cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
670
Views
0
Helpful
1
Replies

ssl certificate

sarahr202
Level 5
Level 5

hi every body

I have few basics questions about ssl certificate.

Here is my understanding about ssl

ssl serves two purposes:

secure the data in transit by public key encryption.

third party certificates validates the side is real not phising side.

now my question is one can copy the certificate belonging to some side and put it on fake side to gain customer trust and fool him into sending his informations such as social security, etc

so how such certificates provide security against this?

thanks alot!

1 Accepted Solution

Accepted Solutions

Gilles Dufour
Cisco Employee
Cisco Employee

the certificate alone is useless.

You also need the associated private key.

So, if you send encrypted data to sb that has stolen your destination certificate, they won't be able to decrypt the traffic since they don't have the associated private key.

Same if they send you data encrypted with a different private key, you won't be able to decrypt with the certificate.

Gilles.

View solution in original post

1 Reply 1

Gilles Dufour
Cisco Employee
Cisco Employee

the certificate alone is useless.

You also need the associated private key.

So, if you send encrypted data to sb that has stolen your destination certificate, they won't be able to decrypt the traffic since they don't have the associated private key.

Same if they send you data encrypted with a different private key, you won't be able to decrypt with the certificate.

Gilles.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: