---
tags:
- networking
- l1
- flashcard-deck
- tls
---
<!-- wiki:breadcrumb:start -->
[Portal](../../../../library/portal/index.md) | **Level:** [L1: Foundations](../../../../library/portal/levels.md) | **Topics:** [TLS & PKI](../../../../library/portal/topics.md) | **Domain:** Networking
<!-- wiki:breadcrumb:end -->

id	category	difficulty	tags	question	answer	source_path
tls/5e5fe50b6e2c	tls	easy	tls, certificates, chain	What is a certificate chain and why must the server send intermediate certificates?	A certificate chain goes: Root CA (trusted by OS) -> Intermediate CA -> Leaf/Server cert. The server must send the leaf plus intermediates because the client only has root CAs in its trust store. Missing intermediates is the #1 cause of "works in browser but fails in curl."	training/library/topics/tls-certificates-ops/primer.md
tls/73da126fc125	tls	easy	tls, openssl, debugging	How do you test a TLS connection and view the certificate chain using openssl?	openssl s_client -connect example.com:443 -servername example.com. This shows the full TLS handshake, certificate chain, negotiated cipher, and TLS version. Add 2>/dev/null | openssl x509 -text -noout to see certificate details.\n\nRemember: "TLS handshake: ClientHello → ServerHello → Certificate → Key Exchange → Finished." TLS 1.3 reduced this to one round trip.	training/library/topics/tls-certificates-ops/primer.md
tls/67b7c2215fbb	tls	easy	tls, certificates, expiry	How do you check when a TLS certificate expires?	openssl x509 -in cert.pem -enddate -noout (local file). For a remote server: echo | openssl s_client -connect host:443 2>/dev/null | openssl x509 -enddate -noout.\n\nRemember: "TLS 1.2 = minimum acceptable today. TLS 1.3 = preferred." TLS 1.0 and 1.1 are deprecated since 2020.	training/library/topics/tls-certificates-ops/primer.md
tls/ffaff54644f9	tls	medium	tls, handshake, protocol	What are the main steps of a TLS 1.2 handshake?	1. ClientHello (client sends supported versions, ciphers, SNI). 2. ServerHello (server picks version, cipher). 3. Certificate (server sends cert chain). 4. Key Exchange (both sides). 5. ChangeCipherSpec (switch to encrypted). 6. Finished (handshake complete). TLS 1.3 reduces this to 1 round trip.\n\nRemember: "Certificate chain: leaf → intermediate → root CA." Browsers trust roots; servers send leaf + intermediates.\n\nGotcha: Missing intermediate certificates cause "untrusted" errors on some clients.	training/library/topics/tls-certificates-ops/primer.md
tls/198c84daad38	tls	medium	tls, cipher-suites, security	What four algorithms does a TLS cipher suite define?	Key Exchange (RSA, ECDHE, DHE), Authentication (RSA, ECDSA), Encryption (AES-GCM, ChaCha20), and MAC/integrity (SHA256, SHA384). Example: TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384. Modern configs should avoid RC4, 3DES, CBC mode, and static RSA key exchange.\n\nRemember: "Let's Encrypt = free, automated TLS certificates." Uses ACME protocol. Certs expire every 90 days — automate renewal.	training/library/topics/tls-certificates-ops/primer.md
tls/465426ca73af	tls	medium	tls, sni, virtual-hosting	What is SNI and why does it matter for TLS debugging?	SNI (Server Name Indication) sends the requested hostname during the TLS handshake, allowing servers to present the correct certificate for each domain on shared hosting. Without SNI (-servername flag in openssl), you may get the wrong certificate.\n\nGotcha: Certificate expiry is the #1 TLS outage cause. Monitor with: openssl s_client -connect host:443.\n\nRemember: "Set calendar reminders or automate renewal. Expired certs = outage."	training/library/topics/tls-certificates-ops/primer.md
tls/b8109599838b	tls	medium	tls, san, hostname	What is the difference between CN and SAN in a certificate, and which takes precedence?	CN (Common Name) is the legacy hostname field in the Subject. SAN (Subject Alternative Name) is the modern field supporting multiple hostnames and wildcards. SANs take precedence; modern browsers require SANs and ignore CN. Check with: openssl x509 -text -noout | grep -A1 "Subject Alternative Name".	training/library/topics/tls-certificates-ops/primer.md
