PKI Cryptography 2 Flashcards
central repository for storing cert.’s, allows admins to set policies in one location and centrally manage all users certificates.
Certificate Server
ensures key is unusable for a period of time, suspend rather than expire to make them temporarily invalid.
Certificate Suspension
est. policies for destroying old keys, when key or cert. is no longer useful destroy and remove from system, then notify CA so CRL and OCSP servers can be updated, deregistration should occur when key is destroyed.
Certificate Lifecycle (Destruction)
EXTRA :
HTTPS request made, server sends cert., client authenticates servers cert. (client uses CA’s public key to validate CA’s digital signature), browser generates session key, server decrypts session key with their private key, secure connection using session key.
TLS uses port 443
TLS Handshake Process