00:00\",\"author\":{\"@id\":\"https:\/\/www.cloudinsidr.com\/content\/#\/schema\/person\/dd6ee9cb21cf05763fd7cff3d6f11b2b\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.cloudinsidr.com\/content\/ssl-tls-encryption-ssltls-certificates\/\"]}]},{\"@type\":[\"Person\"],\"@id\":\"https:\/\/www.cloudinsidr.com\/content\/#\/schema\/person\/dd6ee9cb21cf05763fd7cff3d6f11b2b\",\"name\":\"Cloud Insidr\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.cloudinsidr.com\/content\/#personlogo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/8b2fa1415b3d573b97d818b8f8f83b7c?s=96&d=mm&r=g\",\"caption\":\"Cloud Insidr\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","_links":{"self":[{"href":"https:\/\/www.cloudinsidr.com\/content\/wp-json\/wp\/v2\/posts\/1554"}],"collection":[{"href":"https:\/\/www.cloudinsidr.com\/content\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cloudinsidr.com\/content\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cloudinsidr.com\/content\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cloudinsidr.com\/content\/wp-json\/wp\/v2\/comments?post=1554"}],"version-history":[{"count":7,"href":"https:\/\/www.cloudinsidr.com\/content\/wp-json\/wp\/v2\/posts\/1554\/revisions"}],"predecessor-version":[{"id":1595,"href":"https:\/\/www.cloudinsidr.com\/content\/wp-json\/wp\/v2\/posts\/1554\/revisions\/1595"}],"wp:attachment":[{"href":"https:\/\/www.cloudinsidr.com\/content\/wp-json\/wp\/v2\/media?parent=1554"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cloudinsidr.com\/content\/wp-json\/wp\/v2\/categories?post=1554"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cloudinsidr.com\/content\/wp-json\/wp\/v2\/tags?post=1554"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}