SSCP Systems Security Certified PractitionerCryptographyEasy
A company is implementing a Public Key Infrastructure (PKI) to secure its internal communications. As part of this implementation, a server is designated to issue, revoke, and manage digital certificates. What role does this server fulfill within the PKI?
- ACertificate Authority (CA)
- BRegistration Authority (RA)
- CCertificate Repository (CR)
- DValidation Authority (VA)
Show answer & explanationAnswer & explanation
Correct answer: A. Certificate Authority (CA)
The Certificate Authority (CA) is the trusted entity responsible for issuing, revoking, and managing digital certificates within a PKI.
Why the other options are wrong
- B. A Registration Authority (RA) verifies identities but does not issue certificates.
- C. A Certificate Repository (CR) stores certificates and CRLs for public access, but does not issue or revoke them.
- D. A Validation Authority (VA) specifically validates the status of certificates, often using CRLs or OCSP.
Certificate Authority (CA)
A trusted entity in a PKI that issues, revokes, and manages digital certificates.
- Root of trust in a PKI.
- Digitally signs certificates it issues.
- Maintains Certificate Revocation Lists (CRLs).
Memory trick: PKI is like a government for digital identities, with different departments.