PKI Bootcamp - What is a PKI?

  Рет қаралды 188,777

Paul Turner

Paul Turner

Күн бұрын

A PKI (public key infrastructure) is often confused with a CA (certificate authority) but it is much more than that. A PKI includes all of the components required to enable the use of certificates. Because of this, it represents the attack surface an attacker can exploit when attempting to leverage certificates and keys in their attacks.

Пікірлер: 171
@eduardrotty8584
@eduardrotty8584 3 жыл бұрын
you explained the PKI smoothly and using words that can reach casual, beginner and expert greetings from indonesia
@PaulTurnerChannel
@PaulTurnerChannel 3 жыл бұрын
I really appreciate the feedback, Raki. Greetings to you in Indonesia! I never imagined that my videos would reach so far around the world. It was a heartwarming greeting from you.
@rodrigomunoz1556
@rodrigomunoz1556 3 жыл бұрын
Paul, you really have the talent to explain complex topics in an easy way, and your slides are awesome.
@PaulTurnerChannel
@PaulTurnerChannel 3 жыл бұрын
Thank you for your kind words, Erick. I’m very glad you liked the presentation and appreciate you taking the time to comment.
@Sccoropio
@Sccoropio 4 жыл бұрын
One of the best PKI explanations on KZbin. A true reflection of the real world scenario.
@PaulTurnerChannel
@PaulTurnerChannel 4 жыл бұрын
I’m glad you liked it. Thanks for the feedback.
@IPv6people
@IPv6people 3 жыл бұрын
Very clear and very agreeable to watch and listen to in all respects. I look forward to more of these ten-minute jewels.
@PaulTurnerChannel
@PaulTurnerChannel 3 жыл бұрын
Glad you liked it, Joost. I’m hoping to get another video done in a few weeks.
@Yazeenj1
@Yazeenj1 5 жыл бұрын
Easy to understand and a really great explanation Paul, i can't thank you enough for this
@PaulTurnerChannel
@PaulTurnerChannel 5 жыл бұрын
SkillexeD, I'm really glad you like it. That means a lot to me. Thanks.
@zes7215
@zes7215 3 жыл бұрын
wrg
@BattyVibess
@BattyVibess 4 ай бұрын
After an hour of reading about PKI, trying to understand it and failing, I finally have a grasp on this now. Thank you, Paul!
@ranjankalita1220
@ranjankalita1220 3 жыл бұрын
I have been reading about these concepts for a few days now, your video really helped me connect the dots. Thanks a lot. Beautifully explained.
@PaulTurnerChannel
@PaulTurnerChannel 3 жыл бұрын
You put a big smile on my face, Ranjan. Thanks for your comment.
@lerneninverschiedenenforme7513
@lerneninverschiedenenforme7513 3 жыл бұрын
This - is - awesome! The creme de la creme of explanations here! Thank you very much for the work!
@PaulTurnerChannel
@PaulTurnerChannel 3 жыл бұрын
Wow! Thank you very much for the feedback.
@markduong92
@markduong92 3 жыл бұрын
This is probably one of the best explanations of Public Key Infrastructure. Great Job. I'll be sure to share this video.
@PaulTurnerChannel
@PaulTurnerChannel 3 жыл бұрын
I’m very glad you liked it, Mark. Thanks for the positive feedback!
@yanlevyexperience
@yanlevyexperience 4 жыл бұрын
Great video on PKI Sir Paul, concise and informative. The best I have seen so far.
@PaulTurnerChannel
@PaulTurnerChannel 4 жыл бұрын
Thank you very much, Yanick.
@salakhre3775
@salakhre3775 5 жыл бұрын
The best, easiest and detailed explanation for beginners to the expert. Thank you for making such great video.
@PaulTurnerChannel
@PaulTurnerChannel 5 жыл бұрын
Thanks for the kind comment, Salakh. I really appreciate it.
@jpbaloga
@jpbaloga 3 жыл бұрын
This is a well-explained video about PKI since I'm on a journey for my CISSP cert. Thanks, Paul!
@PaulTurnerChannel
@PaulTurnerChannel 3 жыл бұрын
Good luck on your CISSP, John. I’m glad you found it helpful. Thanks for the feedback.
