Module07ImplementingaPublic
KeyInfrastructureALLSOLUTION
100%CORRECTSPRINGFALL-2023AID
GRADEA+
Whichofthefollowingentityinthecertificateauthority(CA)
hierarchyvalidatesthecertificaterequestfromaclient?
RegistrationAuthority(RA)
Note:
Whenaclientrequestsacertificate,RegistrationAuthority(RA)
validatestherequest.Ifthevalidationissuccessful,thentheRA
confirmstotheCAthatacertificatecanbeissuedbasedonthe
client'srequest.ItisimportanttonotethattheRAneverissuesa
certificatetotheclient.Itonlyvalidatesandsendstherequestto
theCA.ThehierarchybeginswithaRootCAatthetopandwithone
ormoreintermediateCAlevelsbelowit.Inasimplemodel,an
intermediateCAistrustedbytheauthoritygrantedtoitbyaRoot
CA.
AlargeenterprisecancreateitsownRootCA,whichcandelegate
signingauthoritytointermediateCAservers.ThereisarootCA,
thentheintermediate,andthenyoucanalsohavetheleafCA,which
isatthebottomofthehierarchy.Theentirehierarchysharesthe
rootCAcertificateandthepublickeys.
BeforeauserrequestsacertificatefromaCA,whichofthe
followingtasksmustbecompleted?
Generateprivateandpublickeys
Note:
WhenauserrequestsacertificatefromaCA,therequestgoesinthe
formofaCSR,whichcontainstheRSA-basedpublickey.TheCSRalso
containstherequiredinformationforthecertificate.
Therefore,theusermustfirstgenerateprivateandpublickeys.When
aCSRissent,thepublickeyissentinit.TheCAtakesthepublic
keyandembedsitintothecertificatethatitisissuingtoyou.