Using Digital Keys
Diagram taken from a Versign White Paper
Client initiates a connection
Server responds, sending the
client its digital ID. The server might also request the client's digital ID for client authentication.
The client verifies the server's digital ID. If requested the client sends its digital ID in response to the server's request.
When authentication is complete the client sends the server a session key encrypted using the server's public key.
Once a session key is established, securecommunications commence between client & server