tls/f419ce0b2312	tls	hard	tls, intermediate, debugging	How do you diagnose and fix "unable to verify the first certificate" in openssl?	This error means the server is not sending intermediate certificates, so the chain cannot be verified. Fix: concatenate the leaf cert and intermediate(s) into a single file (cat server.crt intermediate.crt > fullchain.pem) and configure the server to use fullchain.pem.	training/library/topics/tls-certificates-ops/primer.md
tls/30979a5716aa	tls	hard	tls, tls13, improvements	What security improvements does TLS 1.3 provide over TLS 1.2?	TLS 1.3 removes insecure ciphers (RC4, 3DES, static RSA key exchange), allows only AEAD ciphers (AES-GCM, ChaCha20-Poly1305), reduces handshake to 1-RTT (or 0-RTT for resumed sessions), and combines key exchange with authentication for a faster, more secure handshake.	training/library/topics/tls-certificates-ops/primer.md
tls/577e2dfb244e	tls	hard	tls, letsencrypt, automation	How do you obtain and auto-renew TLS certificates with Let's Encrypt?	Obtain: certbot certonly --webroot -w /var/www/html -d example.com. Test renewal: certbot renew --dry-run. Auto-renew: enable the systemd timer (systemctl enable certbot-renew.timer) or add a cron job. Certificates are valid for 90 days; certbot renews at 30 days remaining.	training/library/topics/tls-certificates-ops/primer.md
tls/6a8e3f1c9b2d	tls	medium	tls, mtls, mutual-authentication	What is mTLS and when would you use it?	mTLS (mutual TLS) requires both client and server to present certificates and verify each other. Standard TLS only verifies the server. Use mTLS for service-to-service communication in zero-trust networks, API authentication, and microservice mesh (e.g., Istio uses mTLS by default). The client needs its own certificate signed by a CA the server trusts, adding certificate lifecycle management overhead.	
tls/7b9f4a2d0c3e	tls	easy	tls, acme, protocol	What is the ACME protocol and how does it enable automated certificate issuance?	ACME (Automatic Certificate Management Environment) is the protocol behind Let's Encrypt. The client proves domain ownership via challenges: HTTP-01 (place a file at /.well-known/acme-challenge/), DNS-01 (create a TXT record), or TLS-ALPN-01. After verification, the CA issues a signed certificate. DNS-01 is required for wildcard certificates and works even when the server is not publicly accessible.	
tls/8c0a5b3e1d4f	tls	hard	tls, cipher-suites, tls13	How do cipher suites differ between TLS 1.2 and TLS 1.3?	TLS 1.2 has ~37 cipher suites mixing key exchange, authentication, encryption, and MAC. TLS 1.3 reduced this to 5 suites: only AEAD ciphers (AES-128-GCM, AES-256-GCM, ChaCha20-Poly1305) with separate key exchange negotiation. TLS 1.3 removed RSA key exchange (no forward secrecy), CBC mode (padding oracle attacks), RC4, 3DES, and SHA-1. This simplification eliminates entire classes of vulnerabilities.	
tls/9d1b6c4f2e5a	tls	medium	tls, certificate-pinning, security	What is certificate pinning and why has it fallen out of favor?	Certificate pinning hardcodes the expected certificate or public key hash in the client, rejecting any other certificate even if validly signed. It prevents CA compromise attacks but creates operational nightmares: a pinned certificate rotation requires client updates. If the pin expires before clients update, the service becomes unreachable. HPKP (HTTP Public Key Pinning) was deprecated by browsers in 2018 due to these risks.	
tls/0e2c7d5a3f6b	tls	medium	tls, ocsp-stapling, revocation	What is OCSP stapling and why is it preferred over standard OCSP?	Standard OCSP requires the client to contact the CA's OCSP responder to check if a certificate is revoked, adding latency and leaking browsing history. With OCSP stapling, the server periodically fetches a signed OCSP response from the CA and includes ("staples") it in the TLS handshake. This is faster, more private, and eliminates the single-point-of-failure of the OCSP responder being down.	
