PKI Bootcamp - Basics of Certificate Issuance

  Рет қаралды 40,822

Paul Turner

Paul Turner

7 жыл бұрын

This video provides a high level look at how certificates are signed and a certificate chain is created.

Пікірлер: 39
@AliBaba-vw7mo
@AliBaba-vw7mo 4 жыл бұрын
So far, I have not seen a single video that explains so far up the trust chain. Thanks!
@PaulTurnerChannel
@PaulTurnerChannel 4 жыл бұрын
I’m glad you found it helpful!
@chandankundapur
@chandankundapur 3 жыл бұрын
Echo what everyone else has mentioned here . Extremely useful . Thanks much Paul for your time in creating these videos
@PaulTurnerChannel
@PaulTurnerChannel 3 жыл бұрын
Thank you for taking the time to give your positive feedback, Chandan. I really appreciate it.
@vak21
@vak21 4 жыл бұрын
Excellent explanation, clear, detailed, and covering many open questions that had been bothering me for a long time.
@PaulTurnerChannel
@PaulTurnerChannel 4 жыл бұрын
Thank you very much for the feedback, Jose. I really appreciate it.
@GNSK3
@GNSK3 8 ай бұрын
Thank you so much. Great explanation.
@eddierouth
@eddierouth 4 жыл бұрын
Explained very well, loved your way of teaching .. please add more videos. Appreciate for your effort Paul.
@PaulTurnerChannel
@PaulTurnerChannel 4 жыл бұрын
Thanks for taking the time to provide your feedback, Indranil. I hope yo do a few more videos soon.
@irfan_b5186
@irfan_b5186 3 жыл бұрын
Fantastic work Paul.. really appreciated
@PaulTurnerChannel
@PaulTurnerChannel 3 жыл бұрын
I'm glad you like it, Irfan. Thanks for taking the time to write a comment!
@TheGPification
@TheGPification 7 жыл бұрын
very well explained, Paul!
@PaulTurnerChannel
@PaulTurnerChannel 7 жыл бұрын
Thanks for your feedback
@maurod6180
@maurod6180 3 жыл бұрын
THANK YOU!!!!! thank you very much!
@PaulTurnerChannel
@PaulTurnerChannel 3 жыл бұрын
Thank you for the feedback, Mauro.
@jesuschrist5405
@jesuschrist5405 9 ай бұрын
Excellent master for PKI
@PaulTurnerChannel
@PaulTurnerChannel 9 ай бұрын
Glad you liked it, Jesus. Thanks for the feedback.
@abhishekyadav0007
@abhishekyadav0007 6 жыл бұрын
Thanks again Paul..well explained
@PaulTurnerChannel
@PaulTurnerChannel 6 жыл бұрын
Thank you very much, Abhishek. I hope to get more videos out soon (been too busy with the day job :)
@AxelSchwab94
@AxelSchwab94 3 жыл бұрын
thank you for your effort, really cool; how has you made the animations?
@PaulTurnerChannel
@PaulTurnerChannel 3 жыл бұрын
Thanks for your feedback. I use PowerPoint.
@AxelSchwab94
@AxelSchwab94 3 жыл бұрын
Paul Turner nice than we have the same Approach to explain thinge, but you habe the cooler pp
@frankkolmann4801
@frankkolmann4801 3 жыл бұрын
I have never trusted public/private keys, simply because how private can you make a key private. Government level security agencies can simply say give us your private keys and BOOM nothing is secure. Thanks for the video.
@PaulTurnerChannel
@PaulTurnerChannel 3 жыл бұрын
Hi, Frank. You bring up a fairly complicated but important topic. I believe we can trust private keys (as a technology). There are risks related to the security of private keys, however, I believe those risks exist with any technology, and even with data itself. For example, even if I could prevent a government agency from getting access to the TLS private key(s) I use to protect my data, the government can simple tell me to give them the data. If I store the private key(s) in a FIPS hardware device, I may be able to protect them better but then the thing I need to protect is the credentials I use to access the device. I’m providing a bit of an abbreviated response but hope that helps. Thanks a bunch for your comment.
@CKZA10
@CKZA10 3 жыл бұрын
Hi Paul and everyone. I was looking at the X509 RFC (5280) and was wondering if your CA1 can be called the Registration Authority?
@PaulTurnerChannel
@PaulTurnerChannel 3 жыл бұрын
