PKI Bootcamp - Basics of Certificate Issuance

Sdílet
Vložit
  • čas přidán 6. 03. 2017
  • This video provides a high level look at how certificates are signed and a certificate chain is created.

Komentáře • 39

  • @AliBaba-vw7mo
    @AliBaba-vw7mo Před 4 lety +2

    So far, I have not seen a single video that explains so far up the trust chain. Thanks!

  • @chandankundapur
    @chandankundapur Před 3 lety +3

    Echo what everyone else has mentioned here . Extremely useful . Thanks much Paul for your time in creating these videos

    • @PaulTurnerChannel
      @PaulTurnerChannel  Před 3 lety +1

      Thank you for taking the time to give your positive feedback, Chandan. I really appreciate it.

  • @vak21
    @vak21 Před 4 lety +6

    Excellent explanation, clear, detailed, and covering many open questions that had been bothering me for a long time.

    • @PaulTurnerChannel
      @PaulTurnerChannel  Před 4 lety

      Thank you very much for the feedback, Jose. I really appreciate it.

  • @GNSK3
    @GNSK3 Před 8 měsíci

    Thank you so much. Great explanation.

  • @eddierouth
    @eddierouth Před 4 lety +2

    Explained very well, loved your way of teaching .. please add more videos. Appreciate for your effort Paul.

    • @PaulTurnerChannel
      @PaulTurnerChannel  Před 4 lety

      Thanks for taking the time to provide your feedback, Indranil. I hope yo do a few more videos soon.

  • @irfan_b5186
    @irfan_b5186 Před 3 lety +1

    Fantastic work Paul.. really appreciated

    • @PaulTurnerChannel
      @PaulTurnerChannel  Před 3 lety

      I'm glad you like it, Irfan. Thanks for taking the time to write a comment!

  • @TheGPification
    @TheGPification Před 7 lety

    very well explained, Paul!

  • @maurod6180
    @maurod6180 Před 3 lety +1

    THANK YOU!!!!! thank you very much!

  • @jesuschrist5405
    @jesuschrist5405 Před 9 měsíci +1

    Excellent master for PKI

  • @abhishekyadav0007
    @abhishekyadav0007 Před 6 lety

    Thanks again Paul..well explained

    • @PaulTurnerChannel
      @PaulTurnerChannel  Před 6 lety

      Thank you very much, Abhishek. I hope to get more videos out soon (been too busy with the day job :)

  • @AxelSchwab94
    @AxelSchwab94 Před 3 lety +1

    thank you for your effort, really cool; how has you made the animations?

    • @PaulTurnerChannel
      @PaulTurnerChannel  Před 3 lety +1

      Thanks for your feedback. I use PowerPoint.

    • @AxelSchwab94
      @AxelSchwab94 Před 3 lety

      Paul Turner nice than we have the same Approach to explain thinge, but you habe the cooler pp

  • @frankkolmann4801
    @frankkolmann4801 Před 3 lety +1

    I have never trusted public/private keys, simply because how private can you make a key private. Government level security agencies can simply say give us your private keys and BOOM nothing is secure. Thanks for the video.

    • @PaulTurnerChannel
      @PaulTurnerChannel  Před 3 lety

      Hi, Frank. You bring up a fairly complicated but important topic. I believe we can trust private keys (as a technology). There are risks related to the security of private keys, however, I believe those risks exist with any technology, and even with data itself. For example, even if I could prevent a government agency from getting access to the TLS private key(s) I use to protect my data, the government can simple tell me to give them the data. If I store the private key(s) in a FIPS hardware device, I may be able to protect them better but then the thing I need to protect is the credentials I use to access the device. I’m providing a bit of an abbreviated response but hope that helps. Thanks a bunch for your comment.

  • @CKZA10
    @CKZA10 Před 3 lety +2

    Hi Paul and everyone. I was looking at the X509 RFC (5280) and was wondering if your CA1 can be called the Registration Authority?

    • @PaulTurnerChannel
      @PaulTurnerChannel  Před 3 lety +1

      Sorry for the slow response. The actual CA at CA1 can’t be called an RA because it is signing certificates. RAs do not sign certs. However, the RA function is often performed as part of the CA organization. For example, if CA1, Inc. is running a CA, they will perform the RA function to validate that all requesters are authorized to request certs for their domains. CA1, Inc. acts as both the CA and RA.
      The most common case where the RA function is separate is when a corporation is requesting certs for their sub domains. For example, Corp1 goes to CA1, Inc. and says they want to issue certs for a bunch of severs under corp1.com. CA1 acts as the RA to confirm that Corp1 owns corp1.com. Then, if a user at Corp1 requests a cert for finance.corp1.com, an admin at Corp1 will review and approve the request in the CA1 console. In this case, CA1, Inc is the CA and Corp1 is the RA. Hope that helps.

    • @CKZA10
      @CKZA10 Před 3 lety

      @@PaulTurnerChannel Thanks Paul. The drawing in the RFC stated that the RA "publishes cert" so I assumed wrongly its function or intent. All clear now. I'm studying ISAKMP now for CCNP and came upon your excellent videos (which helped on the certificate aspect). Reall appreciate your time with this.
      Do you know by chance where I can get more details on COOKIES in IKEv1 Phase 1? Way off topic but at the end of Phase 1 IKEv1 there's SKEYID and SKEYID_e,d,a. It's generated using DH(secret) and then it says CKY_I and CKY_R (cookie initiator and responder). I can't seem to find an "English" explanation on what the cookies consist of lol.

  • @UmerShabibMohd
    @UmerShabibMohd Před 5 lety

    Could you share the PDf of the slide

    • @PaulTurnerChannel
      @PaulTurnerChannel  Před 5 lety

      Hi, Umer. I'm not aware of a way to attach the file to CZcams video for download. Since this is technically Venafi content, I'm checking with them to see how it can be made available. I'm glad that it is useful enough that you'd like the PDF. Thanks for reaching out.

    • @PaulTurnerChannel
      @PaulTurnerChannel  Před 5 lety

      Umer, sorry for the delay in getting back to you. The PDF has been uploaded to following address (updated with the newer Venafi PPT template :):
      www.venafi.com/resource/pki-bootcamp-basics-of-certificate-issuance-presentation
      Please confirm that you are able to access it.

    • @basantsherwida4586
      @basantsherwida4586 Před rokem

      @@PaulTurnerChannel thanks for sharing the slides , but the access to it is denied via your link :(

    • @PaulTurnerChannel
      @PaulTurnerChannel  Před rokem

      Umer, the slides were shared with you three years ago. I am no longer with Venafi and I assume they’ve taken that link down. Sorry.

    • @basantsherwida4586
      @basantsherwida4586 Před rokem

      that's fine, no matter.
      its a great series videos by the way

  • @JeremyMcBane
    @JeremyMcBane Před 4 lety +2

    3/13/37 I see what you did there

  • @chrisadams27
    @chrisadams27 Před 2 lety +1

    Guys with guns? Please...

    • @PaulTurnerChannel
      @PaulTurnerChannel  Před 2 lety

      Haha. I guess I do have a flair for the dramatic every once in a while. Good catch 😀

    • @chrisadams27
      @chrisadams27 Před 2 lety

      @@PaulTurnerChannel great vid though, thanks

    • @PaulTurnerChannel
      @PaulTurnerChannel  Před 2 lety

      Thanks, Chris. I’m glad you liked it.