tls/1f3d8e6b4a7c	tls	hard	tls, openssl, debugging	What are the most useful openssl s_client flags for debugging TLS issues?	-connect host:port (basic connection)\n-servername host (SNI, critical for shared hosting)\n-showcerts (display full certificate chain)\n-verify_return_error (fail on verification error)\n-CAfile /path/to/ca.pem (custom CA bundle)\n-tls1_2 or -tls1_3 (force specific version)\n-cipher or -ciphersuites (test specific ciphers)\nCombine with | openssl x509 -text -noout to decode the certificate details.	
tls/2a4e9f7c5b8d	tls	easy	tls, certificates, formats	What are the common TLS certificate file formats and how do you convert between them?	PEM (.pem, .crt): Base64-encoded, most common on Linux. DER (.der, .cer): binary format, used by Java and Windows. PKCS#12 (.p12, .pfx): bundles cert + key + chain, password-protected.\nConvert PEM to DER: openssl x509 -in cert.pem -outform DER -out cert.der\nConvert PEM to PKCS#12: openssl pkcs12 -export -in cert.pem -inkey key.pem -out bundle.p12	
tls/3b5f0a8d6c9e	tls	hard	tls, forward-secrecy, key-exchange	What is forward secrecy and why is ECDHE required for it?	Forward secrecy ensures that compromising the server's long-term private key does not compromise past session keys. ECDHE (Elliptic Curve Diffie-Hellman Ephemeral) generates a unique key pair per session. Even if the server key is later stolen, past traffic cannot be decrypted. Static RSA key exchange lacks forward secrecy because the same server key decrypts all sessions. TLS 1.3 mandates forward secrecy by only allowing ephemeral key exchange.	
tls/a1f2b3c4d5e6	tls	easy	tls, certificate-chain	What is a certificate chain and what are its three levels?	Root CA (self-signed, in trust store) signs an Intermediate CA, which signs the Server Certificate. The client verifies the chain upward to a trusted root.\n\nRemember: "HSTS tells browsers to always use HTTPS." Header: Strict-Transport-Security: max-age=31536000.\n\nGotcha: HSTS is hard to undo — start with a short max-age while testing.	training/library/topics/tls-pki/primer.md
tls/b2a3c4d5e6f7	tls	easy	tls, san	What is a SAN (Subject Alternative Name) and why is it preferred over CN?	SAN lists additional identities (domains, IPs) a certificate is valid for. Modern browsers require SAN; CN alone causes NET::ERR_CERT_COMMON_NAME_INVALID errors.\n\nRemember: "SNI = Server Name Indication." It lets multiple HTTPS sites share one IP. The client sends the hostname in the TLS handshake.	training/library/topics/tls-pki/primer.md
tls/c3b4d5e6f7a8	tls	easy	tls, debugging	How do you check a remote server's certificate expiry date from the command line?	echo | openssl s_client -connect app.example.com:443 -servername app.example.com 2>/dev/null | openssl x509 -noout -dates\n\nRemember: "OCSP = Online Certificate Status Protocol." It checks if a cert is revoked. OCSP stapling lets the server include the check.	training/library/topics/tls-pki/primer.md
tls/d4c5e6f7a8b9	tls	medium	tls, cert-manager, kubernetes	How does cert-manager automate TLS in Kubernetes?	cert-manager watches Certificate custom resources, requests certificates from a configured Issuer (Let's Encrypt, internal CA, etc.), stores them in Kubernetes Secrets, and auto-renews before expiry using the renewBefore field.\n\nRemember: "PEM = base64 text format, DER = binary format." Most tools use PEM (.pem, .crt, .key files).	training/library/topics/tls-pki/primer.md
tls/e5d6f7a8b9c0	tls	medium	tls, csr, issuance	What is the role of a CSR (Certificate Signing Request) in certificate issuance?	A CSR contains the public key and identity information (CN, SAN) and is sent to a CA for signing. The CA validates the request and returns a signed certificate. The private key never leaves the requestor.\n\nRemember: "Self-signed certs work for encryption but not trust." Browsers show warnings because no CA vouches for the identity.	training/library/topics/tls-pki/primer.md
