From Preparation

Identity and Cryptographic Protocols

Not written yet. Questions to answer here: what an x509 certificate asserts and who has to be trusted for it to mean anything, what the TLS handshake establishes and in what order, what a certificate authority is inside a company as opposed to on the public internet, what 802.1x does that is different (authenticating a device at the physical network port before it gets an address), what U2F’s hardware token actually signs and why that resists phishing where a password does not, what SAML is passing between an identity provider and an application, and the frame that ties them together: machine identity and human identity are the same problem answered with different instruments.