PKI and Cryptographic Protocols Flashcards
Cleartext
unencrypted data thats not supposed to be encrypted
What states does encryption protect?
processing, transit, rest
What are digital signatures?
Electronic signatures to verify the sender
What is a digital certificate?
Public key associated with users and has been signed by a trusted third party
CA
Certificate Authorities
What do CAs do?
Makes and manages digital certificates
CSR
Certificate Signing Request
How can a digital certificate be authenticated?
Email, Documents, In-person
What is a weakness in a single centralized CA?
Bottlenecks
How do you ensure security and integrity when managing CAs
Offline CA
CR
Certificate Repository
What is a CR?
Public centralized directory of digital signatures where you can see the status
What happens to a digital certificate before its expiration date?
Revoked
CRL
Certificate Revocation List
What is a CRL?
list of certificates revokes by serial numbers
can have a local CRL
OCSP
Online Certificate Status Protocol
OCSP Stapling
Web server sends queries to responders at intervals
What is a OCSP?
Real-time look up of revocation
Browsers that use OCSP
Chrome, Safari, Firefox, Opera, IE
Root Digital Certificate
Self-signed
End is user
Domain Digital Certificate
Web server and browser key exchange
Entry-Lvl
no trust just verifies
Extended Domain Digital Certificate
Audit to follow ev standards
owner verifies by intermediate CA
authorized by intermediate and signature from officer of company
Wildcard Digital Certificate (Domain)
validate main and subdomains
Subject Alternatuve Name Digital Certificate (Domain)
Unified Communications Certificate
Multiple servers or domain names uses same certificate