TLS, Certificates and Public-Key Cryptography: A Practical Deep Dive for Software Engineers

# Chapter 1. The Problem

We write programs for computers. Sometimes this computers are connected and programs needs to communicate with other programs. Computers are connected into network and the network - especially public networks - is dangerous place.

This problem is usually explained with help of Alice, Bob and other involved people. Let's follow this tradition.

So, imagine:

Alice ---------------- Internet ---------------- Bob

What questions are coming to your mind when you see this?

  • Can Alice's message be read by someone else but Bob?
  • Can Alice's message be modified by someone without Bob noticing?
  • Can Alice be sure she talks to Bob and vise-versa?
  • Can they exchange secrets?
  • And who are all those people?!

The answer for the first 4 question is cryptography. People are inventing different cryptographic systems for millennia. Most of them are not good(good - a secure, mathematically sound framework that transforms readable data (plaintext) into unreadable data (ciphertext)).

# Chapter 2. Symmetric Cryptography

It all begin with Symmetric Cryptography. The idea is simple: two participants have the same secret key. It is mixed with plaintext to produce ciphertext. Then the same secret key is added to ciphertext to get the original plain text.

Such systems are usually performant, convenient and straightforward to understand.

One of the popular modern implementation of this concept is AES(Advanced Encryption Standard).