Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesA public key certificate is a digitally signed data structure that links an entity’s identifier to a public key. It is not the private key. In the Internet’s X.509 certificate system, an issuer signs the certificate’s contents to attest to that link; a device must still check the certificate’s chain, validity, status and suitability before relying on it.
What a public key certificate does
RFC 4949 defines a public-key certificate as a digital certificate that binds a system entity’s identifier to a public-key value, possibly with additional data, in a digitally signed structure that attests to ownership of the public key. In practical terms, the certificate lets another system associate a public key with a named subject, such as a server or person.
As an Amazon Associate I earn from qualifying purchases.
The certificate contains the public key and identifying information, not the matching private key. The private key is a separate item and must remain under its owner’s control. A certificate itself is not secret and can be distributed publicly.
Recommended Free Tools
What an X.509 certificate contains
X.509 is the familiar certificate format used by the Internet PKI. Its outer structure has three parts: tbsCertificate, the certificate information to be signed; signatureAlgorithm, which identifies the signing algorithm; and signatureValue, the resulting signature. The signed information typically includes:
#1 Best Overall
- Version and serial number
- Issuer and subject
- Validity period
- Subject public-key information
- Optional extensions, when present in a version 3 certificate
The issuer’s signature covers the signed information, including the association between the subject and public key. For the X.509 Internet profile and its field definitions, see the RFC 5280 certificate profile. The glossary definition appears in RFC 4949.
What the certificate signature proves—and what it does not
Verifying the signature shows that the signed certificate contents were signed by the corresponding issuer key and have not been altered without detection. It does not, by itself, mean that a client should trust the certificate, that the issuer’s identity checks meet every application’s expectations, or that the subject is a particular real-world person or organization.
Rank #2
A client separately performs certification-path validation: it checks the chain of certificates leading to a trust anchor configured in that system, along with applicable constraints, policy and intended use. Trust is therefore conditional on the verifier’s configuration and rules, not simply on the presence of a valid signature.
Validity and revocation
An X.509 certificate has a notBefore and notAfter time, defining its stated validity interval. That interval is not the only status check: a certificate can be revoked before its end date. RFC 5280 describes revocation reasons including a changed relationship between the subject and certificate authority, or compromise or suspected compromise of the associated private key. One X.509 mechanism for publishing revoked certificates is a signed certificate revocation list (CRL).
Rank #3
Certificate authorities and end entities
X.509 distinguishes certificates that can issue other certificates from those that cannot. A CA certificate belongs to a certificate authority and may be authorized to issue certificates subject to its constraints. An end-entity certificate belongs to a subject that is not authorized to issue certificates. Other terms include self-issued and self-signed certificates; those describe issuance or signing relationships, not automatic trustworthiness.
Quick Recap
Best Value
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




