Pki and Certificate Authorities
Santosh Chokhani, Padgett Peterson, Steven Lovaas · 2012
This chapter provides an overview of the public key infrastructure (PKI) and certificate authorities. There are various manual, electronic, and hybrid mechanisms for the distribution of public keys in a trusted manner, so that the relying party can be sure to have the correct public keys of the subscribers. These mechanisms for distribution and binding of public keys are known as a PKI. To ensure the security of the PKI, the PKI components need to operate with a high degree of security. To ensure this, private keys must be kept confidential and used only by the owners of the keys. Initial authentication of the subscriber must be strong so that identity theft does not occur at the point of certificate creation. The Certificate Policy (CP) must specifically enumerate the certificate contents, both fields and extensions. Anything absent from the CP should not be found in the certificate. In addition to the security requirements and in order to facilitate electronic commerce, the PKI must address obligations of all parties and their liabilities in case of dispute.