Skip to main content
Guidance

Design and build a privately hosted Public Key Infrastructure

Principles for the design and build of in-house Public Key Infrastructure (PKI)

Page 3 of 21

Components of a PKI

Public Key Infrastructure is built around a set of components and procedures for managing public and private key pairs.

A typical PKI is made up of the following functions. These can be fulfilled by a procedure or a technology component, and in some cases, a mixture of both.

  1. Certificate authority (CA) - Issues an entity's certificate and acts as a trusted component within a private PKI. Any certificate issued by the CA is trusted by all entities that trust the CA. The exact role of a CA will depend on its position within a CA hierarchy.
  2. Certificate - A digital document, signed by a CA, and used to prove the owner of a public key, within a PKI. The certificate has a number of attributes, such as usage of the key, Client authentication, Server authentication or Digital signature and the public key. The certificate also contains the subject name which is information identifying the owner. This could be, for example, a DNS name or IP address.
  3. Registration authority (RA) - Receives certificate signing requests and verifies the identity of an end entity. The RA will approve a request before the certificate can be issued by the CA. This is a very important stage of the process and it often involves a procedure to enrol end entities into the PKI.
  4. Validation authority (VA) - A VA allows an entity to check that a certificate has not been revoked. The VA role is often carried out by an online facility hosted by an organisation who operates the PKI. A validation authority will often use OCSP or CRL to advertise revoked certificates.
  5. Secure storage - A method of securely storing a private key is required for both the Certificate Authority (CA) and end entity, to protect the key from compromise.
  6. Public/Private key pair - A private key and associated public key are mathematically related to one another. The public key can be shared widely. The private key proves ownership of the identity and must be kept secret.

Published

Reviewed

Version

1.0