1
00:00:06,690 --> 00:00:08,130
- In this lesson, we're gonna talk

2
00:00:08,130 --> 00:00:09,840
about digital certificates

3
00:00:09,840 --> 00:00:12,450
because I bet you've been
wondering where do these keys come

4
00:00:12,450 --> 00:00:13,500
from that we've been talking about,

5
00:00:13,500 --> 00:00:15,270
these private and public keys.

6
00:00:15,270 --> 00:00:16,920
Well, they come from our
digital certificates,

7
00:00:16,920 --> 00:00:19,233
and we're gonna look at how and why.

8
00:00:20,220 --> 00:00:22,110
Digital certificates are the mechanism

9
00:00:22,110 --> 00:00:24,420
used to generate a private key

10
00:00:24,420 --> 00:00:27,570
and to bind the public key to its owners.

11
00:00:27,570 --> 00:00:31,140
The digital certificates are
issued by commercial entities,

12
00:00:31,140 --> 00:00:33,930
but alternately, you can
actually self-generate

13
00:00:33,930 --> 00:00:35,310
a digital certificate.

14
00:00:35,310 --> 00:00:38,260
Not a particularly good idea,
and I will be explaining why.

15
00:00:39,150 --> 00:00:42,000
Now, the X.509 standard currently defines

16
00:00:42,000 --> 00:00:45,630
the certificate format and
fields for public keys.

17
00:00:45,630 --> 00:00:47,520
That same standard X.509

18
00:00:47,520 --> 00:00:50,160
also defines distribution procedures,

19
00:00:50,160 --> 00:00:52,050
and we talked about the
fact that public keys

20
00:00:52,050 --> 00:00:53,460
are freely distributed

21
00:00:53,460 --> 00:00:55,650
and the current version of X.509

22
00:00:55,650 --> 00:00:57,813
for our certificates is version three.

23
00:00:59,100 --> 00:01:01,080
Now, there are lots of different types

24
00:01:01,080 --> 00:01:01,913
of digital certificates

25
00:01:01,913 --> 00:01:06,450
'cause digital certificates are
designed to prove ownership,

26
00:01:06,450 --> 00:01:08,700
who somebody is, as well as produce

27
00:01:08,700 --> 00:01:10,380
those public and private keys.

28
00:01:10,380 --> 00:01:13,470
So we have personal, machine,
domain, organization,

29
00:01:13,470 --> 00:01:16,080
extended validation,
code and object signing,

30
00:01:16,080 --> 00:01:17,910
and trusted and intermediate.

31
00:01:17,910 --> 00:01:20,220
Personal verifies the user's identity.

32
00:01:20,220 --> 00:01:22,650
Machine verifies the device identity.

33
00:01:22,650 --> 00:01:25,560
Domain verifies a domain
including wild cards

34
00:01:25,560 --> 00:01:26,970
for sub-domains.

35
00:01:26,970 --> 00:01:30,600
An organization verifies a
domain and an organization.

36
00:01:30,600 --> 00:01:33,210
An extended validation verifies a domain

37
00:01:33,210 --> 00:01:34,650
and an organization subject

38
00:01:34,650 --> 00:01:37,440
to a standardized global
verification process.

39
00:01:37,440 --> 00:01:39,150
We used to know that as the green bar

40
00:01:39,150 --> 00:01:41,310
because the URL bar would turn green.

41
00:01:41,310 --> 00:01:42,720
It doesn't turn green anymore,

42
00:01:42,720 --> 00:01:45,450
but it's now known as extended validation.

43
00:01:45,450 --> 00:01:47,370
Then we have code and object signing,

44
00:01:47,370 --> 00:01:49,110
which verifies origination

45
00:01:49,110 --> 00:01:51,660
and ownership as well
as the object integrity.

46
00:01:51,660 --> 00:01:54,780
And lastly, trusted and
intermediate certificates

47
00:01:54,780 --> 00:01:56,400
which verify our root

48
00:01:56,400 --> 00:01:58,593
and intermediate certificate authorities.

49
00:02:00,060 --> 00:02:01,200
When you get a certificate,

50
00:02:01,200 --> 00:02:03,600
it will have a finite lifecycle, right?

51
00:02:03,600 --> 00:02:06,000
If you create one, well,
it can go on forever,

52
00:02:06,000 --> 00:02:07,770
but again, you really
don't wanna create your own

53
00:02:07,770 --> 00:02:09,780
and use them out in the public domain.

54
00:02:09,780 --> 00:02:13,860
Commercial digital certificates
have a finite life span

55
00:02:13,860 --> 00:02:16,800
from enrollment to expiration.

