当前位置:网站首页>Is the validity period of the root certificate as long as the server SSL certificate?
Is the validity period of the root certificate as long as the server SSL certificate?
2022-07-24 18:23:00 【Racent_ Y】
In the solution root certificate and server SSL You have to know what they are before the certificate is valid .
What is a root certificate ?
Root certificate means CA Issued by the agency SSL The core of the certificate , It's the starting point of the chain of trust . Every browser has a root Library , Some browsers use their own root certificate Library , Some browsers use third-party root certificate libraries . The root certificate library is a collection of pre loaded root certificates when downloading the client browser . Therefore, the root certificate is very important , Because it ensures that the browser automatically trusts those signed with the private key SSL certificate .
What is a server SSL certificate ?
SSL Server certificate It is a digital certificate configured on the server , It obeys SSL agreement , Through a trusted digital certification authority CA, Issue after the server authentication passes , It has the functions of server authentication and data transmission encryption .
CA The organization will not directly use the root certificate issuance server SSL certificate , Because this operation has risks . If an error occurs and the root certificate needs to be revoked , Then each certificate signed with the root certificate will not be trusted . So the intermediate certificate is created .CA Have many intermediate certificates , But the number of root certificates is relatively limited , Xiaobian guess is also for the convenience of management 、 And store it in browsers and devices .
Root certificate and SSL How long is the certificate valid ?

( Screenshot of the validity period of root certificate and intermediate certificate )
We check the validity of the website security certificate , Generally, you can directly click the security lock next to the address bar to see the website SSL The validity of the certificate .
But check this SSL The validity period of the root certificate and Intermediate Certificate in the certificate chain , It can be used SSL Certificate testing Tools , You can see the complete certificate chain information , Including the length of their validity . Pictured above ,AAA Certificate Services The validity of the root certificate is about 10 year , Intermediate certificates are also 10 year , The remaining duration is attached . And the server used by the final website SSL The validity period of the certificate is 1 A little over a year . Why 1 A little over a year ? The reason lies in CA/B The latest regulations of the Forum SSL The validity period of the certificate cannot exceed 398 God , part CA yes 1 The term of validity of years , Then there was a gift 30 Days , such as sslTrus.
Either way CA Issued by SSL certificate , Both the root certificate and the intermediate certificate are valid longer than the final SSL Length of certificate . The validity period of root certificate and intermediate certificate is generally 10 year , and SSL The validity period of the certificate is 1 year , To shorten the SSL The purpose of the validity of the certificate is to improve the security of the website . This is also the server SSL The function of certificate !
边栏推荐
- Use of jumpserver
- 2022 the latest short video de watermarking analysis API interface sharing
- Several sorting methods for while and sort
- Pytoch's journey 1: linear model
- ES6 cycle filter value
- 无关的表进行关联查询及null=null条件
- Flatten array.Flat (infinity)
- [record of question brushing] 20. Valid brackets
- Get the original data API on 1688app
- Ship new idea 2022.2 was officially released, and the new features are really fragrant!
猜你喜欢

In depth analysis of the famous Alibaba cloud log4j vulnerability

Wechat applet

继承与派生

pycharm配置opencv库

Shanghai Jiaotong University team used joint deep learning to optimize metabonomics research

模拟实现vector

jmeter --静默运行

Laravel笔记-用户登录时密码进行RSA加密(提高系统安全性)

初识Pytorch和Pytorch环境配置

The 5th Digital China Construction summit opened in Fuzhou, Fujian
随机推荐
Flatten array.Flat (infinity)
["code" power is fully open, and "chapter" shows strength] list of contributors to the task challenge in the first quarter of 2022
Wechat applet
4. Basic type and reference type?
JS to achieve progress steps (small exercise)
In depth analysis of the famous Alibaba cloud log4j vulnerability
剑指 Offer 21. 调整数组顺序使奇数位于偶数前面
undefined reference to H5PTopen
缺失值处理
mysql 配置文件
Go language interface and type
Growth of operation and maintenance Xiaobai - week 8 of Architecture
undefined reference to H5PTopen
Techempower web framework performance test 21st round results release --asp Net core continue to move forward
数组扁平化.flat(Infinity)
Go to bed capacity exchange
如何为超级通胀做好准备
Alibaba /166 obtains the API instructions for all products in the store
Emerging potential of interactive virtual reality technology in drug discovery
Section 9 cache penetration follow Daewoo redis ------- directory posts