@afnaanladji947
@afnaanladji947 4 жыл бұрын
Hey Paul, your video makes a lot of sense. Well framed and explained. Thanks.
@PaulTurnerChannel
@PaulTurnerChannel 4 жыл бұрын
Thank you for the feedback, Afnaan. I’m glad it makes sense.
@aletheagallacher4265
@aletheagallacher4265 3 жыл бұрын
Excellent presentation and clarity. Thank you!
@PaulTurnerChannel
@PaulTurnerChannel 3 жыл бұрын
Thank you very much for the positive feedback, Alethea. I really appreciate it!
@samnnamani
@samnnamani Жыл бұрын
I just want to hug you and say thank you. Awesome. Bravo
@arkadeep2687
@arkadeep2687 6 жыл бұрын
These presentations are very very helpful, Paul. I was looking for an easy explanation of PKI certificate issuance and verification and your presentations were jackpot for me.
@PaulTurnerChannel
@PaulTurnerChannel 6 жыл бұрын
I'm very glad to hear that, Arkadeep. Thank you for the feedback.
@catch.2022
@catch.2022 3 жыл бұрын
This is a great video. It clarified so much for me. Thanks Paul!
@PaulTurnerChannel
@PaulTurnerChannel 3 жыл бұрын
I’m so glad to hear that, Ajay. I appreciate you taking the time to comment.
@hawaiiansoulrebel
@hawaiiansoulrebel 3 жыл бұрын
Thank you for this explanation! Lots of other videos seem to rush through this topic.
@PaulTurnerChannel
@PaulTurnerChannel 3 жыл бұрын
Well, I guess if we’re going to have a Hawaiian soul (reference to your great screen name), we definitely don’t want to rush it ;-). Thanks a bunch for the kind feedback.
@paulaganbi5236
@paulaganbi5236 4 жыл бұрын
I been studying PKI for the past 3 weeks for an upcoming exam and I have struggled to grasp it, I watched this video and I instantly understood the basics of the concept. Thank you for this
@PaulTurnerChannel
@PaulTurnerChannel 4 жыл бұрын
Paul, you put a big smile on my face when I read your note. I apologize for being slow in responding. I'm glad the video was helpful!
@hicksticks2001
@hicksticks2001 2 жыл бұрын
Was doing some research on post-quantum cryptography. How have I never come across this video before or your channel? I watched it for nostalgia's sake. Loved it! Glad to see it has gotten so many views.
@PaulTurnerChannel
@PaulTurnerChannel 2 жыл бұрын
Hey, Aaron. Great to hear from you. Coming from a person who could teach the topic much better than me, that means a lot.
@felipefn88
@felipefn88 5 жыл бұрын
Great! Thank you for taking the time.
@PaulTurnerChannel
@PaulTurnerChannel 5 жыл бұрын
Thank you for taking the time to send me a comment, Felipe. I'm glad you found it helpful.
@toddpatrick7695
@toddpatrick7695 4 жыл бұрын
Outstanding video... thank you!
@PaulTurnerChannel
@PaulTurnerChannel 4 жыл бұрын
Todd, thanks for taking the time to give your feedback. I really appreciate it.
@Mr_Duck_RVA
@Mr_Duck_RVA Жыл бұрын
Great video you explained it so well.
@salmanriaz7892
@salmanriaz7892 Күн бұрын
@paul many thanks for making it so easy to understand ! Did you many any explaining private CA and how they work? I have already found one of your video on x.509
@joshd1732
@joshd1732 4 жыл бұрын
Thank you for this.
@PaulTurnerChannel
@PaulTurnerChannel 4 жыл бұрын
You are very welcome, Josh. I hope it was helpful.
@Schmo_theoriginal
@Schmo_theoriginal 2 ай бұрын
Why is this video so well put together?
@Flappy9
@Flappy9 Жыл бұрын
Thanks Paul!
@nareshmallavolu
@nareshmallavolu Жыл бұрын
Awesome, thanks !! it is a good help for me to understand the PKI this better
@PaulTurnerChannel
@PaulTurnerChannel Жыл бұрын
Thank you for taking the time to leave a comment, Naresh. I’m glad it was helpful.
@jdobbs42
@jdobbs42 3 жыл бұрын
Outstanding! Thank You
@PaulTurnerChannel
@PaulTurnerChannel 3 жыл бұрын
Thank you very much for your feedback, Jason!