56
00:02:16,800 --> 00:02:18,810
Effective September 1st in 2020,

57
00:02:18,810 --> 00:02:20,850
the certificates were valid for a year.

58
00:02:20,850 --> 00:02:22,680
Certificates do need to be renewed

59
00:02:22,680 --> 00:02:23,700
at the end of their life

60
00:02:23,700 --> 00:02:26,670
to avoid service disruption
and decreased security.

61
00:02:26,670 --> 00:02:29,220
And there are scenarios
where a certificate

62
00:02:29,220 --> 00:02:31,470
may need to be replaced or retired early.

63
00:02:31,470 --> 00:02:33,540
Perhaps there's a compromise
of the private key

64
00:02:33,540 --> 00:02:35,190
or there's organizational changes

65
00:02:35,190 --> 00:02:37,293
or maybe it's even no longer needed.

66
00:02:40,380 --> 00:02:43,020
In your browser, you can
look at certificates.

67
00:02:43,020 --> 00:02:45,240
You can just take a look, right?

68
00:02:45,240 --> 00:02:46,530
If you're at a secure place,

69
00:02:46,530 --> 00:02:48,750
you'll just see a little
lock up in the URL,

70
00:02:48,750 --> 00:02:50,490
and you can click on that dropdown,

71
00:02:50,490 --> 00:02:52,260
and go into the certificate viewer

72
00:02:52,260 --> 00:02:54,060
and look at the certificate.

73
00:02:54,060 --> 00:02:56,640
Our browsers also have a built-in trust

74
00:02:56,640 --> 00:02:58,020
with certificate authority.

75
00:02:58,020 --> 00:03:00,090
So when they see a certificate,

76
00:03:00,090 --> 00:03:01,620
it's come down to your system,

77
00:03:01,620 --> 00:03:04,530
you know that has been issued
by a trusted authority,

78
00:03:04,530 --> 00:03:08,073
then there is transient trust
or an inheritance of trust.

79
00:03:10,355 --> 00:03:12,720
Now, I did mention that certificates

80
00:03:12,720 --> 00:03:15,960
can be self-generated and self-signed,

81
00:03:15,960 --> 00:03:17,880
so you can make them with
your operating system,

82
00:03:17,880 --> 00:03:19,440
you can make them with a
Linux operating system,

83
00:03:19,440 --> 00:03:22,380
you can make them with a
Windows operating system,

84
00:03:22,380 --> 00:03:23,850
but they're not a good idea.

85
00:03:23,850 --> 00:03:27,090
A self-signed certificate
can easily be impersonated.

86
00:03:27,090 --> 00:03:29,340
If you go to use it out
in the public domain,

87
00:03:29,340 --> 00:03:31,230
it will present a big warning message

88
00:03:31,230 --> 00:03:34,170
like, this certificate
should not be trusted.

89
00:03:34,170 --> 00:03:36,120
You have no way of pulling it back.

90
00:03:36,120 --> 00:03:37,830
It can't be revoked.

91
00:03:37,830 --> 00:03:41,160
So why would you ever create
a self-signed certificate?

92
00:03:41,160 --> 00:03:43,350
Really, the use case is
internal development.

93
00:03:43,350 --> 00:03:45,300
Maybe you're developing a secure app,

94
00:03:45,300 --> 00:03:49,170
or you're doing some testing
for an HTTPS website.

95
00:03:49,170 --> 00:03:52,080
You may create a certificate
just for testing, you know,

96
00:03:52,080 --> 00:03:53,790
and development purposes.

97
00:03:53,790 --> 00:03:56,430
Now, there is a way to get
self-signed certificate

98
00:03:56,430 --> 00:04:00,630
a modicum of trust by using
what's known as a web of trust,

99
00:04:00,630 --> 00:04:03,840
in which case, self-generated
certificates can be signed

100
00:04:03,840 --> 00:04:06,030
and validated by other users.

101
00:04:06,030 --> 00:04:09,000
But generally speaking, we're
gonna use commercial entities

102
00:04:09,000 --> 00:04:11,997
like Network Solutions
and GoDaddy and Thawte

103
00:04:11,997 --> 00:04:13,740
and a host of others, right,

104
00:04:13,740 --> 00:04:16,833
these commercial entities to
generate our certificates.

105
00:04:18,180 --> 00:04:20,100
Now, digital certificates are issued

106
00:04:20,100 --> 00:04:22,260
by those commercial trusted parties,

107
00:04:22,260 --> 00:04:26,610
and we refer to them as
certificate authorities or CAs.

