【文章內(nèi)容簡介】
–gets Bob’s certificate (Bob or elsewhere). –apply CA’s public key to Bob’s certificate, get Bob’s public key Bob’s public key PK B digital signature (decrypt) CA public key PK CA PK B Computer Science Verify the Public Key of a Web Server ? The web browser has CA’s public key built in. ? In practice, there could have several trusted CAs for each web browser ? New CAs can also be installed by users ? The legitimacy of the web browser software bees crucial for ensuring the security of digital certificates ? A certificate is NO more secure than the security of the web browser download site ? Exercise: find out the information of three preinstalled CAs in Inter Explorer Web Browser Inter Web Server (PK, SK) Cert = IDserver, PK, Expiry, SignCA(…) Computer Science Preinstalled CAs Public Key: (RSA 1024bit) 30 81 89 02 81 81 00 cc 5e d1 11 5d 5c 69 d0 ab d3 b9 6a 4c 99 1f 59 98 30 8e 16 85 20 46 6d 47 3f d4 85 20 84 e1 6d b3 f8 a4 ed 0c f1 17 0f 3b f9 a7 f9 25 d7 c1 cf 84 63 f2 7c 63 cf a2 47 f2 c6 5b 33 8e 64 40 04 68 c1 80 b9 64 1c 45 77 c7 d8 6e f5 95 29 3c 50 e8 34 d7 78 1f a8 ba 6d 43 91 95 8f 45 57 5e 7e c5 fb ca a4 04 eb ea 97 37 54 30 6f bb 01 47 32 33 cd dc 57 9b 64 69 61 f8 9b 1d 1c 89 4f 5c 67 02 03 01 00 01 Computer Science A Certificate Use r Na m eCe r t if ica t e V e r sio nV a li d ity P e r io dS e r ia l NoUse r 39。s P u b li c K e yO t h e r u se r a t t r ib u t e sCA 39。s n a m eCA 39。s sig n a t u r e ( o f a ll t h e a b o v e ). User Name: Certificate Version: V3 Validity Period: Jan 28, 05 – Jan 29, 06 Serial No: 4b5c94d17508e86594593d777e4d7dc4 User’s Public Key: RSA (1024 bits) 30 8