@ifeastontoenails
@ifeastontoenails 2 жыл бұрын
Your PKI videos really helped me think through my science fiction writing. Thanks!
@PaulTurnerChannel
@PaulTurnerChannel 2 жыл бұрын
Haha. I’m not sure how to take that. I hadn’t been shooting for fiction on the videos but must have made quite an impression with my delivery to inspire your sci-fi writing 😃
@kam...3247
@kam...3247 Ай бұрын
Where can I read your sci-fi novel ?
@uglyface7665
@uglyface7665 3 жыл бұрын
Thank you so much. The video was very helpful.
@PaulTurnerChannel
@PaulTurnerChannel 3 жыл бұрын
Thank you for taking the time to give me your feedback. I’m really happy to hear it was helpful.
@ofsoundmind28
@ofsoundmind28 3 жыл бұрын
OMG I love your videos thank you so much.
@PaulTurnerChannel
@PaulTurnerChannel 3 жыл бұрын
Thank you for your enthusiastic feedback. Comments like this make my day, Mason.
@SSSingh1320
@SSSingh1320 2 жыл бұрын
great explanation Paul. easy to understand and precise.
@PaulTurnerChannel
@PaulTurnerChannel 2 жыл бұрын
Thank you very much for the feedback, Shashank. I really appreciate it. I’m glad it was helpful.
@SSSingh1320
@SSSingh1320 2 жыл бұрын
@@PaulTurnerChannel was searching this topic for the first time and glad I landed directly on this. you explained the entire architecture very well. Thanks again. stay safe.
@wobuntu
@wobuntu 5 жыл бұрын
Better than any lecture on this topic, thanks so much, very, very good video
@wobuntu
@wobuntu 5 жыл бұрын
Could you probably recommend some sources/books/papers/articles? You made me curious, i'd love to read more about it
@PaulTurnerChannel
@PaulTurnerChannel 5 жыл бұрын
Thank you very much for the feedback, Mathias. I wish I could point you to something I've read but I started in PKI a long time ago and, having learn most of what I know on the job, haven't kept up with book much. However, I can strongly recommend you looking at Ivan Ristic's book "Bulletproof SSL and TLS". He's very knowledgeable in this space. I also believe there is some other guidance that will be coming out soon and will give you a heads up when it hits the street.
@wobuntu
@wobuntu 5 жыл бұрын
@@PaulTurnerChannel t Thank you Paul!
@lokeshselvakumar4058
@lokeshselvakumar4058 2 жыл бұрын
great content explained in a simple way!
@PaulTurnerChannel
@PaulTurnerChannel 2 жыл бұрын
Thank you for the feedback, Lokesh. I’m glad it was understandable.
@meccaadams9299
@meccaadams9299 2 жыл бұрын
OMG! I'm studying for the Security + exam and this video has helped me understand CRL, Root, and OCSP. Thank you for making this video
@PaulTurnerChannel
@PaulTurnerChannel 2 жыл бұрын
Mecca, I’m so glad you found the video helpful. Good luck on your exam. I’m sure you will do great.
@dorab.theitexplorer6462
@dorab.theitexplorer6462 3 жыл бұрын
Thanks a lot it really helped me to clear my vision Greeting from north Africa
@PaulTurnerChannel
@PaulTurnerChannel 3 жыл бұрын
Doudi, you put a big smile on my face with your greeting. Though the internet is clearly global, I frankly never anticipated that the videos I was creating would be viewed from so many different continents and countries. I’m glad you found the video helpful. Thank you so much for reaching out from half way around the world ;-)
@rahellhamarash2915
@rahellhamarash2915 3 жыл бұрын
thank you for the great explanation , but may I ask what is the currently used method to check for validity of certificates ? from what I understand it's what we call ocsp stapling which you didn't talk about
@PaulTurnerChannel
@PaulTurnerChannel 3 жыл бұрын
Hi, Rachell. Thanks for pointing that out. This is an older video and I didn’t include OCSP stapling. It has become much more widely used. I appreciate you bringing it up.
@abhishekyadav0007
@abhishekyadav0007 6 жыл бұрын
Easy to understand.. thanks paul
@PaulTurnerChannel
@PaulTurnerChannel 6 жыл бұрын
Thank you, Abhishek.
