{"id":1781,"date":"2021-04-10T08:30:44","date_gmt":"2021-04-10T08:30:44","guid":{"rendered":"https:\/\/gauravw.com\/blog\/?p=1781"},"modified":"2021-04-10T08:30:50","modified_gmt":"2021-04-10T08:30:50","slug":"tls-ssl-certificate-issuance","status":"publish","type":"post","link":"https:\/\/gauravw.com\/blog\/2021\/04\/tls-ssl-certificate-issuance\/","title":{"rendered":"TLS\/SSL Certificate Issuance"},"content":{"rendered":"<p>Public Key is used to sign into something<br><\/p>\n\n\n\n<p>1. Get certificate issued from CA<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Server asks for the public key CA.<\/li><li>Servers send a new message which has their own public key, domain name to get a certificate from CA. This entire message is encrypted by using the public key of the CA.<\/li><li>CA unlocks the message using their private key and looks into the message, verifies stuff and sends back the Certificate as payload along with other info and signed by the public key of the Server.<\/li><li>The server can read the message using its own private key.<\/li><\/ul>\n\n\n\n<p><br>2. Send certificate to others to establish connection<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/lh4.googleusercontent.com\/XLodYi2OUCrcUXyDbHCLN7zN7Ovr4nSOz-bc_A1LEN9KQDt1ELbGObgI8ErAmz32vfl7-syKF9dVKETyARkTyExTYbxAWzQh9BoPK5R4cSIEZWsTWDSHmfVquVUzv3XoVkHl7PSG\" alt=\"\"\/><\/figure>\n\n\n\n<p>Send certificate to others to establish connection<br><br>Session key is a symmetric key so it&#8217;s used by both server and client.<br><br>Essentially PKI is used for the key exchange process and later the encryption is handled by Symmetric key encryption.\u00a0<\/p>\n\n\n\n<p>RSA and Diffie Hellman are public key system<br><\/p>\n\n\n\n<p><strong>Flaws<\/strong><br>RSA is not to be used from TLS\/SSL 1.2 onwards.<br>RSA has a heartbleed issue in TLS 1.0.1 \/ 2 . Here a special heartbeat message is sent to the server to keep the SSL connection on.<\/p>\n\n\n\n<p><strong>Payload | size<\/strong><br>The message contains a payload and size of it. When the server receives the message, it replies back with the payload that was stored in its memory.<br><br>Now if the client sends a heartbeat message with a payload of actual size = 1 byte but in the size column it says 65k then the server receives and stores the payload in its memory. It then replies back with a payload of size 65k.<br>This means the client gets 65k of the information stored on the server. This is a flaw and it affects because the information that is revealed is keys, sensitive data etc.<\/p>\n\n\n\n<p>RSA is not to be used. They recommend a size higher than 2048 bits for keys and its too large.<\/p>\n\n\n\n<p>Diffie Hellman also suffers from issues like MITM attack so it&#8217;s coupled along with Digital signatures. In recent times we use Elliptic curve based Diffie Hellman as the key size remains smaller and security is as good as lengthier key sizes.<\/p>\n\n<!--themify_builder_content-->\n<div id=\"themify_builder_content-1781\" data-postid=\"1781\" class=\"themify_builder_content themify_builder_content-1781 themify_builder tf_clear\">\n    <\/div>\n<!--\/themify_builder_content-->","protected":false},"excerpt":{"rendered":"<p>Public Key is used to sign into something 1. Get certificate issued from CA Server asks for the public key CA. Servers send a new message which has their own public key, domain name to get a certificate from CA. This entire message is encrypted by using the public key of the CA. CA unlocks [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[97],"tags":[],"class_list":["post-1781","post","type-post","status-publish","format-standard","hentry","category-tech-learnings","has-post-title","has-post-date","has-post-category","has-post-tag","has-post-comment","has-post-author",""],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v24.3 