Security Protocols Part 9 SSL Protocol
Recap • Digital Certificate – Authentication – Integrity – Non-repudiation • CA (Certification Authority) – Issue digital certificates (via digital signature) – Publish/Distribute digital certificates, help verify – Revoke digital certificates • Key Exchange Protocol (Diffie-Hellman, 2 primes)
Successful SSL = padlock
Padlock = layman’s icon for session security*
Getting into the details of a server certificate
Leaf-CA
Intermediate-CA
Certificate Details: Cert Extension SAN
Certificate Details: Cert Extension CRL, OCSP
Root-CA
Broken padlock = ?
Exercise • Write the SSL protocol in the notations we used to describe earlier protocols – A digital certificate issued by Sam to Alice is denoted by {A, S, K A , V, E}k S – You may skip notations for “certificate validity – V” and “certificate extension – E” and their implications – Make use of Diffie-Hellman Key Exchange Protocol
Recommend
More recommend