@sanskarsingh9538
@sanskarsingh9538 4 жыл бұрын
Smooth like butter
@PaulTurnerChannel
@PaulTurnerChannel 4 жыл бұрын
Thank you, Sanskar.
@3eenab
@3eenab 6 жыл бұрын
Thanks a lot.
@aa-ur8wu
@aa-ur8wu 4 жыл бұрын
thank you from France
@PaulTurnerChannel
@PaulTurnerChannel 4 жыл бұрын
:-) Merci pour votre note. Ça m'a fait un grand sourire. Vive la France!
@UralaTAO
@UralaTAO 3 жыл бұрын
Thanks for that man.
@PaulTurnerChannel
@PaulTurnerChannel 3 жыл бұрын
Thank you, BTC. I appreciate you taking the time to comment. Glad it was helpful.
@PaulEllisBIGDATA
@PaulEllisBIGDATA 2 жыл бұрын
Thank you.
@PaulTurnerChannel
@PaulTurnerChannel 2 жыл бұрын
Thank you for taking the time to leave a comment, Paul!
@DanielAlvarez-mt1gk
@DanielAlvarez-mt1gk 3 жыл бұрын
Great video! I have PKI infrastructure in place from a previous engineer. I need to setup EAP+TLS for radius wireless, where can i get a private cert? GoDaddy? Or can the Root CA generate one?
@PaulTurnerChannel
@PaulTurnerChannel 3 жыл бұрын
Hi, Daniel. Sorry for the slow response. Your internal PKI infrastructure should have an issuing CA. That is where you want to issue the EAP-TLS Cert from. If you only have a root CA, you should strongly consider setting up a new issuing CA (and possibly a new root, since the existing root would have gotten lots of exposure if it was issuing end entity certs (e.g., TLS certs)). I hope this helps.
@vitoralexandrino3328
@vitoralexandrino3328 5 жыл бұрын
Paul, great explanation, is there any way I can get this powerpoint file to present in my class on my own language?
@PaulTurnerChannel
@PaulTurnerChannel 5 жыл бұрын
Vitor, let me look into this. Those slides are technically owned by Venafi, the company I used to work for. I'll check with them. It may take me a bit to get back to you. I appreciate the feedback.
@thomasaragaw7415
@thomasaragaw7415 3 жыл бұрын
Hi Paul, Thank you for explaining this subject. Is it possible to find out the RA and VA from the website digital certificate?
@PaulTurnerChannel
@PaulTurnerChannel 3 жыл бұрын
Hi, Thomas. Thanks for your question. You cannot determine the RA from the certificate unless the CA chooses to add a proprietary extension (I'm not aware of any standard extensions that list the RA but may have missed it). From the certificate, you can determine the certificate authority (CA), the CRL distribution point (CDP), OCSP responder location, and the location where the CA chain can be retrieved (CA Issuers). I hope this helps. I'm curious. Why would you want to determine the RA from the certificate as a relying party? I'm not sure what a VA is. Again, I may have missed that term in my travels so feel free to enlighten me. Thanks a bunch for the question
@PrakashSingh-to1nl
@PrakashSingh-to1nl 5 жыл бұрын
This is by far the best video on this topic I have come across.. 🙂 I am glad that I have found it .. Paul any thoughts on browser vs server certificate? Will love to see ur explanation..
@PaulTurnerChannel
@PaulTurnerChannel 5 жыл бұрын
I appreciate you saying that, Prakash. Can you clarify your question about browser (client) vs server certificates? Are you asking about when client certificates should be used or some other aspect? Thanks for your question. Sorry for not understanding it.
