当前位置:网站首页>Is the validity period of the root certificate as long as the server SSL certificate?
Is the validity period of the root certificate as long as the server SSL certificate?
2022-07-24 18:23:00 【Racent_ Y】
In the solution root certificate and server SSL You have to know what they are before the certificate is valid .
What is a root certificate ?
Root certificate means CA Issued by the agency SSL The core of the certificate , It's the starting point of the chain of trust . Every browser has a root Library , Some browsers use their own root certificate Library , Some browsers use third-party root certificate libraries . The root certificate library is a collection of pre loaded root certificates when downloading the client browser . Therefore, the root certificate is very important , Because it ensures that the browser automatically trusts those signed with the private key SSL certificate .
What is a server SSL certificate ?
SSL Server certificate It is a digital certificate configured on the server , It obeys SSL agreement , Through a trusted digital certification authority CA, Issue after the server authentication passes , It has the functions of server authentication and data transmission encryption .
CA The organization will not directly use the root certificate issuance server SSL certificate , Because this operation has risks . If an error occurs and the root certificate needs to be revoked , Then each certificate signed with the root certificate will not be trusted . So the intermediate certificate is created .CA Have many intermediate certificates , But the number of root certificates is relatively limited , Xiaobian guess is also for the convenience of management 、 And store it in browsers and devices .
Root certificate and SSL How long is the certificate valid ?

( Screenshot of the validity period of root certificate and intermediate certificate )
We check the validity of the website security certificate , Generally, you can directly click the security lock next to the address bar to see the website SSL The validity of the certificate .
But check this SSL The validity period of the root certificate and Intermediate Certificate in the certificate chain , It can be used SSL Certificate testing Tools , You can see the complete certificate chain information , Including the length of their validity . Pictured above ,AAA Certificate Services The validity of the root certificate is about 10 year , Intermediate certificates are also 10 year , The remaining duration is attached . And the server used by the final website SSL The validity period of the certificate is 1 A little over a year . Why 1 A little over a year ? The reason lies in CA/B The latest regulations of the Forum SSL The validity period of the certificate cannot exceed 398 God , part CA yes 1 The term of validity of years , Then there was a gift 30 Days , such as sslTrus.
Either way CA Issued by SSL certificate , Both the root certificate and the intermediate certificate are valid longer than the final SSL Length of certificate . The validity period of root certificate and intermediate certificate is generally 10 year , and SSL The validity period of the certificate is 1 year , To shorten the SSL The purpose of the validity of the certificate is to improve the security of the website . This is also the server SSL The function of certificate !
边栏推荐
- 可撤销并查集板子
- CF. Bits And Pieces(子集状压dp + 剪枝)
- Alibaba 1688 keyword search product API usage display
- CF Lomsat gelral(启发式合并)
- 运维小白成长记——架构第8周
- 13 essential methods of color!
- web渗透经验汇总ing
- [record of question brushing] 20. Valid brackets
- In depth analysis of the famous Alibaba cloud log4j vulnerability
- Introduction and use of Pinia
猜你喜欢

Number of times a number appears in an ascending array

Use of jumpserver

redis集群的三种方式

下拉列表组件使用 iScroll.js 实现滚动效果遇到的坑

Go language file operation
![[OBS] dependency Library: x264 vs Build](/img/24/4caea5dc6ff092a3161f43b6026d25.png)
[OBS] dependency Library: x264 vs Build

["code" power is fully open, and "chapter" shows strength] list of contributors to the task challenge in the first quarter of 2022

Wechat applet

JumpServer的使用

pycharm配置opencv库
随机推荐
[record of question brushing] 20. Valid brackets
Show or hide password plaintext + password box verification information
Typora 它依然是我心中的YYDS 最优美也是颜值最高的文档编辑神器 相信你永远不会抛弃它
球面上绘制圆matlab仿真
Go to bed capacity exchange
剑指 Offer 21. 调整数组顺序使奇数位于偶数前面
Baidu touch.js
Four ways of simple interest mode
【校验】只能输入数字(正负数)
Number of times a number appears in an ascending array
【obs】视频、音频编码与rtmp发送的配合
空间三点画圆代码
6. How to add an array in Es5?
Shanghai Jiaotong University team used joint deep learning to optimize metabonomics research
Namespace:集群环境共享与隔离
CF lomsat gelral (heuristic merge)
2022最新短视频去水印解析API接口分享
pycharm配置opencv库
如何用WebGPU流畅渲染百万级2D物体?
5. Reference type and value type as function parameters?