Public key infrastructure.
Describe the public key infrastructure. What is it? What are its major components? Second, explain why an active attacker can break an SSL connection, but not an IPsec connection?
Sample Solution
What is a PKI?
A PKI is a system that uses a set of digital certificates to authenticate and secure communications. It is used in a variety of applications, including secure web browsing, email encryption, and electronic signatures.
Major components of a PKI
The major components of a PKI are:
- Root CA: The root CA is the highest authority in the PKI. It is responsible for issuing certificates to other CAs.
- CAs: CAs are responsible for issuing certificates to users and devices. They are trusted by the root CA.
- Digital certificates: Digital certificates are electronic documents that contain the public key of a user or device. They also contain information about the user or device, such as their name and email address.
- Registration authorities (RAs): RAs are responsible for verifying the identity of users and devices before they are issued a digital certificate.