@PrakashSingh-to1nl
@PrakashSingh-to1nl 5 жыл бұрын
@@PaulTurnerChannel thanks for your reply.. I was referring to sever to server vs browser to server communication .. behavioural difference between these two type of communication... though I really appreciate ur reply.. Thanks
@PaulTurnerChannel
@PaulTurnerChannel 5 жыл бұрын
Prakash, your question is a little broad so I'm not sure I'll be answering what you're inquiring about. With respect to server-to-server (S2S) vs. browser-to-server (B2S), there are no differences in the TLS protocol or the TLS server certificates used in both cases. The primary difference I see between the two is how they will respond to errors. For example, with S2S, the server acting as a client will shutdown the TLS connection and log an error if an expired certificate or name mismatch is encountered. The application served by the S2S communications will stop operating at that point. With B2S, the browser will display an error for the user when an expired certificate is encountered. The user is free to make a choice on how they respond (click through or abandon). The browser manufacturers have made their errors more stern and difficult to dismiss so users are less likely to click through the error but it is not impossible. If they don't click through, they will likely try to contact support for the application (since they can't get to it). The reason I raise this difference (again, not knowing if this is what you were looking for) is that the situation is subtly but importantly different between the two. In the S2S case, someone has to dig through log files to figure out why the application stopped working. In the B2S case, it is pretty clear from the error messages displayed in the browser what happened (especially, if the support person tries to connect to the server and they get the error message). I've heard of organizations troubleshooting S2S expired certificate issues for several hours before they figure out what happened. If there are multiple clustered systems acting as servers and there is only an expired certificate on one (e.g., the others were updated), this can make it even more difficult to troubleshoot because you have a load balancer spreading clients across the clustered servers and it only fails intermittently. As I write this, I realize I'm probably way off from what you were interested in. If so, can you please restate your question? It doesn't appear that you were asking about client TLS certs and the difference between servers acting as clients and browsers. I'm sorry if I'm being slow on this.
@PrakashSingh-to1nl
@PrakashSingh-to1nl 5 жыл бұрын
@@PaulTurnerChannel thanks!! for the detailed explanation.. that pretty much explained my question..🙂
@Duduicostin
@Duduicostin 2 жыл бұрын
Finally, I can understand PKI
@PaulTurnerChannel
@PaulTurnerChannel 2 жыл бұрын
I’m glad it was helpful, Costin. Thank you for the feedback.
@valb4184
@valb4184 5 жыл бұрын
Hi Paul, really informative tutorial. I have a question, can you explain the difference between Centralized (CA generates both keys) vs Decentralized (user generates both keys), does the CA digitally sign the Digital Certificate along with the keys and send it to the user? Thank you.
@PaulTurnerChannel
@PaulTurnerChannel 5 жыл бұрын
Hi, Val. Good question. If you have the CA centrally generate the key pair, the user will provide their information for inclusion in the certificate and the CA will generate the key pair (public and private key), issue a certificate containing the public key, and provide the private key and certificate for download by the user. The private key should be protected by a password when downloaded. In most cases, the private key and password will be provided in PEM or PKCS#12 format (file format of the keystore). Generally, you don't want to have a public CA creating key pairs for you unless you're leveraging the CA as a key escrow/backup service (which only makes sense for things such as email encryption, where you don't want to risk losing all copies of your private key). With decentralized key generation, the user generates the key pair along with a CSR (which contains the public key). They submit the CSR to the CA. The CA uses the information within the CSR and whatever other information they choose to issue a certificate. The CA returns the certificate back to the user. The user installs certificate and private key in the needed location for the application that will use the them for both centralized and decentralized. I hope this helps.
@valb4184
@valb4184 5 жыл бұрын
You are awesome!
@valb4184
@valb4184 5 жыл бұрын
Thanks Paul, explained really well. I keep coming back to your videos for references.
@Mike-kq5yc
@Mike-kq5yc 9 ай бұрын
Hello. Can you recommend any ressource for understanding and implementing the underlying architecture and (as well as file organization) of every component in the PKI ecosystem such as CA, Root CA, ..., If were to be established and deployed in a real life insecure infrastructure?
@PaulTurnerChannel
@PaulTurnerChannel 8 ай бұрын
Hi, Mike. Sorry for the slow response. There are a variety of good PKI consulting organizations out there. You might talk with Encryption Consulting (www.encryptionconsulting.com) or Komar Consulting (www.komarconsulting.com). Brian Komar also has written several papers and books. I hope that helps.
@Mike-kq5yc
@Mike-kq5yc 8 ай бұрын
@@PaulTurnerChannel Never mind. I am glad, that you took your time to respond. Would you mind, if I message you on youtube? I need a couple of tipps for my current project if you do not mind
@PaulTurnerChannel
@PaulTurnerChannel 8 ай бұрын
No problem, Mike. My primary expertise is in the cert and key mgmt of PKI. There many others better than me at CA deployment and mgmt.
