I have three questions regarding SSL that I don't fully understand.
If I get it correctly, a server
Asubmits a request to a certain CA. Then, it receives (after validation etc.) a digital certificate composed of a public key + identity + an encription of this information using the CA's private key.Later on, a client
Bwants to open an SSL communication withA, soAsendsBits digital certificate.My question is can't
Bjust take this certificate, thus stealing the identityA- which will allow them to authenticate asAtoC, for example. I understand thatCwill decrypt the certificate with the CA's public key, It will then encrypt its symetric key which will only be decryptable by the realA.However, I do not see where authentication comes to play if
Bcan actually stealA's identity. Unless I am missing something.Second question: Why use hashing on the certificate if a part of it is already encrypted by the CA? Doesn't this mean that no one can mess around with a digital certificate (in high probability) anyway?
If I am stackoverflow and I have 3 servers doing the same thing - allowing clients to access, read, identify etc. - do I have to have a different digital certificate for each of the 3 servers.
Thank you very much.