6.4 Given a scenario, implement public key infrastructure. Flashcards
Certificate Authority (CA)
A certificate authority (CA) is an organization that is responsible for ISSUING, revoking, and distributing certificates
Registration Authority
– Responsible for verifying users’ identities and approving or denying requests for digital certificates.
– RAs do not issue certificates
Certificate Revocation List (CRL)
list that you need to update about revokes certs.
Certificate Revocation List (CRL)
list that you need to update about revoked certs.
Root CA
most trusted entity in PKI.
Intermediate CA
A CA that is subordinate to the root CA by one or more levels and typically issues certificates to other CAs in the public key infrastructure (PKI) hierarchy.
CSR (Certificate Signing Request)
A message sent to a certificate authority from a user or organization to request and apply for a digital certificate
Certificate or Digital Certificate
Signed with the CA’s private key and associates the user’s credentials with a public key.
Key Pair
Asymmetric encryption - 1 Public key & 1 Private Key
Stapling
allows a web server to provide information on the validity of its own certificate
Single-CA Model
A small company that has to get a cert from a CA
Hierarchical CA Model
A self signed CA, large company
Cross-Certification CA Model
A small company buying or partnering with another small company
Bridge CA Model
When a large company buys or partners with nay size company.
Key Escrow
Used to store keys securely, while allowing one or more 3rd parties (key escrow agents) access to the keys under predefined conditions.
X.509 current Verson
version 3.
X.509 is?
X.509 certificates are written in a specific format.
Self-signed
it will be created and digitally signed by you. probably not trusted by other people.
DER (Distinguished EncodingRules)
Used for binary DER-encoded certificates.
PEM (Privacy-enhanced Electronic Mail)
Provide message confidentiality and integrity to emails.
CER (Canonical Encoding Rules)
- The Base64 format supports storage of a single certificate. – Public Key
- This format does not support storage of the private key or certification path.
PFX (Personal Information Exchange)
Unlike the .cer, the .pfx contains both the public and its associated private keys.
P12 (PKCS #12)
This format usually contains X509 certificates, public and private key
The CRL takes time to be fully disseminated. Which protocol allows a certificate’s authenticity to be immediately verified? A. CA B. CP C. CRC D. OCSP
D. OCSP
Your IT manager has stated that you need to select an appropriate tool for email encryption. Which of the following would be the best choice? A. MD5 B. PGP C. TLS D. IPSEC
B. PGP
Which organization can be used to identify an individual for certificate issue in a PKI environment? A. RA B. LRA C. PKE D. SHA
A. RA
Your company has implemented email encryption throughout the enterprise. You are concerned that someone might lose their cryptographic key. You want to implement some mechanism for storing copies of keys and recovering them. What should you implement? A. Key renewal
B. Key archival
C. Key escrow
D. Certificate rollover
C. Key escrow