Preface

The following texts are written for certificate and IT freshman. Their main purpose is to ease the understanding of certificates, to illustrate the principles behind, and to show, what they are used for. In consequence, some used metaphors may be rarely correct from a pure technical point of view.

What Are Certificates For?

The easiest way to understand a digital certificate is to think of it as an identity card for the internet. You receive this card from an official authority, which confirms your identity and your address — on the internet, your address is your email address. Just as you use your identity card to identify yourself on the street, you can also use a digital certificate to identify yourself on the internet. Additionally, not only individuals but also groups, organizations, and websites can hold such credentials to identify themselves to you—for example, as your actual bank (website).

Who Issues Certificates?

Just like with an identity card, you can only obtain a certificate from an official authority. The University of Rostock operates such an authority and is authorized by the DFN (German Research Network) to issue user certificates. To verify the authenticity of a certificate, each certificate securely includes the issuer’s details. Only if the issuer is trustworthy will the certificate itself be trusted.

In this way, a chain of trust is formed: The Greek provider HARICA signs and creates the certificate for GÉANT, the European umbrella organization for research networks. On behalf of this umbrella organization, we then create your certificate. HARICA itself has so-called root certificates that are usually pre-installed on every computer, smartphone, or tablet, enabling verification at any time.

What Information Is in a Certificate?

Depending on the certificate type, a certificate contains different information. In a simple certificate, the certificate contains only your email address and the issuer. It only confirms that your email address is assigned to the University of Rostock. In an extended certificate, however, your name is also included, proofing your sole identity. In both certificate types, your organization with its location (University of Rostock, Germany) and an expiration date are also recorded. For these certificates to be used by you for signing and encrypting emails, they also include your public key. Since understanding the two mentioned applications is important, here follows a brief (!) explanation of public and private keys.

Public and Private Keys and Certificates?

The terms “public key” and “private key” come from cryptography. They form a key pair used for encryption and decryption:

  • Your public key is used by OTHERS to encrypt messages intended for YOU. It can be shared with anyone so that everyone can send you an encrypted message.
  • Your private key is needed for decrypting messages, and it should be known ONLY to you.

The relationship between the keys is comparable to a mailbox: Anyone who wants to send you a letter can simply drop it into your mailbox — this is the public key. However, only you possess the (private) key to open the mailbox. As with your mailbox key, you should pay special attention to your private key and store it, for example, on a separate USB stick.

A certificate stores your public key and certifies that it actually belongs to you — securely and without falsification.

How to obtain your own key pair and corresponding certificate is shown here.

Certificates and Digital Signatures?

A digital signature is similar to a wax seal on a letter from ancient times: On one hand, the sender can be verified, and on the other, it can be ensured that the message content has not been altered. Since the digital signature depends on both the content of the message and the sender’s private key, any forgery of the message or sender can be detected. To verify the signature, the sender’s certificate is always transmitted along with the message. A successfully verified signature thereby means that the message is in its original form and is 100% from the sender.

How to configure your email program for digital signatures and how to sign your own emails is shown here.

Certificates and Encryption?

Encryption ensures that only the recipient of a message can read it. For this, the public key is used for encryption and the private key for decryption. To ensure that the public key used actually belongs to the intended recipient, it should be taken from the recipient’s certificate. The attentive reader knows that this certificate can be obtained, for example, through a signed email ;)

It is important to keep expired private keys as well, since old encrypted messages can no longer be read if they are lost — as you will no longer be able to open an old mailbox.

How to encrypt emails with your mail program is explained here.

Contact

Certification authority
cauni-rostockde

Albert-Einstein-Str. 22
18059 Rostock

Martin Sievers-Luboschik
Tel: +49 381 498-5328

Martin Röhlig
Tel: +49 381 498-5327

Jörg Maletzky
Tel: +49 381 498-5339

Jörg Zerbe
Tel: +49 381 498-5320