What security services does SSL certificate provide?
發佈時間:2022-05-07
-
瀏覽次數:236次
- As we all know, installing SSL certificate on website has become one of the important security protection means in the process of Internet information transmission. Do you know what security services SSL certificates can provide? What is the working process of SSL certificate?The following is an introduction to the security services provided by SSL:① SSL server authenticationAllows the user to authenticate the server. The client supporting SSL authenticates the real identity of the server and obtains the public key of the server by verifying the certificate from the server.② SSL client authenticationSSL's optional security service allows the server to verify the identity of the client.③ Encrypted SSL sessionEncrypt all messages sent by customers and during service, and detect whether the messages are tampered with.What is the working process of SSL certificate?When visitors visit the website link with SSL certificate installed and establish a TCP connection, first carry out the handshake protocol between the browser and the server, complete the negotiation of encryption algorithm and the transmission of session key, and then carry out secure data transmission.The whole process is as follows:① Negotiation encryption algorithmBrowser a sends the SSL version number of the browser and some optional encryption algorithms to server B, from which B selects the algorithms it supports (such as RSA) and tells a.② Server authenticationServer B sends a digital certificate containing its RSA public key to browser a, and a uses the RSA public key publicly published by the Certification Authority CA of the certificate to verify the certificate.③ Session key calculationBrowser a randomly generates a secret number, encrypts it with the RSA public key of server B and sends it to B. both parties generate a shared symmetric session key according to the negotiated algorithm.④ Secure data transmissionBoth parties use the session key to encrypt and decrypt the data transmitted between them and verify its integrity.
搜索