108
00:04:26,610 --> 00:04:28,920
Our browsers and our devices trust

109
00:04:28,920 --> 00:04:30,090
those certificate authorities

110
00:04:30,090 --> 00:04:33,570
by accepting a root certificate
into its root store,

111
00:04:33,570 --> 00:04:35,130
which is really just a database

112
00:04:35,130 --> 00:04:37,260
of approved certificate authorities

113
00:04:37,260 --> 00:04:38,790
that will come pre-installed,

114
00:04:38,790 --> 00:04:40,200
as I mentioned a moment ago,

115
00:04:40,200 --> 00:04:42,660
with your browser or your device.

116
00:04:42,660 --> 00:04:44,670
The certificate authority is who we go ask

117
00:04:44,670 --> 00:04:45,503
for a certificate,

118
00:04:45,503 --> 00:04:48,600
so the certificate authority
receives certificate requests,

119
00:04:48,600 --> 00:04:51,870
validates the application,
issues a certificate,

120
00:04:51,870 --> 00:04:54,810
and then publishes the
ongoing validity status

121
00:04:54,810 --> 00:04:57,060
of the issued certificates.

122
00:04:57,060 --> 00:05:00,000
Now, there is kind of a
subset of a CA known as an RA,

123
00:05:00,000 --> 00:05:01,290
a registration authority,

124
00:05:01,290 --> 00:05:03,450
and they offload some
of the work from the CA

125
00:05:03,450 --> 00:05:04,800
that they can actually accept

126
00:05:04,800 --> 00:05:06,840
and process the registration request

127
00:05:06,840 --> 00:05:08,790
and distribute the certificates

128
00:05:08,790 --> 00:05:11,223
but they can't create the certificates.

129
00:05:12,960 --> 00:05:15,900
So let's look at the
certificate request process.

130
00:05:15,900 --> 00:05:17,850
You go to the commercial entity

131
00:05:17,850 --> 00:05:19,770
and the first thing it's gonna have you do

132
00:05:19,770 --> 00:05:23,133
is actually generate your
public and private key pair.

133
00:05:24,150 --> 00:05:27,540
Then the applicant will submit
a certificate signing request

134
00:05:27,540 --> 00:05:30,450
which is you'll be sending
the public key back

135
00:05:30,450 --> 00:05:31,500
to the certificate authority.

136
00:05:31,500 --> 00:05:32,970
You're going to keep your private key.

137
00:05:32,970 --> 00:05:35,280
It's never going to go to
the certificate authority.

138
00:05:35,280 --> 00:05:37,200
And identifying information.

139
00:05:37,200 --> 00:05:39,180
Now, what that information
will be will depend

140
00:05:39,180 --> 00:05:40,593
on the type of certificate.

141
00:05:41,580 --> 00:05:44,070
Then the CA, or maybe the
registration authority,

142
00:05:44,070 --> 00:05:47,370
will validate the
identity of the applicant.

143
00:05:47,370 --> 00:05:48,990
The CA, the certificate authority,

144
00:05:48,990 --> 00:05:50,790
is gonna generate the certificate

145
00:05:50,790 --> 00:05:52,800
and sign it with their private key.

146
00:05:52,800 --> 00:05:55,110
Their private key says,
I'm the one, right,

147
00:05:55,110 --> 00:05:56,253
who is signing it.

148
00:05:57,330 --> 00:05:59,400
The CA or the RA will send the certificate

149
00:05:59,400 --> 00:06:01,230
back to the applicant, and at that point,

150
00:06:01,230 --> 00:06:03,543
their certificate is ready to be used.

151
00:06:07,320 --> 00:06:09,750
Now, how do we know that
a certificate is valid?

152
00:06:09,750 --> 00:06:11,580
Well, there's really two ways.

153
00:06:11,580 --> 00:06:13,892
One is using what's known as a CRL.

154
00:06:13,892 --> 00:06:16,530
A CRL is a certificate revocation list.

155
00:06:16,530 --> 00:06:18,690
The CA, the commercial authority,

156
00:06:18,690 --> 00:06:21,330
maintains a list of certificates
that have been revoked,

157
00:06:21,330 --> 00:06:23,940
and we have two models, a
pull model and a push model.

158
00:06:23,940 --> 00:06:25,890
In a pull model, a CRL is downloaded

159
00:06:25,890 --> 00:06:27,870
by a user or the organization.

160
00:06:27,870 --> 00:06:30,180
A push model, the CRL
is automatically sent

161
00:06:30,180 --> 00:06:33,540
out by the certificate
authority at regular intervals.

