Ravindra BagaleCourses & study guides Track your progress

Labs · Cyber Security

Lab: Check an HTTPS Certificate Chain in Your Browser and Verify a Download with Its Published SHA-256 Hash

Beginner30 minChrome, Edge or Firefox · openssl (Mac/Linux/Git Bash, optional) · sha256sum, shasum or PowerShell Get-FileHash

Course: Cyber Security · Chapter 33: Cryptography Basics

Chapter 33 explains hashing, encryption and certificates; this lab shows both in everyday use: the padlock and the download checksum.

Chala mitrano! Cryptography is not only for experts. Every time you see a padlock, a certificate chain is working. Every time a site gives a long SHA-256 code next to a download, a hash is protecting you. Today we look inside both, with our own eyes. Padlock chya maage kay aahe, bagha!

Suppose we are…

Suppose we are on the IT security team at ICICI Bank. Staff ask two everyday questions: "How do I know this website's padlock is genuine?" and "How do I know this tool I downloaded was not tampered with?" We prepare a 10-minute demo: reading a certificate chain, and verifying the popular SSH client PuTTY against the SHA-256 list its authors publish.

Goal of this lab

By the end you will be able to:

  • Read a site's certificate: who it is issued to, who issued it, the chain up to a trusted root, and the expiry date.
  • Check the same details from the command line with openssl.
  • Verify a real download against a published SHA-256 hash and see what a mismatch looks like.

What you need (all free)

  • A browser and internet access. Optional: openssl (built into Mac/Linux, and Git Bash on Windows).
  • About 30 minutes.

Safety and ethics

You are only reading public certificates and hashing a file on your own laptop. Do not run software that fails its hash check; delete it and download again from the official site.

Part 1: certificate chain in the browser

  1. Open https://ravindrabagale.com (or any HTTPS site). Click the icon left of the address (Chrome/Edge: the tune icon or padlock) → Connection is secure → Certificate is valid.
  2. On the General tab read Issued To, Issued By and Validity Period.

    What you should see: Issued To matches the domain, Issued By is a certificate authority (for example Let's Encrypt), and an expiry date about 90 days after the issue date.

  3. Open the Details tab and look at Certificate Hierarchy.

    What you should see: three levels: a root at the top (trusted by your device), an intermediate in the middle, and the site's leaf certificate at the bottom.

  4. Click the leaf and find Subject Alternative Name: the list of domain names the certificate covers.

Part 2: the same check with openssl (optional)

  1. In a terminal:

    echo | openssl s_client -connect ravindrabagale.com:443 -servername ravindrabagale.com 2>/dev/null | openssl x509 -noout -subject -issuer -dates
    

    What you should see: subject=CN=ravindrabagale.com (older openssl adds spaces around =), an issuer= line such as O=Let's Encrypt, and notBefore= and notAfter= dates that match the browser.

Part 3: verify a download with SHA-256

  1. Download the 64-bit PuTTY program from the official page https://www.chiark.greenend.org.uk/~sgtatham/putty/latest.html → Alternative binary files → under putty.exe (the SSH and Telnet client itself) click the 64-bit x86 putty.exe. You do not need to run it; we only hash it, so this works on Mac and Linux too.
  2. On the same page click SHA-256 under Checksum files (the sha256sums file) and find the line ending with w64/putty.exe (not the one marked "installer version").
  3. Hash your download. Windows PowerShell: Get-FileHash .\putty.exe -Algorithm SHA256 · Mac: shasum -a 256 putty.exe · Linux: sha256sum putty.exe

    What you should see: exactly the same 64-character value as the w64/putty.exe line. Same hash = same file the authors published.

  4. Simulate tampering on a copy: copy putty.exe to putty-copy.exe, append one character (Mac/Linux: echo x >> putty-copy.exe; PowerShell: Add-Content .\putty-copy.exe "x"), and hash the copy.

    What you should see: a completely different hash. Delete putty-copy.exe.

  5. Write two lines for the staff demo: what the padlock proves (you are talking to the real domain, encrypted), and what a matching hash proves (the file is exactly what the publisher released).

Ravindra Bagale's Tip

A padlock means "encrypted, to this domain". It does not mean the site is honest: a phishing site on a look-alike domain can also have a padlock. Always read the domain itself. And for hashes, compare the full value, not just the first few characters. Purna hash, purna vishwas!

Common mistakes

Mistake What happens Fix
Thinking a padlock means "safe site" Phishing sites with valid certificates fool you Read the domain name carefully
Comparing with the "installer version" line Hashes differ and you think the file is bad Use the plain w64/putty.exe line
Taking the hash from a mirror or forum A tampered file can come with a tampered hash Take the hash from the official site over HTTPS
Using MD5 or SHA-1 lists They are weak against deliberate tampering Prefer SHA-256 or stronger
Running a file whose hash does not match You may run tampered software Delete it and download again

Self-check checklist

0 of 5 done

Try-at-home challenge

Use the openssl command from step 5 on three sites you use every day. Which one expires soonest, and how many days are left?

Check your answer

Compare the notAfter= dates. Sites using Let's Encrypt usually show certificates valid for about 90 days and are renewed automatically around 30 days before expiry (Lab 13's certbot renew --dry-run), so a date 20–60 days away is normal. Commercial certificates can last longer, up to about a year.

Samjla ka? The chain proves who, the hash proves what. Aata pudhe jaauya: Chapter 34 covers Indian cyber law and how to report a crime.