Certification service provider
CSP components (authorities)
Registration authority
RA: Registration
Proof of Possession: Certificate request message format
PoP: Encryption keys
PoP: Key agreement keys
Establishment of a shared secret key between CSP and entity
Secure “Out-of-Band” channel
RA models
Reasons for decentralization
Security requirements for registration
Certificate classes
Classification for TLS certificates
EV certificates: Scope
Are intended for use in establishing web-based data communication conduits via TLS/SSL protocols
EV certificates: Primary purposes
EV certificates: Secondary purposes
EV certificates: What is verified
Certification authority
Directory services
Chain model - problems
Certification request construction
Key/certificate life cycle and CA