Free course

TLS and Certificates Course

Inspect TLS connections, create a local certificate authority, run HTTPS and mutual TLS labs, and diagnose certificate failures with evidence.

5 modules · 25 lessons · No signup

Prerequisites: Shell Commands, Networking Foundations, HTTP and curl

~~~

Your progress

of lessons completed.

Course completed.

What you'll learn

Create and protect keys, issue local certificates, serve verified HTTPS and mutual TLS, and identify the exact cause of a failed handshake.

Take this course offline

Subscribe to my newsletter to get every free book and course in PDF and EPUB format.

Get the downloads

Course contents

  1. Inspect TLS

    Inspect live handshakes, certificates, names, chains, and negotiated connection properties.

    1. Connect with openssl s_client
    2. Read a certificate
    3. Understand the certificate chain
    4. Record the negotiated connection
    5. Check your understanding: inspect tls
  2. Build a local certificate authority

    Create protected keys, a local CA, CSRs, and signed leaf certificates for a controlled lab.

    1. Generate a private key
    2. Create a local CA certificate
    3. Create a certificate signing request
    4. Sign a server certificate
    5. Check your understanding: build a local certificate authority
  3. Serve local HTTPS

    Run a local HTTPS application, trust the lab root narrowly, and verify names from multiple clients.

    1. Run a Node.js HTTPS server
    2. Map the lab hostname
    3. Trust the lab CA for one command
    4. Serve a complete chain
    5. Check your understanding: serve local https
  4. Diagnose TLS failures

    Reproduce hostname, time, chain, protocol, and key failures and identify the exact failed check.

    1. Diagnose a hostname mismatch
    2. Diagnose certificate validity time
    3. Diagnose a missing intermediate
    4. Diagnose protocol and key failures
    5. Check your understanding: diagnose tls failures
  5. Mutual TLS and operations

    Require client certificates, convert formats, rotate identities, and complete an evidence-based TLS review.

    1. Issue a client certificate
    2. Require client authentication
    3. Convert certificate formats
    4. Plan rotation and recovery
    5. Check your understanding: mutual tls and operations