TLS and certificates: trust and operations
Six lessons, 30 questions, and six cases covering TLS, trust, identity, mTLS, renewal, and certificate diagnosis.
Objectives and progression
A technical course with six modules and fictional APS cases. Interpret chain, identity, validity, and purpose; distinguish mTLS from authorization; plan renewal, deployment, rotation, and trust changes; interpret tools without confusing connection and verification. References IETF, OpenSSL 3.5, NGINX, curl, and cert-manager. Internal assessment of 24 decisions in 60 minutes without external certification or executed labs.
Audience: APS L2/L3 teams, middleware administrators, platform teams, and technical managers.
Prerequisites: TCP/IP and HTTP/HTTPS fundamentals; cases supply enough evidence for decisions.
300 estimated study minutes
- Distinguish public material, secrets, and construction of a verifiable chain.
- Verify reference identity and validity interval with explicit scope.
- Distinguish protocol, authenticated identity, and business permission.
- Plan issuance, distribution, and activation with evidence for each stage.
- Interpret status and sequence CA changes without confusing uncertainty with approval.
- Read tool evidence without treating connection as complete verification.
Modules
- Keys, certificates, and trust
- Identity, name, and time
- Negotiation, mTLS, and the application
- Renewal and served certificates
- Revocation and trust transition
- Diagnosis with explicit criteria
Continue learning
References and version
DR TLS/certificates 2026-09; selected TLS 1.2/1.3, RFC 9525 identity and OpenSSL 3.5 diagnostics
- TLS 1.3 selected handshake and replay semantics · 2026-09-30
- Service Identity in TLS · 2026-09-30
- TLS deployment guidance · 2026-09-30
- X.509 certificates and path validation · 2026-09-30
- OCSP response semantics · 2026-09-30
- TLS 1.0 and 1.1 deprecation · 2026-09-30
- OpenSSL certificate verification · 2026-09-30
- OpenSSL certificate inspection · 2026-09-30
- OpenSSL diagnostic TLS client · 2026-09-30
- OpenSSL verification options and purpose · 2026-09-30
- OpenSSL public and private key operations · 2026-09-30
- cert-manager Certificate lifecycle · 2026-09-30
- NGINX TLS configuration · 2026-09-30
- NGINX upstream TLS · 2026-09-30
- NGINX HTTPS chains and virtual hosts · 2026-09-30
- curl certificate trust and identity checks · 2026-09-30
What you will explore
0 / 6Keys, certificates, and trust
Distinguish public material, secrets, and construction of a verifiable chain.
Identity, name, and time
Verify reference identity and validity interval with explicit scope.
Negotiation, mTLS, and the application
Distinguish protocol, authenticated identity, and business permission.
Renewal and served certificates
Plan issuance, distribution, and activation with evidence for each stage.
Revocation and trust transition
Interpret status and sequence CA changes without confusing uncertainty with approval.
Diagnosis with explicit criteria
Read tool evidence without treating connection as complete verification.