1
00:00:06,360 --> 00:00:07,410
- [Instructor] In this segment,

2
00:00:07,410 --> 00:00:10,950
we're gonna take a closer
look at digital certificates.

3
00:00:10,950 --> 00:00:12,030
Now first we're going to look

4
00:00:12,030 --> 00:00:16,140
at certificates that are
stored locally on our machines,

5
00:00:16,140 --> 00:00:18,420
specifically certificates related to

6
00:00:18,420 --> 00:00:20,943
trusted certification authorities.

7
00:00:22,797 --> 00:00:24,330
And then we'll look at a
certificate in a browser.

8
00:00:24,330 --> 00:00:26,250
We're gonna use Cert Manager

9
00:00:26,250 --> 00:00:28,470
on my local Windows machine

10
00:00:28,470 --> 00:00:31,590
to look at the certificates
that are stored locally.

11
00:00:31,590 --> 00:00:32,850
Now, on the left-hand side,

12
00:00:32,850 --> 00:00:35,370
you can see folders with
various certificates,

13
00:00:35,370 --> 00:00:38,340
Personal, Trusted Route
Certification Authorities,

14
00:00:38,340 --> 00:00:40,530
Enterprise Trust, all the way down

15
00:00:40,530 --> 00:00:43,050
to Smart Card Trusted Routes.

16
00:00:43,050 --> 00:00:45,000
These are going to be certificates

17
00:00:45,000 --> 00:00:47,733
that came pre-installed with my browser.

18
00:00:49,050 --> 00:00:52,320
Now let's look at Trusted Route
Certification Authorities.

19
00:00:52,320 --> 00:00:55,650
So I'm gonna open that up
and go to certificates.

20
00:00:55,650 --> 00:00:59,430
And there we can see a
whole set of certificates.

21
00:00:59,430 --> 00:01:01,560
Now this is really
interesting to look through

22
00:01:01,560 --> 00:01:04,650
because they all have
different intended purposes.

23
00:01:04,650 --> 00:01:06,360
As I scroll through I can see some

24
00:01:06,360 --> 00:01:08,100
are for client authentication,

25
00:01:08,100 --> 00:01:09,540
some are from Timestamping,

26
00:01:09,540 --> 00:01:11,910
some are for code signing.

27
00:01:11,910 --> 00:01:14,070
Some can do everything.

28
00:01:14,070 --> 00:01:15,900
And we can see who it was issued to,

29
00:01:15,900 --> 00:01:17,400
who it was issued by,

30
00:01:17,400 --> 00:01:20,490
their expiration date and
that intended purpose,

31
00:01:20,490 --> 00:01:21,720
and the friendly name.

32
00:01:21,720 --> 00:01:25,230
And we can actually take a
look at the certificates.

33
00:01:25,230 --> 00:01:27,000
I'm gonna look at a DigiCert

34
00:01:27,000 --> 00:01:29,913
Assured Root ID certificate authority.

35
00:01:30,900 --> 00:01:33,090
And this will tell me the certificate

36
00:01:33,090 --> 00:01:35,280
is intended for the following purposes,

37
00:01:35,280 --> 00:01:37,260
to prove your identity
to a remote computer.

38
00:01:37,260 --> 00:01:39,750
To ensure software came
from a software publisher,

39
00:01:39,750 --> 00:01:42,450
to protect software from
alteration after publication,

40
00:01:42,450 --> 00:01:44,310
to protect email messages,

41
00:01:44,310 --> 00:01:46,950
to ensure the identity
of a remote computer,

42
00:01:46,950 --> 00:01:49,710
and allows data to be signed
with the current time.

43
00:01:49,710 --> 00:01:53,460
So these are all the possible
uses for the certificate.

44
00:01:53,460 --> 00:01:55,830
I can see who it was
issued to and issued by.

45
00:01:55,830 --> 00:01:58,400
I can see the validity dates.

46
00:01:58,400 --> 00:01:59,520
And then if I go into details,

47
00:01:59,520 --> 00:02:03,120
I can see that we are
an X.509 version three.

48
00:02:03,120 --> 00:02:06,330
The serial number, I can
see the signature algorithm.

49
00:02:06,330 --> 00:02:08,400
So sha1RSA.

50
00:02:08,400 --> 00:02:11,911
The signature hash algorithm, sha1.

51
00:02:11,911 --> 00:02:13,350
If I scroll down,

52
00:02:13,350 --> 00:02:14,520
I can see the public key.

53
00:02:14,520 --> 00:02:18,060
The public key is an RSA key, a 2048 bit.

54
00:02:18,060 --> 00:02:20,010
And what you're seeing
down in the lower part

55
00:02:20,010 --> 00:02:23,013
is actually a representation of the key.

56
00:02:24,030 --> 00:02:26,130
I can get information about key usage.

57
00:02:26,130 --> 00:02:28,350
Again, we're using it
for digital certificate,

58
00:02:28,350 --> 00:02:32,793
certificate signing, offline
CRL signing, and CRL signing.

59
00:02:34,320 --> 00:02:35,530
I can see a hash

60
00:02:37,432 --> 00:02:39,210
and that it's an extended validation.

61
00:02:39,210 --> 00:02:40,230
So I can go right here

62
00:02:40,230 --> 00:02:42,963
and see all of the properties
of the certificate.

