A certificate binds a public key to an identity and carries the signature of a certificate authority (CA). A registration authority (RA) checks the requester's identity before the CA issues. When a certificate has to die early, the CA either publishes it on a certificate revocation list (CRL) or answers live status queries through OCSP. The first is a list the client downloads; the second is a real-time lookup.
Disk encryption comes in two scopes. Full-disk encryption covers the whole volume, operating system included; file- or folder-level encryption covers only what you select. Either protects a device that is powered off or stolen. Neither helps much once the system is running and the user is signed in.
Hashes and modes
A hash proves integrity only if nobody can swap the hash along with the data, which is why HMAC mixes a secret key into the hash and why signatures are applied to hashes. For stored passwords, a random salt per account makes precomputed tables useless and hides the fact that two users share a password.
Block cipher modes are worth one line each. ECB encrypts identical blocks identically, so patterns in the plaintext survive into the ciphertext. CBC chains each block to the one before. GCM adds authentication, so tampering is detected on decryption.
Mail encryption shows up in two trust models: S/MIME trusts certificates from a CA hierarchy, while web-of-trust tools rely on users vouching for each other's keys.
Steganography sits next door
Cryptography hides what a message says; steganography hides that there is a message at all. Steganalysis is the job of detecting the hidden payload. The pair also appears in the system hacking module, under hiding files.