
Andrei Lupu
I build every explanation of TLS from the handshake outwards, because that order matches how a browser decides whether to trust a page and most certificate problems only make sense once you have watched that decision happen. The handshake establishes a cipher suite, a protocol version and a server identity. A browser checks the server identity against a chain of certificates it already trusts locally, and every failure in that chain produces a different error message that people routinely misread. A missing intermediate looks like an untrusted issuer. A name mismatch looks like a security error. An expired leaf has its own code. I go through what each one is telling you. The certificate fields worth understanding are few. Subject Alternative Name replaced the Common Name for host matching, and a certificate carrying only a Common Name fails in current browsers. Basic Constraints marks whether a certificate can sign others. Key Usage and Extended Key Usage narrow what a key may be used for, and a certificate that signs nothing is a server leaf rather than an authority. The chain runs from the leaf through any intermediates the server chose to send to a root already in the trust store. The server controls the middle of that list, which is where most deployments go wrong. TLS 1.3 removed the cipher suite choices behind most older configuration advice, along with renegotiation and much of the padding oracle surface. TLS 1.2 is still everywhere and still worth understanding, particularly its cipher negotiation and the forward secrecy question. I also cover revocation, which is subtler than it looks. CRLs are large and stale. OCSP stapling moves the check to the server but needs a responder. Certificate Transparency logs mean a misissued certificate is public whether or not anybody revoked it, and that changed how quickly a bad certificate gets noticed. What I will not do is call a site secure. A scan reads the handshake from one machine at one moment, and says nothing about the certificate served during an incident.
About ToolSura
ToolSura offers 80+ free, privacy-first online tools that run 100% in your browser — no uploads, no logins. Learn more about our mission →