Is It My Browser? Or Is It Their Server?


The .com DNS server, which contains the record for serverfault.com, refers the request to that DNS server, which contains the record we are looking for: the IP address of www.serverfault.com. The cert has a bunch of data fields but the main ones you should know about are these five: Issuer, Validity (valid from that date to that date), The Public Key is critical because it lets you scramble data in such a way that it can only be deciphered by someone with a secret file known as a private key. The private and public keys are mathematically related in such a way that you can't derive the former from the later.

IP datagrams contain the destination IP address and not a human-readable name. There are Root Servers, but your local machine is unlikely to use them.

Verisign bombards twitter.com with a fusillade of questions before it issues the cert because it needs to have reasonable assurance that Twitter.com is who it claims it is.