tls/f6e7a8b9c0d1	tls	medium	tls, mtls	What is mTLS and when is it used?	Mutual TLS requires both client and server to present certificates for authentication. It is used for service-to-service communication where both sides must prove identity, common in service meshes and internal APIs.\n\nRemember: "mTLS = both sides present certificates." Server authenticates client AND client authenticates server. Used in service meshes and zero-trust.	training/library/topics/tls-pki/primer.md
tls/a7f8b9c0d1e2	tls	medium	tls, key-rotation	What is the correct sequence for manual certificate rotation in Kubernetes?	1) Generate new certificate, 2) Update the K8s Secret, 3) Trigger rollout restart of pods using the cert, 4) Verify new cert is served, 5) Revoke the old certificate.\n\nRemember: "Cipher suite = key exchange + authentication + encryption + MAC." Weak suites (RC4, 3DES) must be disabled.	training/library/topics/tls-pki/primer.md
tls/b8a9c0d1e2f3	tls	hard	tls, acme, challenge	What are HTTP-01 and DNS-01 ACME challenge types, and when would you use each?	HTTP-01 proves domain ownership by serving a token on port 80 — simple but requires public HTTP access. DNS-01 proves ownership via a DNS TXT record — works for wildcard certs and when port 80 is not accessible, but requires DNS API access.	training/library/topics/tls-pki/primer.md
tls/c9b0d1e2f3a4	tls	hard	tls, x509, errors	What does the error "x509: certificate signed by unknown authority" mean and how do you fix it?	The client does not trust the CA that signed the server certificate. Fix by adding the CA certificate to the client's trust store, or by using a well-known public CA. In Kubernetes, this often means distributing the internal CA cert to all consuming pods.	training/library/topics/tls-pki/primer.md
tls/d0c1e2f3a4b5	tls	hard	tls, cert-manager, issuer	What is the difference between an Issuer and a ClusterIssuer in cert-manager?	An Issuer is namespace-scoped and can only issue certificates within its namespace. A ClusterIssuer is cluster-scoped and can issue certificates for any namespace, making it suitable for shared infrastructure like a single Let's Encrypt or internal CA configuration.	training/library/topics/tls-pki/primer.md

<!-- wiki:related:start -->
---

## Wiki Navigation

### Related Content

- [Case Study: BMC Clock Skew Cert Failure](../../../../library/case-studies/datacenter_ops/bmc-clock-skew-cert-failure/README.md) (Case Study, L2) — TLS & PKI
- [Case Study: DNS Looks Broken — TLS Expired, Fix Is Cert-Manager](../../../../library/case-studies/cross-domain/dns-tls-certmanager/README.md) (Case Study, L2) — TLS & PKI
- [Case Study: Deployment Stuck — ImagePull Auth Failure, Vault Secret Rotation](../../../../library/case-studies/cross-domain/deployment-stuck-imagepull-vault/README.md) (Case Study, L2) — TLS & PKI
- [Case Study: SSL Cert Chain Incomplete](../../../../library/case-studies/networking/ssl-cert-chain-incomplete/README.md) (Case Study, L1) — TLS & PKI
- [Case Study: User Auth Failing — OIDC Cert Expired, Cloud KMS Rotation](../../../../library/case-studies/cross-domain/user-auth-oidc-cert-kms/README.md) (Case Study, L2) — TLS & PKI
- [Deep Dive: TLS Handshake](../../../../library/deep-dives/tls.handshake.deep.dive.md) (deep_dive, L2) — TLS & PKI
- [HTTP Protocol](../../../../library/topics/http-protocol/index.md) (Topic Pack, L0) — TLS & PKI
- [Interview: Certificate Expired](../../../../library/interview-scenarios/12-certificate-expired.md) (Scenario, L2) — TLS & PKI
- [Networking Deep Dive](../../../../library/topics/networking/index.md) (Topic Pack, L1) — TLS & PKI
- [Nginx & Web Servers](../../../../library/topics/nginx-web-servers/index.md) (Topic Pack, L1) — TLS & PKI

<!-- wiki:related:end -->
