|
certificate formats
|
Please note, that the Knowledge Base isn't translated to english completely at the moment. You will still find some german texts - we are translating permanently the outstanding parts! Thank you for understanding! |
Certificates |
| |
|
|
|
For verification of a digital signature you need the corresponding public key, thus these keys has to be distributed or accessable in a directory. A Public-Key-Certificate is a credential, which links the public key to the identity of its owner.
The data structure of a digital certificate contains a public key signed by a hopefully trustworthy third party (certification authority). The third party is issuer of the credential, verification can only be done with teh public key of the third party (ca-certificate) Without these mechanisms there could be a "man in the middle" attack.
|
 |
 |
 |
Certificate |
|
|
Of course there are more data included and signed in a certificate, like the name, validity period, version and serial number, identity information about the issuing third party, and more information about allowed purpose of use, revocation information, etc. At least a certificate consists of a name, a public key and a digital signature over these information.
|
|
|