@Mike-kq5yc
@Mike-kq5yc 8 ай бұрын
@@PaulTurnerChannel can I have your E-Mail Address? I cannot find any way to communicate with you. I posted my E-Mail here in a comment but it got deleted somehow
@PaulTurnerChannel
@PaulTurnerChannel 8 ай бұрын
@@Mike-kq5yc Sorry for the slow response. Please connect with me on Linkedin at www.linkedin.com/in/equio/.
@fbifido2
@fbifido2 9 ай бұрын
@4:50 - what's the max & min timeframe (using pki best practice as a guide) for a Root-CA and an Issuing-CA?
@jda3741
@jda3741 4 жыл бұрын
I thought the diagram you used to describe the whole process was very useful. I was just wondering with what software you used to create it.
@PaulTurnerChannel
@PaulTurnerChannel 4 жыл бұрын
Hi, JD. I use PowerPoint to create the graphics and animations. Thanks a bunch for you feedback. I’m glad you liked it.
@houssemedyn5678
@houssemedyn5678 4 жыл бұрын
Thank you
@PaulTurnerChannel
@PaulTurnerChannel 4 жыл бұрын
Thank you for taking the time to comment, Houssem.
@clebo99
@clebo99 4 жыл бұрын
Very nice video. Thank you.
@PaulTurnerChannel
@PaulTurnerChannel 4 жыл бұрын
I appreciate the feedback. I have to say that I didn’t expect that particular video to be as well received and helpful as it appears to be. I’m glad it is helpful!
@clebo99
@clebo99 4 жыл бұрын
@@PaulTurnerChannel No problem. I learn a lot from KZbin and this was great. If I may ask a follow-up question (since you responded so quickly). I'm also trying to learn about HSM's and my main/basic question is: Can an HSM be a CA as well or are they traditionally/always separate systems?
@PaulTurnerChannel
@PaulTurnerChannel 4 жыл бұрын
A CA would use an HSM to secure its signing key but you would likely not want an HSM to BE a CA. The reason is that HSMs must conform to a standard called FIPS 140, which is very restrictive and requires retesting for certification when changes are made to the internal code. HSMs typically perform a limited number of functions (key gen, signing, etc.) and therefore have a smaller code base and don’t require frequent changes/updates. On the other hand, CAs typically have large amounts of code and need updating frequently with new functionality to respond to changing market needs. The size of CA code would significantly extend testing/certification times and the retesting for certification would slow down the ability to get new features out. Consequently, most CAs have not been built into HSMs and instead use them as a security resource to protect their signing keys. Hope this makes sense.
@clebo99
@clebo99 4 жыл бұрын
@@PaulTurnerChannel Perfect. Much appreciated!!!!!
@junaid_qadir
@junaid_qadir 2 жыл бұрын
Hi Paul, this is a very awesome explanation indeed. Thanks for the wonderful lecture. Now can you please implement this scenario in code? Secondly, how you have made these slides, is it PPT or any other software?
@PaulTurnerChannel
@PaulTurnerChannel 2 жыл бұрын
Thanks for the feedback, Junaid. The slides were created with PowerPoint.
@junaid_qadir
@junaid_qadir 2 жыл бұрын
@@PaulTurnerChannel Thanks for your prompt response. Do you supervise students? How can I reach you privately?
@PaulTurnerChannel
@PaulTurnerChannel 2 жыл бұрын
Hi, Junaid. You ca. contact me on LinkedIn with my name and Epuio.
@junaid_qadir
@junaid_qadir 2 жыл бұрын
@@PaulTurnerChannel thank you so much, sure I will get in touch with you soon.
@ohaRega
@ohaRega 2 жыл бұрын
Awesome
@PaulTurnerChannel
@PaulTurnerChannel 2 жыл бұрын
Thank you for the feedback. I’m glad you liked it.
@chandu354
@chandu354 2 жыл бұрын
Very helpful 👍👍👍❤️❤️
@PaulTurnerChannel
@PaulTurnerChannel 2 жыл бұрын
I’m very happy to hear it was helpful, Chandu!
