Loading CryptoViz...
Loading page content...Loading CryptoViz...
Loading page content...Explore how X.509 certificates are chained, verified, and anchored to a trusted certificate authority.
Explore how X.509 certificates are chained, verified, and connected to a trusted certificate authority.
Step 1 of 7
The end-entity certificate identifies the server and contains its public key, issuer, validity period, and other X.509 information.
Follow the path from the end-entity certificate to the trusted root.
Issuer: Example Intermediate CA
Issuer: Example Root CA
Basic Constraints: CA = TRUE
Root Certificate Authority
Each check becomes active as the validation process advances.
A valid certificate signature alone does not establish trust. Validation also requires building a certification path, checking the certificates in that path, and determining whether it terminates at a trusted trust anchor.