PKI concepts Flashcards

1
Q

What is the certificate Authority?

A

It is the computer giving out the certificate

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the hierarchy of CA’s (certificate authorities)?

A

The root CA gives out the CA’s to the intermediate authorities and they give them out to the users. The root CA’s are then taken offline completely

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the two kinds of CA’s

A

There are internal PKI’s which are done within companies and then External PKI which are for public facing and are backed with high dollar

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is a common name for a CA?

A

Also known as the Fully Qualified Domain Name (FQDN), is the characteristic value within a Distinguished Name (DN). Typically, it is composed of Host Domain Name and looks like, “www.digicert.com” or “digicert.com”. The Common Name field is often misinterpreted and is filled out incorrectly

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is a self sign certificate?

A

Is when you sign your own certificate locally, and issues it to the intermediate.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the Certificate chain validation ?

A

Where the users computer looks at the root and subordinate CA validates their certificates

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Are cerfiticates suspectible to password attacks?

A

no they are not

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

User certificates can be used for?

A

They can be use for email, disk encryption, and authentication

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What does code signing certificate mean

A

It provides identity of vendor, and ensures integrity of software, and operating systems use this to vaildate.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are wild card certificate?

A

Its used to identify the parent domain and verifies all the sub domains and represented by an asterisk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are the levels of validation certificate?

A

Domain validation: lowest level of validation and verifies the ownership over domain. organizztion validation: greater than the DV and verifies the identity of orgainzation. Extended validation: highest form of the organization identification, most rigourous vaildation process.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is .der certifcate format

A

It’s binary encoded and does not include private key (.cer)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

what is PEM certificate format?

A

It’s base64 ASCII encoded and has various extensions (.perm,.cer, crt)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is PKCS#7 certificate format?

A

It includes the public key, and certificate information, and certificate chain (.PB7B)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is PKCS#12 certificate format?

A

It includes both private/public keys, certificate information(inlcudes extended properties) and certificate chain

How well did you know this?
1
Not at all
2
3
4
5
Perfectly