ArticleslgStudy

engineering

Root certificate

Root certificate is a engineering topic covered in the lgStudy science library. This page brings together a partial reference excerpt, illustrations, worked examples, real-world applications and a short study plan, so you can understand Root certificate rather than just read about it. In short: In cryptography and computer security, a root certificate is a public key certificate that identifies a root certificate authority (CA). Root certificates are self-signed (and it is possible for a certificate to have multiple trust paths, say if the certificate was issued by a root that was cross-signed) and form the basis of an X.509-based public key infrastructure (PKI).

Root certificate — main illustration
Root certificate — illustration

Key takeaways

  • Root certificate belongs to engineering; place it in that map before memorising details.
  • Learn the definition first, then one example that makes the definition concrete.
  • Connect Root certificate to a quantity you can measure, compute or draw — that is where exam questions come from.
  • Reproduce the core statement of Root certificate from memory before moving on to harder problems.

Reference excerpt

In cryptography and computer security, a root certificate is a public key certificate that identifies a root certificate authority (CA). Root certificates are self-signed (and it is possible for a certificate to have multiple trust paths, say if the certificate was issued by a root that was cross-signed) and form the basis of an X.509-based public key infrastructure (PKI). Either it has matched Authority Key Identifier with Subject Key Identifier, in some cases there is no Authority Key identifier, then Issuer string should match with Subject string (RFC 5280). For instance, the PKIs supporting HTTPS for secure web browsing and electronic signature schemes depend on a set of root certificates. A certificate authority can issue multiple certificates in the form of a tree structure. A root certificate is the top-most certificate of the tree, the private key which is used to "sign" other certificates. All certificates signed by the root certificate, with the "CA" field set to true, inherit the trustworthiness of the root certificate—a signature by a root certificate is somewhat analogous to "notarizing" identity in the physical world. Such a certificate is called an intermediate certificate or subordinate CA certificate. Certificates further down the tree also depend on the trustworthiness of the intermediates. The root certificate is usually made trustworthy by some mechanism other than a certificate, such as by secure physical distribution. For example, some of the best-known root certificates are distributed in operating systems by their manufacturers. Microsoft distributes root certificates belonging to members of the Microsoft Root Certificate Program to Windows desktops and Windows Phone 8. Apple distributes root certificates belonging to members of its own root program.

Incidents of root certificate misuse

DigiNotar hack of 2011

In 2011, the Dutch certificate authority DigiNotar suffered a security breach. This led to the issuing of various fraudulent certificates, which was among others abused to target Iranian Gmail users. The trust in DigiNotar certificates was retracted and the operational management of the company was taken over by the Dutch government.

China Internet Network Information Center (CNNIC) issuance of fake certificates

In 2009, an employee of the China Internet Network Information Center (CNNIC) applied to Mozilla to add CNNIC to Mozilla's root certificate list and was approved. Later, Microsoft also added CNNIC to the root certificate list of Windows. In 2015, many users chose not to trust the digital certificates issued by CNNIC because an intermediate CA issued by CNNIC was found to have issued fake certificates for Google domain names and raised concerns about CNNIC's abuse of certificate issuing power. On April 2, 2015, Google announced that it no longer recognized the electronic certificate issued by CNNIC. On April 4, following Google, Mozilla also announced that it no longer recognized the electronic certificate issued by CNNIC.

WoSign and StartCom: Issuing fake and backdated certificates

In 2016, WoSign, China's largest CA certificate issuer owned by Qihoo 360 and its Israeli subsidiary StartCom, were denied recognition of their certificates by Google. Microsoft removed the relevant certificates in 2017. WoSign and StartCom issued hundreds of certificates with the same serial number in just five days, as well as issuing backdated certificates. In 2016, a system administrator in Florida was able to get WoSign and StartCom to issue fake certificates for multiple GitHub domains.

See also Online Certificate Status Protocol (OCSP) Superfish SHA-1 Timestamp Verisign Google and Symantec clash on website security checks

References

Illustrations

Root certificate: The role of root certificate as in the chain of trust.
The role of root certificate as in the chain of trust.
Root certificate: Example of a DigiCert root certificate
Example of a DigiCert root certificate

Worked examples

Example 1 — a first encounter with Root certificate

Start with the simplest possible case. Write down what Root certificate claims or describes in one sentence, then invent the smallest concrete situation in which that sentence is true. In engineering, the smallest case is usually a single object, a single equation or a single measurement. Check that every symbol or term in your sentence has a meaning in that case.

Example 2 — changing one variable

Take the situation from Example 1 and change exactly one quantity: double it, halve it, or set it to zero. Predict what should happen to Root certificate before you calculate. Comparing your prediction with the result is the fastest way to find out whether you understand the idea or only the words.

Example 3 — an exam-style question

Typical questions about Root certificate ask you to (a) state it precisely, (b) apply it to given data, and (c) explain a limitation. Practise writing all three answers in under five minutes; the third part is what separates a full-mark answer from an average one.

Applications of Root certificate

In research
Root certificate appears in engineering research whenever the underlying quantities have to be modelled precisely. Papers usually cite it as a starting assumption and then explore where it breaks down.
In technology and industry
Engineering practice reuses Root certificate in design rules, simulations and safety margins. Knowing the idea lets you read a specification sheet and understand why the numbers look the way they do.
In the classroom
Root certificate is common in secondary-school and first-year university syllabi. It links to neighbouring topics Public key infrastructure, Transport Layer Security, so understanding it makes those chapters shorter.
In everyday life
Look for Root certificate outside the textbook — in sport, cooking, traffic, electronics or the sky above you. An example you found yourself is remembered far longer than one you were given.

Affiliate

Preply — study more efficiently by working with a personal tutor. 50% off.

How to study Root certificate in 20 minutes

  1. Read the reference excerpt below once, without taking notes.
  2. Close the page and write down what Root certificate means in your own words.
  3. Compare your version with the excerpt and mark what you missed.
  4. Work through the three examples above with pen and paper.
  5. Explain Root certificate out loud to somebody else — or to Teacher Smith in the lgStudy chat.

Frequently asked questions

What is Root certificate in simple terms?

In cryptography and computer security, a root certificate is a public key certificate that identifies a root certificate authority (CA). Root certificates are self-signed (and it is possible for a certificate to have multiple trust paths, say if the certificate was issued by a root that was cross-s…

Why does Root certificate matter?

Because it connects several engineering ideas at once: it gives you a definition you can apply, a quantity you can calculate, and a way to check whether a result is plausible.

How should I study Root certificate?

Read the excerpt, restate it from memory, then work through the examples and applications listed on this page. The five-step study plan above takes about twenty minutes.

What does this page cover?

It gives you a compact reference excerpt plus original lgStudy explanations, examples, applications and study material on Root certificate.

Tags

  • Public key infrastructure
  • Transport Layer Security

Keep exploring