Difficulty: Intermediate
What is the difference between symmetric and asymmetric encryption? What is a digital certificate and how does the chain of trust work?
Let's use a lock analogy. Symmetric encryption is a padlock where the same key locks and unlocks it. It is quick and strong, but you have to somehow deliver the key to your friend without anyone copying it, which is the key distribution problem. Asymmetric encryption is a mailbox with a slot: anyone can drop a letter in (the public key encrypts), but only the owner with the mailbox key (the private key) can open it and read. You can shout your public key to the world safely.
Symmetric algorithms, such as AES-128, AES-256 and ChaCha20, use one shared secret key for both encryption and decryption. They are very fast, often hardware accelerated, and suitable for bulk data. Asymmetric algorithms, such as RSA, elliptic curve schemes (ECDSA, ECDH, Ed25519) and Diffie-Hellman, use a mathematically linked pair of keys. They are hundreds to thousands of times slower and can only handle small inputs, so in practice they are used to exchange or agree on a symmetric key, or to sign things. This hybrid design is exactly what TLS and SSH do.
Asymmetric keys work in two directions. For confidentiality, you encrypt with the recipient's public key and only their private key can decrypt. For authentication and integrity, you create a digital signature: hash the message and encrypt the hash with your private key; anyone can verify using your public key that the message came from you and was not modified. Note that a signature does not hide the message, it proves origin. Hashing (SHA-256) is a third tool: one way, fixed-size output, used for integrity, and passwords should be stored with slow salted hashes like bcrypt or Argon2, not encrypted.
But there is a hole. If I hand you my public key over an insecure network, how do you know it is mine and not an attacker's? That is where digital certificates and Certificate Authorities come in. A certificate, in the X.509 format, binds an identity (like the domain internhack.xyz) to a public key, along with a validity period, issuer, serial number and the issuer's digital signature. A CA such as Let's Encrypt or DigiCert verifies that you control the domain and then signs your certificate with the CA's private key.
The chain of trust works like this. Your browser or OS ships with a root store of about 150 root CA certificates that it trusts unconditionally. Root CAs are kept offline and rarely sign server certificates directly. They sign intermediate CA certificates, and the intermediates sign the leaf certificates that servers present. When you connect, the server sends the leaf and intermediate certificates. The client verifies leaf signed by intermediate, intermediate signed by a root in its trust store, and checks that the leaf's subject alternative names include the hostname, the dates are valid, and the certificate has not been revoked (via CRL or OCSP, and OCSP stapling where the server attaches a fresh response).
Failure cases explain the concept well. A self-signed certificate has no trusted CA, so browsers show warnings. A missing intermediate certificate makes validation fail on some clients. A corporate proxy that intercepts TLS installs its own root CA on employee machines, which is why it can decrypt traffic. Compromised CAs, like DigiNotar in 2011, are why we have Certificate Transparency logs where all issued certificates are publicly logged and why CAA DNS records restrict who may issue for a domain. Also mention that certificate private keys must be protected, and Let's Encrypt certificates last 90 days to encourage automated renewal.
$ openssl genpkey -algorithm RSA -out priv.pem -pkeyopt rsa_keygen_bits:2048
$ openssl pkey -in priv.pem -pubout -out pub.pem
$ echo 'pay 500' > msg.txt
$ openssl dgst -sha256 -sign priv.pem -out msg.sig msg.txt
$ openssl dgst -sha256 -verify pub.pem -signature msg.sig msg.txt
Verified OK
$ echo 'pay 900' > msg.txt
$ openssl dgst -sha256 -verify pub.pem -signature msg.sig msg.txt
Verification failure
Changing even one character of the message breaks verification, which is the integrity guarantee.
Symmetric Encryption, Asymmetric Encryption, Digital Signature, Certificate Authority, Chain of Trust