LinuxQuestions.org
Help answer threads with 0 replies.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-17-2020, 03:40 AM   #1
lelunicu
Member
 
Registered: Jun 2019
Posts: 105

Rep: Reputation: 0
pki


hi,
is the command to verify that a certificate or private key is corrupted?

Last edited by lelunicu; 01-17-2020 at 04:49 AM.
 
Old 01-17-2020, 05:44 AM   #2
berndbausch
LQ Addict
 
Registered: Nov 2013
Location: Tokyo
Distribution: Mostly Ubuntu and Centos
Posts: 6,316

Rep: Reputation: 2002Reputation: 2002Reputation: 2002Reputation: 2002Reputation: 2002Reputation: 2002Reputation: 2002Reputation: 2002Reputation: 2002Reputation: 2002Reputation: 2002
If the certificate is signed by a real CA, you can verify its signature chain. E.g. https://www.linuxquestions.org/quest...-chain-929960/.

A few suggestions of checking a private/public keypair (which is not the same as just the private key): https://stackoverflow.com/questions/...te-dsa-keypair
 
Old 01-17-2020, 07:30 AM   #3
lelunicu
Member
 
Registered: Jun 2019
Posts: 105

Original Poster
Rep: Reputation: 0
if my certificate is signed by an intermediate certificate and this by an CA then when my certificate is verified then is verified in chain the intermediate certificate and CA certificate?
 
Old 01-17-2020, 07:45 AM   #4
berndbausch
LQ Addict
 
Registered: Nov 2013
Location: Tokyo
Distribution: Mostly Ubuntu and Centos
Posts: 6,316

Rep: Reputation: 2002Reputation: 2002Reputation: 2002Reputation: 2002Reputation: 2002Reputation: 2002Reputation: 2002Reputation: 2002Reputation: 2002Reputation: 2002Reputation: 2002
You can check your CA's certificate against the next higher certificate, and so on.

Perhaps it's also possible to copy the entire CA trust chain into one file and check that. Try it
 
Old 01-17-2020, 08:36 AM   #5
lelunicu
Member
 
Registered: Jun 2019
Posts: 105

Original Poster
Rep: Reputation: 0
when is using an certificate then all the upper certificates until CA root certificate are checked authomatically by the application?
 
Old 01-17-2020, 08:45 AM   #6
sevendogsbsd
Senior Member
 
Registered: Sep 2017
Distribution: FreeBSD
Posts: 2,252

Rep: Reputation: 1011Reputation: 1011Reputation: 1011Reputation: 1011Reputation: 1011Reputation: 1011Reputation: 1011Reputation: 1011
Depends on the application. For a browser, yes, normally. I don't understand your original question OP - are you worried about file corruption or what?
 
Old 01-17-2020, 09:19 AM   #7
lelunicu
Member
 
Registered: Jun 2019
Posts: 105

Original Poster
Rep: Reputation: 0
just asked because if a certificate is corrupted maybe the tls channel will not be setup thus no data will travel encrypted over this channelright?
 
Old 01-17-2020, 09:53 AM   #8
sevendogsbsd
Senior Member
 
Registered: Sep 2017
Distribution: FreeBSD
Posts: 2,252

Rep: Reputation: 1011Reputation: 1011Reputation: 1011Reputation: 1011Reputation: 1011Reputation: 1011Reputation: 1011Reputation: 1011
If a certificate is corrupted, you would probably either not be able to install it or the web server would not start, if it is a web server certificate.
 
Old 01-20-2020, 03:17 AM   #9
lelunicu
Member
 
Registered: Jun 2019
Posts: 105

Original Poster
Rep: Reputation: 0
the web server before starting verify the certificates?
CA signature is inside the intermediate certificate.right?

Last edited by lelunicu; 01-20-2020 at 06:28 AM.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
How to run PKI Gins Linux - General 2 01-17-2007 12:45 PM
PKI implementation amsri Linux - Networking 0 01-24-2006 07:49 AM
PKI Enabled FTP Client elvinyup Linux - Software 0 09-20-2005 02:31 AM
PKI implementation on Red Hat Linux Fedora 3.0 fauzie Linux - Networking 4 01-14-2005 10:01 PM
Pki subban Linux - Enterprise 1 12-19-2004 04:02 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 11:40 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration