How does an SSL certificate prove the emitter is who he pretends to be ?
If Bob (holding a certificate) and Alice wanted to establish a SSL-secured connection, wouldn't John be able to get the certificate from Bob and send it to Alice, pretending to be Bob ?
I understand the private/public key very well, but I don't understand what role it plays in a certificate.