162
00:06:33,540 --> 00:06:35,430
But there's a much more
efficient way to do that,

163
00:06:35,430 --> 00:06:38,730
and that's using a protocol known as OCSP,

164
00:06:38,730 --> 00:06:41,160
online certificate status protocol.

165
00:06:41,160 --> 00:06:43,230
Now that's a process
that's designed to query

166
00:06:43,230 --> 00:06:46,800
the status of a certificate in real time.

167
00:06:46,800 --> 00:06:51,690
And a version of OSCP is
known as OCSP stapling.

168
00:06:51,690 --> 00:06:56,690
OSCP stapling is a time-stamped,
or cached, OCSP response.

169
00:06:57,960 --> 00:06:59,847
And that brings us to
the end of certificates

170
00:06:59,847 --> 00:07:01,830
and the beginning of a
three-second challenge.

171
00:07:01,830 --> 00:07:02,850
Are you ready?

172
00:07:02,850 --> 00:07:05,523
Five challenge questions,
three seconds each.

173
00:07:07,050 --> 00:07:09,450
Mechanism used to generate a private key

174
00:07:09,450 --> 00:07:11,523
and to bind a public key to its owner.

175
00:07:12,630 --> 00:07:14,910
It's what this whole
lesson has been about.

176
00:07:14,910 --> 00:07:16,770
One, two, three.

177
00:07:16,770 --> 00:07:18,810
It's gonna be a digital certificate.

178
00:07:18,810 --> 00:07:22,113
Question two, digital
certificate standard.

179
00:07:24,030 --> 00:07:27,030
One, two, three.

180
00:07:27,030 --> 00:07:28,713
That's X.509.

181
00:07:29,820 --> 00:07:31,590
Question three.

182
00:07:31,590 --> 00:07:34,893
Commercial entity that
issues trusted certificates.

183
00:07:35,730 --> 00:07:37,440
What are they called?

184
00:07:37,440 --> 00:07:39,423
One, two, three.

185
00:07:40,410 --> 00:07:42,423
It's gonna be a certificate authority.

186
00:07:44,190 --> 00:07:46,500
Number four, the type of certificate

187
00:07:46,500 --> 00:07:48,240
that subjects an organization

188
00:07:48,240 --> 00:07:51,330
and the associated domain
to additional vetting.

189
00:07:51,330 --> 00:07:54,180
Remember, I said that it used
to be called the green bar.

190
00:07:54,180 --> 00:07:56,163
One, two, three.

191
00:07:57,180 --> 00:07:59,430
And that's extended validation.

192
00:07:59,430 --> 00:08:01,410
And lastly, number five,

193
00:08:01,410 --> 00:08:03,360
protocol used to query the status

194
00:08:03,360 --> 00:08:05,733
of a certificate in real time.

195
00:08:07,830 --> 00:08:10,080
You're thinking it's
oh, oh, oh, something.

196
00:08:10,080 --> 00:08:12,330
One, two, three.

197
00:08:12,330 --> 00:08:16,023
OCSP, online certificate status protocol.

198
00:08:17,340 --> 00:08:20,220
That brings us to our security-in-action.

199
00:08:20,220 --> 00:08:23,520
Your organization recently
established a relationship

200
00:08:23,520 --> 00:08:24,483
with a new vendor.

201
00:08:25,530 --> 00:08:29,130
When you connect to their site,
the following security alert

202
00:08:29,130 --> 00:08:31,770
for the certificate is presented.

203
00:08:31,770 --> 00:08:34,080
So what does it mean?

204
00:08:34,080 --> 00:08:36,240
So you can see that there's
all kinds of problems, right?

205
00:08:36,240 --> 00:08:38,910
You get a message that says
information you exchange

206
00:08:38,910 --> 00:08:42,750
with the site cannot be
viewed or changed by others.

207
00:08:42,750 --> 00:08:43,590
However, there's a problem

208
00:08:43,590 --> 00:08:45,660
with the site security certificate.

209
00:08:45,660 --> 00:08:47,010
The security certificate was issued

210
00:08:47,010 --> 00:08:49,920
by a company you have not chosen to trust.

211
00:08:49,920 --> 00:08:53,460
The security certificate
date is valid, that's good,

212
00:08:53,460 --> 00:08:56,340
and the security certificate
has a valid name matching

213
00:08:56,340 --> 00:08:58,860
the name of the page
you're trying to open,

214
00:08:58,860 --> 00:09:02,190
but it got that big explanation point.

