Case 1CD187 · Cryptography · L3 Applied
PKI and Certificate Chains
Practise as: Explain it · Interview · Deep dive
Interview questionWalk me through how a browser decides to trust a website certificate.
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- Server sends leaf plus intermediates; the client builds a path to a root in its trust store (X.509, RFC 5280).
- Each link is checked: signature, validity dates, BasicConstraints CA:TRUE, KeyUsage, name constraints.
- Leaf must match the hostname via subjectAltName (CN is ignored by modern browsers).
- Revocation is soft-fail in practice; OCSP is fading (Let's Encrypt ended it in 2025), so CRLs and short-lived certs lead.
- Certificate Transparency logs make mis-issuance publicly detectable; Chrome, Safari and Firefox (desktop) require SCTs.
If the interviewer pushes back
- Why are roots kept offline and intermediates used to sign leaves, and what happens when an intermediate is compromised?
- How do CAA records and CT monitoring together reduce mis-issuance risk for your domain?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.