Summary

The primary focus of this chapter has been the structure and semantics of the X.509 Version 3 public-key certificate, and the need for certification in order to maintain the integrity and trustworthiness of the certificate itself. This chapter notes that the X.509 public-key certificate is by far the preferred choice for the enterprise domain, and it is quickly becoming widely accepted in other environments such as the Internet. It also has discussed a number of other certificate types (which may or may not be encountered in wide-scale implementation practice).

This chapter has also addressed the importance and role of the CA and RA components. A CA is responsible for issuing certificates in accordance with one or more certificate polices. ...

Get Understanding Public-Key Infrastructure: Concepts, Standards, and Deployment Considerations now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.