Labs · Cyber Security
Lab: Check an HTTPS Certificate Chain in Your Browser and Verify a Download with Its Published SHA-256 Hash
Course: Cyber Security · Chapter 33: Cryptography Basics
Chapter 33 explains hashing, encryption and certificates; this lab shows both in everyday use: the padlock and the download checksum.
Chala mitrano! Cryptography is not only for experts. Every time you see a padlock, a certificate chain is working. Every time a site gives a long SHA-256 code next to a download, a hash is protecting you. Today we look inside both, with our own eyes. Padlock chya maage kay aahe, bagha!
चला मित्रांनो! Cryptography फक्त experts साठी नाही. प्रत्येक वेळी padlock दिसतो तेव्हा certificate chain काम करत असते. प्रत्येक वेळी site download शेजारी लांब SHA-256 code देते तेव्हा hash तुमचं रक्षण करतो. आज आपण दोन्हीच्या आत स्वतःच्या डोळ्यांनी बघणार. Padlock च्या मागे काय आहे, बघा!
चलो दोस्तों! Cryptography सिर्फ experts के लिए नहीं है। हर बार padlock दिखे तो certificate chain काम कर रही होती है। हर बार site download के पास लंबा SHA-256 code दे तो hash आपकी रक्षा कर रहा है। आज हम दोनों के अंदर अपनी आँखों से देखेंगे। Padlock के पीछे क्या है, देखो!
Suppose we are…
Suppose we are on the IT security team at ICICI Bank. Staff ask two everyday questions: "How do I know this website's padlock is genuine?" and "How do I know this tool I downloaded was not tampered with?" We prepare a 10-minute demo: reading a certificate chain, and verifying the popular SSH client PuTTY against the SHA-256 list its authors publish.
Goal of this lab
By the end you will be able to:
- Read a site's certificate: who it is issued to, who issued it, the chain up to a trusted root, and the expiry date.
- Check the same details from the command line with
openssl. - Verify a real download against a published SHA-256 hash and see what a mismatch looks like.
What you need (all free)
- A browser and internet access. Optional:
openssl(built into Mac/Linux, and Git Bash on Windows). - About 30 minutes.
Safety and ethics
You are only reading public certificates and hashing a file on your own laptop. Do not run software that fails its hash check; delete it and download again from the official site.
Part 1: certificate chain in the browser
- Open
https://ravindrabagale.com(or any HTTPS site). Click the icon left of the address (Chrome/Edge: the tune icon or padlock) → Connection is secure → Certificate is valid. -
On the General tab read Issued To, Issued By and Validity Period.
What you should see: Issued To matches the domain, Issued By is a certificate authority (for example Let's Encrypt), and an expiry date about 90 days after the issue date.
-
Open the Details tab and look at Certificate Hierarchy.
What you should see: three levels: a root at the top (trusted by your device), an intermediate in the middle, and the site's leaf certificate at the bottom.
-
Click the leaf and find Subject Alternative Name: the list of domain names the certificate covers.
Part 2: the same check with openssl (optional)
-
In a terminal:
echo | openssl s_client -connect ravindrabagale.com:443 -servername ravindrabagale.com 2>/dev/null | openssl x509 -noout -subject -issuer -datesWhat you should see:
subject=CN=ravindrabagale.com(older openssl adds spaces around=), anissuer=line such asO=Let's Encrypt, andnotBefore=andnotAfter=dates that match the browser.
Part 3: verify a download with SHA-256
- Download the 64-bit PuTTY program from the official page
https://www.chiark.greenend.org.uk/~sgtatham/putty/latest.html→ Alternative binary files → under putty.exe (the SSH and Telnet client itself) click the 64-bit x86putty.exe. You do not need to run it; we only hash it, so this works on Mac and Linux too. - On the same page click SHA-256 under Checksum files (the
sha256sumsfile) and find the line ending withw64/putty.exe(not the one marked "installer version"). -
Hash your download. Windows PowerShell:
Get-FileHash .\putty.exe -Algorithm SHA256· Mac:shasum -a 256 putty.exe· Linux:sha256sum putty.exeWhat you should see: exactly the same 64-character value as the
w64/putty.exeline. Same hash = same file the authors published. -
Simulate tampering on a copy: copy
putty.exetoputty-copy.exe, append one character (Mac/Linux:echo x >> putty-copy.exe; PowerShell:Add-Content .\putty-copy.exe "x"), and hash the copy.What you should see: a completely different hash. Delete
putty-copy.exe. -
Write two lines for the staff demo: what the padlock proves (you are talking to the real domain, encrypted), and what a matching hash proves (the file is exactly what the publisher released).
Ravindra Bagale's Tip
A padlock means "encrypted, to this domain". It does not mean the site is honest: a phishing site on a look-alike domain can also have a padlock. Always read the domain itself. And for hashes, compare the full value, not just the first few characters. Purna hash, purna vishwas!
Ravindra Bagale's Tip – मराठी
Padlock म्हणजे "encrypted, या domain पर्यंत". त्याचा अर्थ site प्रामाणिक आहे असा नाही: look-alike domain वरच्या phishing site ला पण padlock असू शकतो. नेहमी domain स्वतः वाचा. आणि hash साठी पूर्ण value compare करा, फक्त पहिली काही अक्षरं नाही. पूर्ण hash, पूर्ण विश्वास!
Ravindra Bagale's Tip – हिंदी
Padlock मतलब "encrypted, इस domain तक"। इसका मतलब ये नहीं कि site ईमानदार है: look-alike domain वाली phishing site पर भी padlock हो सकता है। हमेशा domain खुद पढ़ो। और hash के लिए पूरी value compare करो, सिर्फ पहले कुछ अक्षर नहीं। पूरा hash, पूरा भरोसा!
Common mistakes
| Mistake | What happens | Fix |
|---|---|---|
| Thinking a padlock means "safe site" | Phishing sites with valid certificates fool you | Read the domain name carefully |
| Comparing with the "installer version" line | Hashes differ and you think the file is bad | Use the plain w64/putty.exe line |
| Taking the hash from a mirror or forum | A tampered file can come with a tampered hash | Take the hash from the official site over HTTPS |
| Using MD5 or SHA-1 lists | They are weak against deliberate tampering | Prefer SHA-256 or stronger |
| Running a file whose hash does not match | You may run tampered software | Delete it and download again |
Self-check checklist
0 of 5 done
Try-at-home challenge
Use the openssl command from step 5 on three sites you use every day. Which one expires soonest, and how many days are left?
Check your answer
Compare the notAfter= dates. Sites using Let's Encrypt usually show certificates valid for about 90 days and are renewed automatically around 30 days before expiry (Lab 13's certbot renew --dry-run), so a date 20–60 days away is normal. Commercial certificates can last longer, up to about a year.
Samjla ka? The chain proves who, the hash proves what. Aata pudhe jaauya: Chapter 34 covers Indian cyber law and how to report a crime.