PKI
Public key infrastructure: roles, hierarchies, revocation, HSMs and governance.
Introduction to PKI
Public key infrastructure: roles, components (CA, RA, repository) and a decentralized trust model.
Certification authority and registration authority
Separation of issuer and verifier roles, issuance process and request traceability.
PKI hierarchy: root and intermediates
Offline root CA, operational intermediate CAs and impact on chain depth.
CRL and OCSP: checking revocation
Revocation lists, OCSP responders, stapling and availability versus security trade-offs.
HSMs and certification key protection
Hardware security modules, non-exportability of keys and common requirements for CAs.
Governance and audit of an internal PKI
Certificate policy (CP/CPS), separation of duties, logging and periodic review.