PKI Environment
This topic describes the public key infrastructure (PKI).
Registration and Certification Issuance
Certificate Authority
Key Generation
Key Recovery^
Key Generation
Certificate Revocation
Certificate Distribution
Trusted Time Service
Key Storage
Support for Nonrepudiation
A PKI provides a hierarchical framework for managing digital security attributes of entities that will engage in secured communications. In addition to human users, there are encryption gateways, secure web servers, and other resources that require close control of identity and encryption.
A PKI consists of these entities:
■ Peers communicating on a secure network
■ At least one CA that grants and maintains certificates
■ Digital certificates, which contain information such as the certificate validity period, peer identity information, encryption keys that are used for secure communications, and the signature of the issuing CA
■ An optional registration authority (RA) to offload the CA by processing enrollment requests. Certificate enrollment is the process of obtaining a certificate from a CA.
■ A distribution mechanism, such as Lightweight Directory Access Protocol (LDAP) or HTTP, for certificate revocation lists (CRLs)
PKI provides customers with a scalable, secure mechanism for distributing, managing, and revoking encryption and identity information in a secured data network. Every entity (a person or device) participating in the secured communications is enrolled in the PKI in a process in which the entity generates an RSA key pair (one private key and one public key) and has their identity validated by a trusted entity (also known as a CA or trust point).
© 2006 Cisco Systems, Inc.
IPsec VPNs 4-39
After enrolling in a PKI, each peer (also known as end host) in a PKI is granted a digital certificate that has been issued by a CA. When peers must negotiate a secured communication session, they exchange digital certificates. Based on the information in the certificate, a peer can validate the identity of another peer and establish an encrypted session with the public keys contained in the certificate.
Implementing Secure Converged Wide Area Networks (ISCW) v1.0
4-40
A CA, also known as a trustpoint, manages certificate requests and issues certificates to participating network devices. These services, managing certificate requests and issuing certificates, provide centralized key management for the participating devices and are explicitly trusted by the receiver to validate identities and to create digital certificates. Before any PKI operations can begin, the CA generates its own public key pair and creates a self-signed CA certificate; thereafter, the CA can sign certificate requests and begin peer enrollment for the PKI.
You can use a CA provided by a third-party CA vendor, or you can use an internal CA, which is the Cisco IOS Certificate Server.
Hierarchical PKI: Multiple CAs
You can set up a PKI in a hierarchical framework to support multiple CAs. At the top of the hierarchy is a root CA, which holds a self-signed certificate. The trust within the entire hierarchy is derived from the RSA key pair of the root CA. The subordinate CAs within the hierarchy can be enrolled with either the root CA or with another subordinate CA. These enrollment options enable multiple tiers of CAs to be configured. Within a hierarchical PKI, all enrolled peers can validate the certificate of each other if the peers share a trusted root CA certificate or a common subordinate CA.
© 2006 Cisco Systems, Inc. IPsec VPNs 4-41
Multiple CAs provide users with added flexibility and reliability. For example, subordinate CAs can be placed in branch offices while the root CA is at the office headquarters. Also, different granting policies can be implemented per CA, so you can set up one CA to automatically grant certificate requests while another CA within the hierarchy requires each certificate request to be manually granted.
Scenarios in which at least a two-tier CA is recommended are as follows:
■ Large and very active networks in which a large number of certificates are revoked and reissued. A multiple tier CA helps to control the size of the CRLs.
■ When online enrollment protocols are used, the root CA can be kept offline with the exception of issuing subordinate CA certificates. This scenario provides added security for the root CA.
Implementing Secure Converged Wide Area Networks (ISCW) v1.0
4-42
Certificates can be used for the large-scale use of public key cryptography. Securely exchanging secret keys among users becomes impractical for large networks.
Continue reading here: X509 v3 Certificate
Was this article helpful?