Guidance
Design and build a privately hosted Public Key Infrastructure
Principles for the design and build of in-house Public Key Infrastructure (PKI)
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
Page 6 of 21
The Root CA will issue the intermediate CA certificate. The intermediate CA will then issue another CA, one level down, or sign end entity certificates.
A CA hierarchy enables you to have a level of segmentation between different uses cases for the PKI. This applies both to administration and the role of certificate authority.
Separating administration roles allows different people or functions to manage a certificate authority. Having a segmentation of duty at the CA level reduces the blast radius of a compromised CA and gives flexibility to the parameters of the certificate issued by a CA. For example, this enables different certificate lifetimes issued on certificates per CA.
In a 2-tier hierarchy, a root CA will issue an intermediate CA certificate. The intermediate CA will issue certificate to end entities. The intermediate CA will often be organised to issue certificates to a certain function, such as a technology use case e.g VPN or web application. Alternatively the CA's could be organised by organisational function e.g user authentication, machine or service authentication.
In a 3-tier hierarchy, there is a root CA and two levels of intermediate CAs, in which the lowest layer will issue certificate to end entities. This setup is often used to give an extra layer of separation between the Root CA and the intermediate issuing certificates to end entities.
The number of tiers in a CA hierarchy is a balance between the level of separation required and the tolerable administration overheard. Try to keep the PKI design as simple as possible without unnecessary levels. If possible, keep to 2 or 3 tiers.


