Guidance
Design and build a privately hosted Public Key Infrastructure
Principles for the design and build of in-house Public Key Infrastructure (PKI)
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
Page 7 of 21
The trust store is a collection of certificates that are trusted, they are often part an operating system and are installed locally on an end entity. This is often the root CA that sits on top of the CA hierarchy. In the case of a private PKI, the root CA certificate will typically be installed in an end entity's trust store.
Here is a simple example of checking the certificate chain: 
The end entity inspects the certificate it has received from another end entity and finds it has been issued by a certain intermediate CA. The intermediate CA could be in the same file as the client certificate and be exchanged when a connection is initiated or it could already be installed on an end entity.
The certificate of the intermediate CA will be inspected. This has been issued by a CA at the next level of the CA hierarchy. In our example this is the root CA, in the trust store which is installed on the end entity and it normally part of the operating system.
The last certificate - which is usually pre-installed in the trust store - is inspected. If everything is in order the checking stops as the chain of trust is complete, having reached a certificate in the trust store.
Normally, the end entity will check each certificate against a revocation list, verify its expiry date and its configuration. Any failures will cause the certificate to be rejected. Please note the certificate in the trust store is trusted without question.
If all the certificates check out, then the end entity should have confidence that the peer’s certificate is genuine.
For a more detailed description or for more information on building certification path, see RFC 4158.