Sorry for the slow response. The actual CA at CA1 can’t be called an RA because it is signing certificates. RAs do not sign certs. However, the RA function is often performed as part of the CA organization. For example, if CA1, Inc. is running a CA, they will perform the RA function to validate that all requesters are authorized to request certs for their domains. CA1, Inc. acts as both the CA and RA. The most common case where the RA function is separate is when a corporation is requesting certs for their sub domains. For example, Corp1 goes to CA1, Inc. and says they want to issue certs for a bunch of severs under corp1.com. CA1 acts as the RA to confirm that Corp1 owns corp1.com. Then, if a user at Corp1 requests a cert for finance.corp1.com, an admin at Corp1 will review and approve the request in the CA1 console. In this case, CA1, Inc is the CA and Corp1 is the RA. Hope that helps.
@CKZA10
@CKZA10 3 жыл бұрын
@@PaulTurnerChannel Thanks Paul. The drawing in the RFC stated that the RA "publishes cert" so I assumed wrongly its function or intent. All clear now. I'm studying ISAKMP now for CCNP and came upon your excellent videos (which helped on the certificate aspect). Reall appreciate your time with this. Do you know by chance where I can get more details on COOKIES in IKEv1 Phase 1? Way off topic but at the end of Phase 1 IKEv1 there's SKEYID and SKEYID_e,d,a. It's generated using DH(secret) and then it says CKY_I and CKY_R (cookie initiator and responder). I can't seem to find an "English" explanation on what the cookies consist of lol.
@UmerShabibMohd
@UmerShabibMohd 5 жыл бұрын
Could you share the PDf of the slide
@PaulTurnerChannel
@PaulTurnerChannel 5 жыл бұрын
Hi, Umer. I'm not aware of a way to attach the file to KZbin video for download. Since this is technically Venafi content, I'm checking with them to see how it can be made available. I'm glad that it is useful enough that you'd like the PDF. Thanks for reaching out.
@PaulTurnerChannel
@PaulTurnerChannel 5 жыл бұрын
Umer, sorry for the delay in getting back to you. The PDF has been uploaded to following address (updated with the newer Venafi PPT template :): www.venafi.com/resource/pki-bootcamp-basics-of-certificate-issuance-presentation Please confirm that you are able to access it.
@basantsherwida4586
@basantsherwida4586 Жыл бұрын
@@PaulTurnerChannel thanks for sharing the slides , but the access to it is denied via your link :(
@PaulTurnerChannel
@PaulTurnerChannel Жыл бұрын
Umer, the slides were shared with you three years ago. I am no longer with Venafi and I assume they’ve taken that link down. Sorry.
@basantsherwida4586
@basantsherwida4586 Жыл бұрын
that's fine, no matter. its a great series videos by the way
@JeremyMcBane
@JeremyMcBane 4 жыл бұрын
3/13/37 I see what you did there
@PaulTurnerChannel
@PaulTurnerChannel 4 жыл бұрын
;-). Thanks!
@chrisadams27
@chrisadams27 2 жыл бұрын
Guys with guns? Please...
@PaulTurnerChannel
@PaulTurnerChannel 2 жыл бұрын
Haha. I guess I do have a flair for the dramatic every once in a while. Good catch 😀
@chrisadams27
@chrisadams27 2 жыл бұрын
@@PaulTurnerChannel great vid though, thanks
@PaulTurnerChannel
@PaulTurnerChannel 2 жыл бұрын
Thanks, Chris. I’m glad you liked it.
PKI Bootcamp   Basics of Certificate Chain Validation
3:43
Paul Turner
Рет қаралды 35 М.
PKI Bootcamp - Certificate Governance for Better Security
17:06
Paul Turner
Рет қаралды 10 М.
КАКОЙ ВАШ ЛЮБИМЫЙ ЦВЕТ?😍 #game #shorts
00:17
Poopigirl
Рет қаралды 10 МЛН
Sprinting with More and More Money
00:29
MrBeast
Рет қаралды 149 МЛН
ХОТЯ БЫ КИНОДА 2 - официальный фильм
1:35:34
ХОТЯ БЫ В КИНО
Рет қаралды 2,8 МЛН
ПАРАЗИТОВ МНОГО, НО ОН ОДИН!❤❤❤
01:00
Chapitosiki
Рет қаралды 2,8 МЛН
Introduction to Cryptographic Keys and Certificates
18:06
Paul Turner
Рет қаралды 166 М.
Digital Certificates: Chain of Trust
16:41
Dave Crabbe
Рет қаралды 284 М.
PKI -  trust & chain of trust -why, who and how?
8:19
Sunny Classroom
Рет қаралды 144 М.
PKI Bootcamp - What is a PKI?
10:48
Paul Turner
Рет қаралды 189 М.
Tech Talk: What is Public Key Infrastructure (PKI)?
9:22
IBM Technology
Рет қаралды 101 М.
Breaking Down the TLS Handshake
12:29
F5 DevCentral
Рет қаралды 251 М.
Certificates from Scratch - X.509 Certificates explained
21:50
OneMarcFifty
Рет қаралды 89 М.
Revocation of digital certificates: CRL, OCSP, OCSP stapling
6:40
Sunny Classroom
Рет қаралды 73 М.
КАКОЙ ВАШ ЛЮБИМЫЙ ЦВЕТ?😍 #game #shorts
00:17
Poopigirl
Рет қаралды 10 МЛН