What is an SSL/TLS certificate?
A cryptographic credential pairing a public key with a domain identity, facilitating HTTPS encrypted transport and verifying host authenticity.
Micro-Technology Solutions
Check the validity, issuer and trust chain of any domain's SSL certificate.
Your last audits will show up here, only in this browser.
Asymmetric encryption, TLS 1.3 handshake, Certificate Authorities (CA), and HSTS.
TLS 1.3 optimizes handshakes to 1-RTT using ECDHE ephemeral key exchange (Curve25519/P-256) ensuring Perfect Forward Secrecy.
Browsers validate root CAs embedded in OS keystores. The leaf server certificate is signed by an intermediate CA, terminating at the trusted root.
SAN extensions enable multi-domain and wildcard certificates. SNI allows web servers to host hundreds of distinct HTTPS sites on a single shared IP address.
HSTS headers force HTTPS connections, thwarting SSLStrip downgrade attacks. Preloaded domains are strictly protected directly in browser source code.
Technical fixes for Nginx, Apache, Let's Encrypt Certbot, and Cloudflare SSL errors.
Historical trivia about Netscape SSL, Microsoft's $35 slip-up, and Post-Quantum cryptography.
Developed at Netscape by Taher Elgamal, SSL 1.0 had serious replay flaws and was never published. The web first met SSL 2.0 in 1995 with Netscape Navigator 1.1.
Prior to 2015, SSL certs cost $50-$300/yr with manual fax checks. Let's Encrypt's ACME protocol drove global HTTPS adoption from 38% to over 95% today.
On Christmas 1999, Hotmail went down globally because Microsoft forgot to renew `passport.com`. A Linux consultant named Michael Lawrie paid the $35 renewal fee with his own credit card to restore it.
To defend against 'Harvest Now, Decrypt Later' attacks, Cloudflare and Chromium browsers now negotiate hybrid X25519Kyber768 lattice-based post-quantum cryptography.
Learn the fundamental concepts, protocols, and technical terminology of this tool.
A cryptographic credential pairing a public key with a domain identity, facilitating HTTPS encrypted transport and verifying host authenticity.
The hierarchical validation chain linking an end-entity domain certificate through intermediate issuers up to a trusted pre-installed Root CA store.
Deprecates legacy vulnerable ciphers, accelerates session handshakes to a single round-trip (1-RTT), and encrypts key exchange metadata.
A response header commanding browsers to communicate exclusively over encrypted HTTPS, thwarting SSL stripping and man-in-the-middle attacks.