Open cardosec

Case 1CD187 · Cryptography · L3 Applied

PKI and Certificate Chains

Practise as: Explain it · Interview · Deep dive

Interview questionWalk me through how a browser decides to trust a website certificate.

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Server sends leaf plus intermediates; the client builds a path to a root in its trust store (X.509, RFC 5280).
  2. Each link is checked: signature, validity dates, BasicConstraints CA:TRUE, KeyUsage, name constraints.
  3. Leaf must match the hostname via subjectAltName (CN is ignored by modern browsers).
  4. Revocation is soft-fail in practice; OCSP is fading (Let's Encrypt ended it in 2025), so CRLs and short-lived certs lead.
  5. Certificate Transparency logs make mis-issuance publicly detectable; Chrome, Safari and Firefox (desktop) require SCTs.

If the interviewer pushes back

  • Why are roots kept offline and intermediates used to sign leaves, and what happens when an intermediate is compromised?
  • How do CAA records and CT monitoring together reduce mis-issuance risk for your domain?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.