← Back to Labs

Certificate Chain Validation

Walk a public-web certificate chain from leaf to root, then layer revocation, CT, and pinning checks on top.

LeafDNS: debtman.devCA:FALSE · serverAuthLet's Encrypt R11CA:TRUE · keyCertSignpathlen:0ISRG Root X1trust anchorstored locallysigStart with the hostname, EKU, validity dates, and CA:FALSE.Build the chain, verify signatures, enforce X.509 policy, then check status and key constraintsstapled OCSP statusSCT / CT log proofSPKI pin match
Step 1 / 6The server sends a leaf certificate for the hostname

The website sends a certificate saying which hostname its public key is supposed to belong to.

Arrow keys to navigate · R to reset

Tap dots to jump to any step

Read the full article →Take the quiz →