215
00:09:02,190 --> 00:09:04,230
Security certificate was issued

216
00:09:04,230 --> 00:09:06,813
by a company you have chosen not to trust.

217
00:09:07,800 --> 00:09:10,710
And it goes on to say, view
the certificate to determine

218
00:09:10,710 --> 00:09:14,610
whether you want to trust
the certifying authority.

219
00:09:14,610 --> 00:09:17,310
Hmm, so you get that message.

220
00:09:17,310 --> 00:09:19,863
What do you think it means?

221
00:09:21,630 --> 00:09:23,370
Go ahead and put me on pause,

222
00:09:23,370 --> 00:09:25,110
think about it for a few
minutes, write down some notes,

223
00:09:25,110 --> 00:09:27,563
and then come on back and
we'll talk about the meaning.

224
00:09:30,510 --> 00:09:32,010
Well, the message is warning you

225
00:09:32,010 --> 00:09:34,380
that the certificate has not been issued

226
00:09:34,380 --> 00:09:37,590
by a trusted authority, or at
least not one that you trust.

227
00:09:37,590 --> 00:09:40,020
Now, this is a really big red flag,

228
00:09:40,020 --> 00:09:43,500
and your organization
should absolutely proceed

229
00:09:43,500 --> 00:09:44,910
with caution.

230
00:09:44,910 --> 00:09:46,920
Now, what I would do in this
case is I would get right

231
00:09:46,920 --> 00:09:50,850
on the phone and/or the email
and contact the vendor, right?

232
00:09:50,850 --> 00:09:52,290
That the vendor should be contacted

233
00:09:52,290 --> 00:09:54,810
before you attempt to connect to the site,

234
00:09:54,810 --> 00:09:57,570
and say, Hey, what's going on here?

235
00:09:57,570 --> 00:10:00,150
Then most likely what
happened is the certificate

236
00:10:00,150 --> 00:10:02,643
was self-signed by the issuing party.

237
00:10:03,690 --> 00:10:06,060
The self-signed certificates
are not validated

238
00:10:06,060 --> 00:10:08,460
for authenticity and they're
not gonna be trusted.

239
00:10:08,460 --> 00:10:10,410
And of course, they also can't be revoked

240
00:10:10,410 --> 00:10:11,523
if there's an issue.

241
00:10:12,690 --> 00:10:14,370
Now, if it's self-signed,

242
00:10:14,370 --> 00:10:16,230
either the vendor doesn't understand

243
00:10:16,230 --> 00:10:18,480
the security implications,

244
00:10:18,480 --> 00:10:20,460
so that's a big red flag, right?

245
00:10:20,460 --> 00:10:22,560
You definitely wanna
talk to 'em about that.

246
00:10:22,560 --> 00:10:26,430
Or perhaps, a development
site was published in error,

247
00:10:26,430 --> 00:10:28,890
or maybe you were just sent a
link for the development site

248
00:10:28,890 --> 00:10:31,470
and they actually do have a correct site.

249
00:10:31,470 --> 00:10:32,490
In either case, right,

250
00:10:32,490 --> 00:10:34,500
you wanna be on the phone asking them.

251
00:10:34,500 --> 00:10:36,330
Now there is another option

252
00:10:36,330 --> 00:10:40,110
and the other possibility is
that the site is being spoofed,

253
00:10:40,110 --> 00:10:42,960
that someone has a fake site up there,

254
00:10:42,960 --> 00:10:45,870
did a self-sign certificate,
sent you the link,

255
00:10:45,870 --> 00:10:49,110
and now you're at a spoofed
or an impersonated site.

256
00:10:49,110 --> 00:10:52,620
Again, once again, reason to
be talking to your vendor,

257
00:10:52,620 --> 00:10:56,010
say this is what I have,
is this legitimate?

258
00:10:56,010 --> 00:10:59,820
Being able to look at a certificate
error messages like this

259
00:10:59,820 --> 00:11:02,430
and say, wait a minute,
something's fishy, something's up.

260
00:11:02,430 --> 00:11:03,690
This is what I'm gonna research

261
00:11:03,690 --> 00:11:05,280
and how I'm gonna respond to it,

262
00:11:05,280 --> 00:11:08,613
that, my friends, is
absolutely security in action.

263
00:11:10,800 --> 00:11:12,090
That takes you to the word cloud.

264
00:11:12,090 --> 00:11:13,410
You know what to do.

265
00:11:13,410 --> 00:11:15,390
When you're ready, come
on up to the next lesson,

266
00:11:15,390 --> 00:11:18,140
and we're gonna be talking
about emerging cryptography.
