How does Tier 2 Certificate Server works












0















I have a question regarding standalone root CA. I understand when we create the root CA, we will have to create a private key that only the root CA has. And it is used to encrypt or decrypt messages with other clients with the public key.



My question is if we have subordinate CA in the domain. Then we will put the root CA offline so no one can touch the private key. But if we put root CA offline, then no one else has that private key. So Do the root CA pass the private key to the subordinate CA?



Thank you so much










share|improve this question























  • No; the root CA signs the subordinate (and marks it as allowed to sign other certs). You should never transfer private keys.

    – SLaks
    Nov 27 '18 at 1:43
















0















I have a question regarding standalone root CA. I understand when we create the root CA, we will have to create a private key that only the root CA has. And it is used to encrypt or decrypt messages with other clients with the public key.



My question is if we have subordinate CA in the domain. Then we will put the root CA offline so no one can touch the private key. But if we put root CA offline, then no one else has that private key. So Do the root CA pass the private key to the subordinate CA?



Thank you so much










share|improve this question























  • No; the root CA signs the subordinate (and marks it as allowed to sign other certs). You should never transfer private keys.

    – SLaks
    Nov 27 '18 at 1:43














0












0








0








I have a question regarding standalone root CA. I understand when we create the root CA, we will have to create a private key that only the root CA has. And it is used to encrypt or decrypt messages with other clients with the public key.



My question is if we have subordinate CA in the domain. Then we will put the root CA offline so no one can touch the private key. But if we put root CA offline, then no one else has that private key. So Do the root CA pass the private key to the subordinate CA?



Thank you so much










share|improve this question














I have a question regarding standalone root CA. I understand when we create the root CA, we will have to create a private key that only the root CA has. And it is used to encrypt or decrypt messages with other clients with the public key.



My question is if we have subordinate CA in the domain. Then we will put the root CA offline so no one can touch the private key. But if we put root CA offline, then no one else has that private key. So Do the root CA pass the private key to the subordinate CA?



Thank you so much







pki ca






share|improve this question













share|improve this question











share|improve this question




share|improve this question










asked Nov 27 '18 at 1:42









perryfanfanperryfanfan

8118




8118













  • No; the root CA signs the subordinate (and marks it as allowed to sign other certs). You should never transfer private keys.

    – SLaks
    Nov 27 '18 at 1:43



















  • No; the root CA signs the subordinate (and marks it as allowed to sign other certs). You should never transfer private keys.

    – SLaks
    Nov 27 '18 at 1:43

















No; the root CA signs the subordinate (and marks it as allowed to sign other certs). You should never transfer private keys.

– SLaks
Nov 27 '18 at 1:43





No; the root CA signs the subordinate (and marks it as allowed to sign other certs). You should never transfer private keys.

– SLaks
Nov 27 '18 at 1:43












0






active

oldest

votes











Your Answer






StackExchange.ifUsing("editor", function () {
StackExchange.using("externalEditor", function () {
StackExchange.using("snippets", function () {
StackExchange.snippets.init();
});
});
}, "code-snippets");

StackExchange.ready(function() {
var channelOptions = {
tags: "".split(" "),
id: "1"
};
initTagRenderer("".split(" "), "".split(" "), channelOptions);

StackExchange.using("externalEditor", function() {
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled) {
StackExchange.using("snippets", function() {
createEditor();
});
}
else {
createEditor();
}
});

function createEditor() {
StackExchange.prepareEditor({
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader: {
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
},
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
});


}
});














draft saved

draft discarded


















StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53491568%2fhow-does-tier-2-certificate-server-works%23new-answer', 'question_page');
}
);

Post as a guest















Required, but never shown

























0






active

oldest

votes








0






active

oldest

votes









active

oldest

votes






active

oldest

votes
















draft saved

draft discarded




















































Thanks for contributing an answer to Stack Overflow!


  • Please be sure to answer the question. Provide details and share your research!

But avoid



  • Asking for help, clarification, or responding to other answers.

  • Making statements based on opinion; back them up with references or personal experience.


To learn more, see our tips on writing great answers.




draft saved


draft discarded














StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53491568%2fhow-does-tier-2-certificate-server-works%23new-answer', 'question_page');
}
);

Post as a guest















Required, but never shown





















































Required, but never shown














Required, but never shown












Required, but never shown







Required, but never shown

































Required, but never shown














Required, but never shown












Required, but never shown







Required, but never shown







Popular posts from this blog

Contact image not getting when fetch all contact list from iPhone by CNContact

count number of partitions of a set with n elements into k subsets

A CLEAN and SIMPLE way to add appendices to Table of Contents and bookmarks