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>TLS\/SSL Certificate Issuance &#187; Gaurav Wadhwani<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/gauravw.com\/blog\/2021\/04\/tls-ssl-certificate-issuance\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"TLS\/SSL Certificate Issuance &#187; Gaurav Wadhwani\" \/>\n<meta property=\"og:description\" content=\"Public Key is used to sign into something 1. Get certificate issued from CA Server asks for the public key CA. Servers send a new message which has their own public key, domain name to get a certificate from CA. This entire message is encrypted by using the public key of the CA. CA unlocks [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/gauravw.com\/blog\/2021\/04\/tls-ssl-certificate-issuance\/\" \/>\n<meta property=\"og:site_name\" content=\"Gaurav Wadhwani\" \/>\n<meta property=\"article:published_time\" content=\"2021-04-10T08:30:44+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-04-10T08:30:50+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/lh4.googleusercontent.com\/XLodYi2OUCrcUXyDbHCLN7zN7Ovr4nSOz-bc_A1LEN9KQDt1ELbGObgI8ErAmz32vfl7-syKF9dVKETyARkTyExTYbxAWzQh9BoPK5R4cSIEZWsTWDSHmfVquVUzv3XoVkHl7PSG\" \/>\n<meta name=\"author\" content=\"Gaurav Wadhwani\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Gaurav Wadhwani\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/gauravw.com\/blog\/2021\/04\/tls-ssl-certificate-issuance\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/gauravw.com\/blog\/2021\/04\/tls-ssl-certificate-issuance\/\"},\"author\":{\"name\":\"Gaurav Wadhwani\",\"@id\":\"https:\/\/gauravw.com\/blog\/#\/schema\/person\/9a05a9c3487f35f6b4577c6956cf252e\"},\"headline\":\"TLS\/SSL Certificate Issuance\",\"datePublished\":\"2021-04-10T08:30:44+00:00\",\"dateModified\":\"2021-04-10T08:30:50+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/gauravw.com\/blog\/2021\/04\/tls-ssl-certificate-issuance\/\"},\"wordCount\":355,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/gauravw.com\/blog\/#\/schema\/person\/9a05a9c3487f35f6b4577c6956cf252e\"},\"image\":{\"@id\":\"https:\/\/gauravw.com\/blog\/2021\/04\/tls-ssl-certificate-issuance\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/lh4.googleusercontent.com\/XLodYi2OUCrcUXyDbHCLN7zN7Ovr4nSOz-bc_A1LEN9KQDt1ELbGObgI8ErAmz32vfl7-syKF9dVKETyARkTyExTYbxAWzQh9BoPK5R4cSIEZWsTWDSHmfVquVUzv3XoVkHl7PSG\",\"articleSection\":[\"Tech Learnings\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/gauravw.com\/blog\/2021\/04\/tls-ssl-certificate-issuance\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/gauravw.com\/blog\/2021\/04\/tls-ssl-certificate-issuance\/\",\"url\":\"https:\/\/gauravw.com\/blog\/2021\/04\/tls-ssl-certificate-issuance\/\",\"name\":\"TLS\/SSL Certificate Issuance &#187; Gaurav Wadhwani\",\"isPartOf\":{\"@id\":\"https:\/\/gauravw.com\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/gauravw.com\/blog\/2021\/04\/tls-ssl-certificate-issuance\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/gauravw.com\/blog\/2021\/04\/tls-ssl-certificate-issuance\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/lh4.googleusercontent.com\/XLodYi2OUCrcUXyDbHCLN7zN7Ovr4nSOz-bc_A1LEN9KQDt1ELbGObgI8ErAmz32vfl7-syKF9dVKETyARkTyExTYbxAWzQh9BoPK5R4cSIEZWsTWDSHmfVquVUzv3XoVkHl7PSG\",\"datePublished\":\"2021-04-10T08:30:44+00:00\",\"dateModified\":\"2021-04-10T08:30:50+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/gauravw.com\/blog\/2021\/04\/tls-ssl-certificate-issuance\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/gauravw.com\/blog\/2021\/04\/tls-ssl-certificate-issuance\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/gauravw.com\/blog\/2021\/04\/tls-ssl-certificate-issuance\/#primaryimage\",\"url\":\"https:\/\/lh4.googleusercontent.com\/XLodYi2OUCrcUXyDbHCLN7zN7Ovr4nSOz-bc_A1LEN9KQDt1ELbGObgI8ErAmz32vfl7-syKF9dVKETyARkTyExTYbxAWzQh9BoPK5R4cSIEZWsTWDSHmfVquVUzv3XoVkHl7PSG\",\"contentUrl\":\"https:\/\/lh4.googleusercontent.com\/XLodYi2OUCrcUXyDbHCLN7zN7Ovr4nSOz-bc_A1LEN9KQDt1ELbGObgI8ErAmz32vfl7-syKF9dVKETyARkTyExTYbxAWzQh9BoPK5R4cSIEZWsTWDSHmfVquVUzv3XoVkHl7PSG\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/gauravw.com\/blog\/2021\/04\/tls-ssl-certificate-issuance\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/gauravw.