@citizensnipsnw
@citizensnipsnw 5 жыл бұрын
excellent video
@PaulTurnerChannel
@PaulTurnerChannel 5 жыл бұрын
Thanks for the feedback. I appreciate it.
@rmcgraw7943
@rmcgraw7943 3 жыл бұрын
Very good intro to certs.
@PaulTurnerChannel
@PaulTurnerChannel 3 жыл бұрын
Thank you very much for the feedback, Lee. I’m glad it was helpful b
@giladbaruchian7522
@giladbaruchian7522 5 жыл бұрын
so if you DDOS all the OCSP you can break large chunks of the internet? :)
@PaulTurnerChannel
@PaulTurnerChannel 5 жыл бұрын
Hi, Gilad. Yes, DDOS is a risk with OCSP.
@prash2905
@prash2905 3 жыл бұрын
At 4:11, do you mean giving their "PUBLIC KEY" certificate?
@PaulTurnerChannel
@PaulTurnerChannel 3 жыл бұрын
Hi, Prashanth. Good catch. It sounds like I say "root" certificate there (before I even introduce the concept of a root certificate). Yes, I meant to say they provide their own certificate, which is a public key certificate. Thank you for catching that!
@prash2905
@prash2905 3 жыл бұрын
@@PaulTurnerChannel Paul, I seriously love your videos and I hope you make more videos where you take complex topics and break them down like this. Thank you x 100. I was just making sure I understood it right. I don't mean to point mistakes. I hope you have a fantastic day!
@prash2905
@prash2905 3 жыл бұрын
@@PaulTurnerChannel Your videos will be here forever and help countless folks! Thank you again.
@austin12091
@austin12091 2 жыл бұрын
would have been great to of seen this for my sec+ test
@PaulTurnerChannel
@PaulTurnerChannel 2 жыл бұрын
I guess we’d need a time machine for that MillerTheGreat ;-). Sorry that you didn’t find it before the test. Hope it was helpful nonetheless.
@td4yd154
@td4yd154 2 жыл бұрын
The entire process starts with sally requesting a website by entering a password? Bob tells the CA that the cert is not good anymore? Confusing.
@PaulTurnerChannel
@PaulTurnerChannel 2 жыл бұрын
I’m sorry you found it confusing, TD. The portion about Sally is not meant to imply she is requesting a website. She knows she wants to use that particular website and wants to do so securely. The rest of the video explains how the PKI system was designed to support that secure communication. Again, I’m sorry you found the video confusing. I hope you’re able to find information that is helpful to you.
@marcooceda5832
@marcooceda5832 4 жыл бұрын
Pki is the same that Kpi? I have a work about kpi with Power pivot
@PaulTurnerChannel
@PaulTurnerChannel 4 жыл бұрын
Marco, I have to confess that I don't understand your question. I have never heard PKI (public key infrastructure) referred to as KPI so I would have to reply that they're not the same. The only time I've heard of KPI for "key performance indicators". That is definitely not the focus of this presentation.
@marcooceda5832
@marcooceda5832 4 жыл бұрын
@@PaulTurnerChannel Is the pki related to excel power pivot?
@PaulTurnerChannel
@PaulTurnerChannel 4 жыл бұрын
Hi, Marco. No. This presentation is not about Power Pivot in Excel. I hope you find a good resource to help you on that topic. Good luck.
@bobonaqa
@bobonaqa 4 жыл бұрын
@@PaulTurnerChannel Is mayonnaise an instrument?
@entertainmentnlearning7941
@entertainmentnlearning7941 4 жыл бұрын
nice
@PaulTurnerChannel
@PaulTurnerChannel 4 жыл бұрын
Thank you!
@shubhamsingla2120
@shubhamsingla2120 5 жыл бұрын
What will happen if some client has copied the certificate of the website and then started being that website because he has the certificate and now this stealing client can host a similar website with this certificate and fooling other loyal clients? :(
@PaulTurnerChannel
@PaulTurnerChannel 5 жыл бұрын
In the case you’re mentioning, the attacker would need to steal the private key that matches the certificate (typically installed on the server to which the certificate is assigned). Then they would need to redirect traffic to come to their server instead of the legitimate server. Please see my response to your question about MITM for additional background. I hope this helps.
