Skip to main content
Guidance

Design and build a privately hosted Public Key Infrastructure

Principles for the design and build of in-house Public Key Infrastructure (PKI)

Page 7 of 21

Checking the Certificate Path

Trust in an end entity certificate is achieved by checking the certification path though a number CAs, back to a trusted certificate, installed in a trust store.

The trust store is a collection of certificates that are trusted, they are often part an operating system and are installed locally on an end entity. This is often the root CA that sits on top of the CA hierarchy. In the case of a private PKI, the root CA certificate will typically be installed in an end entity's trust store.

Here is a simple example of checking the certificate chain: image shows set up as just described

  • 1

    End entity certificate

    The end entity inspects the certificate it has received from another end entity and finds it has been issued by a certain intermediate CA. The intermediate CA could be in the same file as the client certificate and be exchanged when a connection is initiated or it could already be installed on an end entity.

  • 2

    Certificate of the intermediate CA

    The certificate of the intermediate CA will be inspected. This has been issued by a CA at the next level of the CA hierarchy. In our example this is the root CA, in the trust store which is installed on the end entity and it normally part of the operating system.

  • 3

    Final certificate

    The last certificate - which is usually pre-installed in the trust store - is inspected. If everything is in order the checking stops as the chain of trust is complete, having reached a certificate in the trust store.

Normally, the end entity will check each certificate against a revocation list, verify its expiry date and its configuration. Any failures will cause the certificate to be rejected. Please note the certificate in the trust store is trusted without question.

If all the certificates check out, then the end entity should have confidence that the peer’s certificate is genuine.

For a more detailed description or for more information on building certification path, see RFC 4158.

Published

Reviewed

Version

1.0