Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

A public key certificate is a digitally signed data structure that connects an entity’s identifier to a public key. It is not the private key, and a signature alone does not make the certificate trustworthy: a client must also validate its certificate path, validity dates, status, and suitability for the intended use.

What a public key certificate does

A certificate lets a system associate a public key with a named subject, such as a server or other entity. In the Internet X.509 model, a certificate authority (CA) signs that association so a relying system can check that the certificate’s contents have not been altered and that the issuer made the assertion.

RFC 4949 defines a public-key certificate as “A digital certificate that binds a system entity’s identifier to a public key value, and possibly to additional, secondary data items; i.e., a digitally signed data structure that attests to the ownership of a public key.” RFC 4949, Internet Security Glossary (2007) describes the general concept; RFC 5280 (May 2008) specifies the Internet X.509 profile.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The certificate is not secret and does not contain the matching private key. The private key is a separate item that its owner must keep under control. A certificate can be distributed publicly; its role is to make the signed public-key association available for verification.

What an X.509 certificate contains

An X.509 certificate has three outer fields: tbsCertificate, signatureAlgorithm, and signatureValue. The first field contains the information covered by the issuer’s signature.

  • Version and serial number: identify the certificate format version and the issuer-assigned certificate number.
  • Issuer and subject: identify the issuing authority and the entity named in the certificate.
  • Validity: gives the notBefore and notAfter times.
  • Subject public-key information: carries the subject’s public key and related algorithm information.
  • Extensions: optional additional constraints and information; X.509 version 3 is used when extensions are present.

The issuer’s signature covers the certificate information, especially the link between the subject and the public key. It does not disclose or sign the subject’s private key.

What the signature proves—and what it does not

Verifying the issuer’s signature establishes that the signed certificate contents match what the issuer signed. It does not, by itself, establish that the issuer is trusted by a particular device or application, that the named subject is suitable for every purpose, or that the certificate remains acceptable now.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For an X.509 certificate, a relying system performs certification-path validation: it checks the relationships among certificates in the chain, applies relevant constraints and policy, and evaluates the chain against a configured trust anchor. Whether the certificate is accepted also depends on the verifier’s rules and the intended use. A signature that verifies is therefore one part of the decision, not the whole decision.

Validity dates and revocation

The notBefore and notAfter fields define the certificate’s stated validity interval. RFC 5280 describes this as the period in which the CA warrants that it will maintain information about the certificate’s status. Reaching the end date makes the certificate expired, but being within the date range does not by itself establish that it should be trusted.

A certificate can be revoked before its notAfter date. Reasons can include a changed relationship between the subject and CA, or compromise—or suspected compromise—of the associated private key. X.509 supports publishing revocation information in a signed certificate revocation list (CRL). A relying system must apply its status-checking rules as well as its path, date, and use checks.

Rank #4
10 Packs Certificate Holders, Navy Blue Certificate Covers, Diploma Holders
  • PACKAGE CONTAINS: Set of 10 classic Navy Blue certificate holders to keep your certificate paper free of creases. Ideal protector and collector for your 8-1/2 x 11" size graduation, awards, presentations, diplomas, or letter size cardstock paper
  • SIZE: Certificate Holders measured 9.4 x12 inches after folded. Suit for holding vertically or horizontally 8.5" x 11" size documents, awards, certificates, and photos
  • STRUCTURE: Foldable certificate covers have semicircular cut grooves at four corners to hold the paper in place easily and securely and prevent slipping, which can protect your certificate perfectly and look more elegant
  • CLASSIC AND PROFESSIONAL LOOKING: Our Certificate Holders are Navy Blue and the front cover with ornate gold foil scroll design, making the certificate cover look official and easy to distinguish front and back
  • WIDE APPLICATION: Certificate covers were great for the presentation of awards and certificates! The ideal choice for schools, enterprises, organizations, Veterans Day, and churches to present awards and certificates
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

CA certificates and end-entity certificates

X.509 distinguishes certificates by the role of their subject. The distinction matters because a certificate does not automatically authorize its holder to issue other certificates.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • CA certificate: identifies a certificate authority and can be used in a certification path subject to the applicable constraints and policy.
  • End-entity certificate: belongs to a subject that is not authorized to issue certificates.

RFC 5280 also describes self-issued, self-signed, and cross-certificates. These labels describe relationships among subjects, issuers, or keys; they do not eliminate the need to assess trust, constraints, validity, status, and intended use.

Best Value
Sale
Happy Secret Book-Style Diploma Cover 8.5" x 11", Smooth Leather Certificate Holder for Diplomas and Certificates
  • Designed for Standard 8.5" x 11" Documents: This diploma cover is designed to hold one standard 8.5" x 11" certificate or diploma and features a 4mm foam-padded core for support and a professional presentation.
  • Book-Style Opening with Clean Blank Front: This holder features a classic book-style opening and a plain front without printed text, creating a clean and professional look suitable for graduation, awards, and formal document presentation.
  • Smooth Leather-Look Exterior: Made with a smooth PU leather-look exterior, this certificate holder offers a classic appearance with a durable structure suitable for display, storage, and ceremony use.
  • Protective Interior Design: Four corner ribbons help hold the document in place, while the clear protective sheet provides added coverage against dust, fingerprints, and everyday handling.
  • Suitable for Individual and Bulk Orders: A practical choice for individual use, schools, training programs, award ceremonies, and corporate recognition events. Also suitable for bulk institutional purchases and custom logo applications.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.