[Cloud Computing]Mechanisms: Certificate Authority

本文介绍了公共密钥基础设施(PKI)中的核心组件——证书权威机构(CA)。CA负责签署数字证书及证书撤销列表(CRL),确保信息安全可靠。文章还解释了注册权威机构(RA)的角色及其如何验证证书信息的有效性和准确性。

摘要生成于 C知道 ,由 DeepSeek-R1 满血版支持, 前往体验 >

Certificate Authority


The certificate authority, or certification authority, is the public key infrastructure (PKI) entity that digitally signs certificates and certificate revocation lists (CRLs). The CA generates some certificate information but is primarily responsible for collecting information from authorized sources and entering that information into a certificate before signing.

The CA digitally signs and issues a subscriber's certificate when authorized by the appropriate trusted person or process, called a registration authority (RA). The RA ensures that only valid and appropriate information is included in the certificate and maintains evidence that due diligence was exercised in confirming the information to the required assurance level of the PKI.


Figure 1 - An example of a certificate authority as part of a public key infrastructure (PKI).

Figure 1 shows a certificate authority issuing certificates and CRLs as part of a PKI. The PKI must be operated in accordance with a certificate policy and certificate practice statement (CPS) that establishes the security assurance level of the issued certificates. Periodic audits are performed to confirm that the PKI is being operated in accordance with their CPS.

Related Patterns:

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值