Answer the question
In order to leave comments, you need to log in
How to properly deploy a certification authority?
Good day! Comrades, experts, please tell me how to properly organize a certification center within the company.
Technical question:
Let's say I want to organize the following structure of certification centers:
Answer the question
In order to leave comments, you need to log in
Should the root certificate (CompanyName Root CA) have links to crl and ocsp?
Answer: The root self-signed certificate should not contain links to crl and ocsp
But as for any (well, almost any) subordinate certificate, it should contain. crl link. Link to ocsp - optional, according to your desire or the requirement of the information system (IS).
Accordingly, as in the certificates of subordinate CAs (Project 1, Project 2, VPN, etc.), there must be a link to crl. Not to mention the client certificates issued by the CAs of Project 1, Project 2, VPN, etc.
Link to crl in CA certificates of Project 1, Project 2, VPN, etc. will be the same and will contain the revocation list issued by the Root CA. With the help of this SOS, you can manage the certificates of subordinate CAs.
In certificates issued by UCs of Project 1, Project 2, VPN, etc. will contain a link to the crl corresponding to each specific CA, and you can manage the revocation of client certs from each subordinate CA on which the cert of this client was issued.
It is not entirely clear what the phrase "get access to the CompanyName Project 2 CA using a certificate issued by the CompanyName Security CA CA" means.
Apparently, the answer is "no" - you won't be able to access the CompanyName Project 2 CA using a certificate issued from under the CompanyName Security CA.
As for information systems that use certificates, the implementation of the function of trusting this information system to a certificate falls entirely on the shoulders of the developer of the information system and its architecture.
The easiest way to limit the use of serts issued only by the CompanyName Project 2 CA is to install the CompanyName Project 2 CA root sert on the system and check this chain. At the same time, the CompanyName Security CA cert must be absent in the IS
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question