certificates and PKI question


hi all,

i trying better understand certificates , pki.

i totally understand how certificates work , totally understand how pki works have been doing reading morning certificates , pki think have got myself confused.

ok . . if go internet explorer > internet options > tools > content > certificates see number of tabs - personal - other people - intermediate certificate authorities - trusted root certificate authorities - can see lots of vendors certificates in list under trusted root certificate authorities. if go website such paypal (who secure , use certificate) certificate appear? downloaded computer or not? understand certificate holds public key not understand certificate , comes from?

why internet explorer hold certificates people verisign? thought verisign ca issue certificates people such paypal. don't quite understand why cas have certificates listed within interne explorer.

sorry if explanation isn't clear . . . can me understand above?

thanks

> example if go paypal , explorer bar turns green, can click , view cert explorer bar can see downloaded cert?

in web browser, obviously. downloaded memory , linked context handle current ssl sesstion. not installed anywhere.

> these certs in list?

these trusted root certificates , used establish trust certificates , chains.


my weblog: http://en-us.sysadmins.lv
powershell pki module: http://pspki.codeplex.com
check out new: powershell fciv tool.



Windows Server  >  Security



Comments

Popular posts from this blog

some help on Event 540

WMI Repository 4GB limit - Win 2003 Ent Question

Event ID 1302 (error 1307) DFS replication service encountered an error while writing to the debug log file