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"TLS\/SSL Certificate Issuance\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/gauravw.com\/blog\/#website\",\"url\":\"https:\/\/gauravw.com\/blog\/\",\"name\":\"Gaurav Wadhwani\",\"description\":\"Where I write \/ scribble\",\"publisher\":{\"@id\":\"https:\/\/gauravw.com\/blog\/#\/schema\/person\/9a05a9c3487f35f6b4577c6956cf252e\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/gauravw.com\/blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\/\/gauravw.com\/blog\/#\/schema\/person\/9a05a9c3487f35f6b4577c6956cf252e\",\"name\":\"Gaurav Wadhwani\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/gauravw.com\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/88929454012064ffbe95370287faa36b?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/88929454012064ffbe95370287faa36b?s=96&d=mm&r=g\",\"caption\":\"Gaurav Wadhwani\"},\"logo\":{\"@id\":\"https:\/\/gauravw.com\/blog\/#\/schema\/person\/image\/\"},\"sameAs\":[\"http:\/\/gauravw.com\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"TLS\/SSL Certificate Issuance &#187; Gaurav Wadhwani","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/gauravw.com\/blog\/2021\/04\/tls-ssl-certificate-issuance\/","og_locale":"en_US","og_type":"article","og_title":"TLS\/SSL Certificate Issuance &#187; Gaurav Wadhwani","og_description":"Public Key is used to sign into something 1. Get certificate issued from CA Server asks for the public key CA. Servers send a new message which has their own public key, domain name to get a certificate from CA. This entire message is encrypted by using the public key of the CA. CA unlocks [&hellip;]","og_url":"https:\/\/gauravw.com\/blog\/2021\/04\/tls-ssl-certificate-issuance\/","og_site_name":"Gaurav Wadhwani","article_published_time":"2021-04-10T08:30:44+00:00","article_modified_time":"2021-04-10T08:30:50+00:00","og_image":[{"url":"https:\/\/lh4.googleusercontent.com\/XLodYi2OUCrcUXyDbHCLN7zN7Ovr4nSOz-bc_A1LEN9KQDt1ELbGObgI8ErAmz32vfl7-syKF9dVKETyARkTyExTYbxAWzQh9BoPK5R4cSIEZWsTWDSHmfVquVUzv3XoVkHl7PSG","type":"","width":"","height":""}],"author":"Gaurav Wadhwani","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Gaurav Wadhwani","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/gauravw.com\/blog\/2021\/04\/tls-ssl-certificate-issuance\/#article","isPartOf":{"@id":"https:\/\/gauravw.com\/blog\/2021\/04\/tls-ssl-certificate-issuance\/"},"author":{"name":"Gaurav Wadhwani","@id":"https:\/\/gauravw.com\/blog\/#\/schema\/person\/9a05a9c3487f35f6b4577c6956cf252e"},"headline":"TLS\/SSL Certificate Issuance","datePublished":"2021-04-10T08:30:44+00:00","dateModified":"2021-04-10T08:30:50+00:00","mainEntityOfPage":{"@id":"https:\/\/gauravw.com\/blog\/2021\/04\/tls-ssl-certificate-issuance\/"},"wordCount":355,"commentCount":0,"publisher":{"@id":"https:\/\/gauravw.com\/blog\/#\/schema\/person\/9a05a9c3487f35f6b4577c6956cf252e"},"image":{"@id":"https:\/\/gauravw.com\/blog\/2021\/04\/tls-ssl-certificate-issuance\/#primaryimage"},"thumbnailUrl":"https:\/\/lh4.googleusercontent.com\/XLodYi2OUCrcUXyDbHCLN7zN7Ovr4nSOz-bc_A1LEN9KQDt1ELbGObgI8ErAmz32vfl7-syKF9dVKETyARkTyExTYbxAWzQh9BoPK5R4cSIEZWsTWDSHmfVquVUzv3XoVkHl7PSG","articleSection":["Tech Learnings"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/gauravw.com\/blog\/2021\/04\/tls-ssl-certificate-issuance\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/gauravw.com\/blog\/2021\/04\/tls-ssl-certificate-issuance\/","url":"https:\/\/gauravw.com\/blog\/2021\/04\/tls-ssl-certificate-issuance\/","name":"TLS\/SSL Certificate Issuance &#187; Gaurav Wadhwani","isPartOf":{"@id":"https:\/\/gauravw.