@anakkeempat
@anakkeempat 2 жыл бұрын
hello, anyone can help me how to installation signserver in Ubuntu server.. urgent
@PaulTurnerChannel
@PaulTurnerChannel 2 жыл бұрын
Hi, Dita. I don’t have any experience with SignServer. Are you having trouble with the documentation? Have you tried reaching out to someone on the user forum sourceforge.net/projects/signserver/support ?
@bhootnimon
@bhootnimon Жыл бұрын
Plz speak little loud 🔊 or Inc volume of mike
@PaulTurnerChannel
@PaulTurnerChannel Жыл бұрын
Sorry, Swagata. That was one of my early videos when I didn’t have a good microphone.
@silvertad3833
@silvertad3833 2 жыл бұрын
@ 3:30 : " ... the software manufacturers putting the relevant certificate authorities in the software" , inaccurate statements
@PaulTurnerChannel
@PaulTurnerChannel 2 жыл бұрын
Hi, Silver. I’m confused by your comment. Many operating systems and other software/hardware come preloaded with root certs. Can you clarify?
@silvertad3833
@silvertad3833 2 жыл бұрын
@@PaulTurnerChannel Hi Paul, they are putting "root certificates" in the software/hardware not "certificate authorities", the certificate authorities are organizations
@PaulTurnerChannel
@PaulTurnerChannel 2 жыл бұрын
Ah. You are correct. I didn’t realize I had said that in the video. Good catch.
@genericrocker7655
@genericrocker7655 Жыл бұрын
Speak up! Max volume and I can still barely hear you.
@PaulTurnerChannel
@PaulTurnerChannel Жыл бұрын
Sorry, Generic Rocker. This was one of my early videos before I understood the importance of a good microphone. Hopefully, some of my later videos have better sound quality. Thanks for pointing it out. All the best.
@syahputraadha4854
@syahputraadha4854 4 жыл бұрын
Pki is(partai komunis indonesian) indonesian communist party in 1948-1965
@PaulTurnerChannel
@PaulTurnerChannel 4 жыл бұрын
:-). And all this time I thought it stood for public key infrastructure. I stand corrected. On a serious note, I was not aware of the existence of the PKI in Indonesia. Thank you for broadening my horizons.
@yosatip182
@yosatip182 4 жыл бұрын
BP U PKI
@sharifahsuhailasyedmuhsein6802
@sharifahsuhailasyedmuhsein6802 4 жыл бұрын
What is pki?: *commie indonesia*
@PaulTurnerChannel
@PaulTurnerChannel 4 жыл бұрын
Hello, Sharifah. I wasn’t aware of the PKI in Indonesia. I’m sorry for the overlap. I didn’t pick the name “public key infrastructure”, which results in “PKI” and is a broadly used term in the technology industry. This video is to help technologists understand that technology. I wish you all the best.
@BabuBakthavachalam
@BabuBakthavachalam 3 жыл бұрын
Thank you
@PaulTurnerChannel
@PaulTurnerChannel 3 жыл бұрын
Thank you for your expressions of appreciation for several videos. I’m very happy you find them useful.
PKI Bootcamp - Basics of Certificate Issuance
6:53
Paul Turner
Рет қаралды 40 М.
格斗裁判暴力执法!#fighting #shorts
00:15
武林之巅
Рет қаралды 37 МЛН
Follow @karina-kola please 🙏🥺
00:21
Andrey Grechka
Рет қаралды 17 МЛН
skibidi toilet 73 (part 2)
04:15
DaFuq!?Boom!
Рет қаралды 32 МЛН
Она Постояла За Себя! ❤️
00:25
Глеб Рандалайнен
Рет қаралды 7 МЛН
Introduction to Cryptographic Keys and Certificates
18:06
Paul Turner
Рет қаралды 166 М.
Certificates from Scratch - X.509 Certificates explained
21:50
OneMarcFifty
Рет қаралды 85 М.
End to End Encryption (E2EE) - Computerphile
8:12
Computerphile
Рет қаралды 740 М.
Tech Talk: What is Public Key Infrastructure (PKI)?
9:22
IBM Technology
Рет қаралды 97 М.
Intro to Digital Signatures & HMACs (and a little about TLS :)
21:04
格斗裁判暴力执法!#fighting #shorts
00:15
武林之巅
Рет қаралды 37 МЛН