x.509证书
X.509 是密碼學里公鑰證書的格式標準。 X.509 證書己應用在包括TLS/SSL在內的眾多 Intenet協議里.同時它也用在很多非在線應用場景里,比如電子簽名服務。X.509證書里含有公鑰、身份信息(比如網絡主機名,組織的名稱或個體名稱等)和簽名信息(可以是證書簽發機構CA的簽名,也可以是自簽名)。對于一份經由可信的證書簽發機構簽名或者可以通過其它方式驗證的證書,證書的擁有者就可以用證書及相應的私鑰來創建安全的通信,對文檔進行數字簽名.
可以通過在瀏覽器里導出獲得:
用記事本打開這個base64 encode的509證書:
When using SSL/TLS to protect network communication, the server of the communication scenario is typically authenticated by an X.509 certificate, and there is a convention to identify the server by matching the server hostname from the connection parameters (such as the URL) to name attributes in the certificate. This matching is called “server endpoint identification”, and was first described in Section 3.1 of rfc2818 “HTTP over TLS” based on the behaviour implemented in common web browsers at the time. Similar checking of server endpoint identification has been adopted by other protocols that use TLS, and has been described in rfc6125.
要獲取更多Jerry的原創文章,請關注公眾號"汪子熙":
總結
- 上一篇: Cloud for Customer的前
- 下一篇: 特斯拉 Cybertruck 皮卡车雨刮