63
00:02:45,870 --> 00:02:47,070
Now I'm just gonna sort

64
00:02:47,070 --> 00:02:49,770
by expiration date because
remember we said that

65
00:02:49,770 --> 00:02:51,750
certificates have an expiration date

66
00:02:51,750 --> 00:02:54,810
or they could be revoked
and no longer useful.

67
00:02:54,810 --> 00:02:57,030
So we could see that in
their expiration date.

68
00:02:57,030 --> 00:02:59,310
And I'm just gonna go
choose any one of them.

69
00:02:59,310 --> 00:03:02,550
And you can see that says
the certificate has expired

70
00:03:02,550 --> 00:03:03,870
or is not yet valid.

71
00:03:03,870 --> 00:03:05,220
So letting me know, right?

72
00:03:05,220 --> 00:03:07,530
In this case, we're past 2020,

73
00:03:07,530 --> 00:03:09,903
the certificate is not valid anymore.

74
00:03:12,390 --> 00:03:13,350
Again, another one,

75
00:03:13,350 --> 00:03:16,503
the certificate's
expired or not yet valid.

76
00:03:19,380 --> 00:03:21,510
So if you wanna look at what certificates

77
00:03:21,510 --> 00:03:23,113
are on your system, you can go right

78
00:03:23,113 --> 00:03:25,920
to your cert manager in
the Windows environment

79
00:03:25,920 --> 00:03:28,533
and take a look at those certificates.

80
00:03:30,210 --> 00:03:35,210
Now let's look at certificates
being used on the browser.

81
00:03:35,310 --> 00:03:37,800
So here I am at Amazon site,

82
00:03:37,800 --> 00:03:39,990
and I'd like to see their certificate.

83
00:03:39,990 --> 00:03:41,580
So what am I gonna do?

84
00:03:41,580 --> 00:03:44,673
I'm gonna come up to the
padlock in the URL bar.

85
00:03:46,740 --> 00:03:48,120
And I have a couple of options here.

86
00:03:48,120 --> 00:03:49,260
Connection is secure,

87
00:03:49,260 --> 00:03:52,290
cookies and site data or site settings.

88
00:03:52,290 --> 00:03:54,183
I'm gonna go to connection is secure.

89
00:03:55,350 --> 00:03:57,870
It tells me that the connection
is secured, that's good.

90
00:03:57,870 --> 00:04:00,570
And that the certificate is valid.

91
00:04:00,570 --> 00:04:03,210
Okay, so now I'd like to
look at the certificate.

92
00:04:03,210 --> 00:04:05,040
I can see general information.

93
00:04:05,040 --> 00:04:06,960
It's Amazon.com.

94
00:04:06,960 --> 00:04:09,540
It was issued by DigiCert.

95
00:04:09,540 --> 00:04:11,490
That was a certificate
authority that we looked

96
00:04:11,490 --> 00:04:14,130
at in our cert manager,

97
00:04:14,130 --> 00:04:17,583
the one that was a trusted
certificate authority.

98
00:04:18,570 --> 00:04:21,660
We can see it was issued
on January 16th, 2023.

99
00:04:21,660 --> 00:04:24,720
And it's good through January 16th, 2024.

100
00:04:24,720 --> 00:04:28,230
We can see with their
SHA-256 fingerprint or hashes

101
00:04:28,230 --> 00:04:30,690
as well as a SHA-1 fingerprint.

102
00:04:30,690 --> 00:04:33,210
If I want additional details,

103
00:04:33,210 --> 00:04:36,210
I can come here and I can
see it's a version three,

104
00:04:36,210 --> 00:04:38,277
the serial number,
again, their certificate,

105
00:04:38,277 --> 00:04:41,220
the signing algorithm when it's valid,

106
00:04:41,220 --> 00:04:43,590
not before and not after.

107
00:04:43,590 --> 00:04:47,010
Then I can see the public key using RSA.

108
00:04:47,010 --> 00:04:48,300
I can see the public key.

109
00:04:48,300 --> 00:04:52,440
Remember we said that public
keys are freely distributed.

110
00:04:52,440 --> 00:04:54,360
Again, the certificate key usage,

111
00:04:54,360 --> 00:04:55,740
the extended key usage,

112
00:04:55,740 --> 00:05:00,150
of CRL distribution point, any policies.

113
00:05:00,150 --> 00:05:01,680
And I can go right to DigiCert

114
00:05:01,680 --> 00:05:03,570
on the particular policies

115
00:05:03,570 --> 00:05:05,670
as well as, again the fingerprints.

116
00:05:05,670 --> 00:05:09,093
The SHA-256 and the SHA-1 fingerprint.

117
00:05:10,710 --> 00:05:13,260
So ever have a question
about a certificate?

118
00:05:13,260 --> 00:05:16,020
Go right to the padlock
and take a look at it.

119
00:05:16,020 --> 00:05:18,210
Wanna know about the certificates
that are on your system?

120
00:05:18,210 --> 00:05:19,500
Again, go to your cert manager

121
00:05:19,500 --> 00:05:21,780
if you're in the Windows
environment and take a look.

122
00:05:21,780 --> 00:05:24,270
And it's a really great way
to get to know certificates

123
00:05:24,270 --> 00:05:26,910
by just spending a little
bit of time exploring them,

124
00:05:26,910 --> 00:05:28,680
both the ones that are stored locally

125
00:05:28,680 --> 00:05:30,480
and the ones that will be presented

126
00:05:30,480 --> 00:05:33,210
to you whenever you're at a secure site.

127
00:05:33,210 --> 00:05:35,103
And that my friends is a closer look.
