PKI Chain of Trust

How your browser decides a website's public key is genuine, without ever meeting the website in person

PREREQUISITE • Your OS / browser ships with a built-in list of trusted Root CA public keys — this is the one thing you have to trust in advance Start 1 🏛️ Root CA Signs Intermediate CA Root's private key signs the intermediate's public key 2 🏛️ Intermediate CA Signs Leaf Certificate Signs the website's public key + domain name 3 🌐 Web Server Presents Chain Sends its leaf cert + intermediate cert to you Chain Valid, Reaches Trusted Root? Yes 4 🔒 Browser Session Secured Continues the TLS handshake as normal 🔒 Secure Connection padlock shown to user No ⚠️ Certificate Warning connection blocked Legend Certificate Authority signs Web server / TLS handshake Browser-side verification Decision Start / End

Prerequisites

  • • Trusted Root CA store, pre-installed by OS/browser vendor
  • • X.509 certificate format for every link in the chain

Inputs → Outputs

  • • Input: leaf cert + intermediate cert from server
  • • Output: verified identity, or a blocked connection
  • • Revocation checked via CRL / OCSP

Tools & Commands

  • • openssl x509 — inspect a certificate
  • • openssl s_client -connect — view a live chain
  • • Let's Encrypt, DigiCert — common public CAs