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/gauravw.com\/blog\/2021\/04\/tls-ssl-certificate-issuance\/#primaryimage"},"image":{"@id":"https:\/\/gauravw.com\/blog\/2021\/04\/tls-ssl-certificate-issuance\/#primaryimage"},"thumbnailUrl":"https:\/\/lh4.googleusercontent.com\/XLodYi2OUCrcUXyDbHCLN7zN7Ovr4nSOz-bc_A1LEN9KQDt1ELbGObgI8ErAmz32vfl7-syKF9dVKETyARkTyExTYbxAWzQh9BoPK5R4cSIEZWsTWDSHmfVquVUzv3XoVkHl7PSG","datePublished":"2021-04-10T08:30:44+00:00","dateModified":"2021-04-10T08:30:50+00:00","breadcrumb":{"@id":"https:\/\/gauravw.com\/blog\/2021\/04\/tls-ssl-certificate-issuance\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/gauravw.com\/blog\/2021\/04\/tls-ssl-certificate-issuance\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/gauravw.com\/blog\/2021\/04\/tls-ssl-certificate-issuance\/#primaryimage","url":"https:\/\/lh4.googleusercontent.com\/XLodYi2OUCrcUXyDbHCLN7zN7Ovr4nSOz-bc_A1LEN9KQDt1ELbGObgI8ErAmz32vfl7-syKF9dVKETyARkTyExTYbxAWzQh9BoPK5R4cSIEZWsTWDSHmfVquVUzv3XoVkHl7PSG","contentUrl":"https:\/\/lh4.googleusercontent.com\/XLodYi2OUCrcUXyDbHCLN7zN7Ovr4nSOz-bc_A1LEN9KQDt1ELbGObgI8ErAmz32vfl7-syKF9dVKETyARkTyExTYbxAWzQh9BoPK5R4cSIEZWsTWDSHmfVquVUzv3XoVkHl7PSG"},{"@type":"BreadcrumbList","@id":"https:\/\/gauravw.com\/blog\/2021\/04\/tls-ssl-certificate-issuance\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/gauravw.com\/blog\/"},{"@type":"ListItem","position":2,"name":"TLS\/SSL Certificate Issuance"}]},{"@type":"WebSite","@id":"https:\/\/gauravw.com\/blog\/#website","url":"https:\/\/gauravw.com\/blog\/","name":"Gaurav Wadhwani","description":"Where I write \/ scribble","publisher":{"@id":"https:\/\/gauravw.com\/blog\/#\/schema\/person\/9a05a9c3487f35f6b4577c6956cf252e"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/gauravw.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":["Person","Organization"],"@id":"https:\/\/gauravw.com\/blog\/#\/schema\/person\/9a05a9c3487f35f6b4577c6956cf252e","name":"Gaurav Wadhwani","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/gauravw.com\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/88929454012064ffbe95370287faa36b?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/88929454012064ffbe95370287faa36b?s=96&d=mm&r=g","caption":"Gaurav Wadhwani"},"logo":{"@id":"https:\/\/gauravw.com\/blog\/#\/schema\/person\/image\/"},"sameAs":["http:\/\/gauravw.com"]}]}},"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"","builder_content":"","_links":{"self":[{"href":"https:\/\/gauravw.com\/blog\/wp-json\/wp\/v2\/posts\/1781","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/gauravw.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/gauravw.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/gauravw.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/gauravw.com\/blog\/wp-json\/wp\/v2\/comments?post=1781"}],"version-history":[{"count":1,"href":"https:\/\/gauravw.com\/blog\/wp-json\/wp\/v2\/posts\/1781\/revisions"}],"predecessor-version":[{"id":1782,"href":"https:\/\/gauravw.com\/blog\/wp-json\/wp\/v2\/posts\/1781\/revisions\/1782"}],"wp:attachment":[{"href":"https:\/\/gauravw.com\/blog\/wp-json\/wp\/v2\/media?parent=1781"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/gauravw.com\/blog\/wp-json\/wp\/v2\/categories?post=1781"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/gauravw.com\/blog\/wp-json\/wp\/v2\/tags?post=1781"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}