[Contents] [Prev] [Next] [Index] [Report an Error]

PKI Hierarchy for a Single CA Domain or Across Domains

Figure 90 shows the structure of a single-domain certificate authority.

Figure 90: PKI Hierarchy of Trust—CA Domain

Image g030622.gif

If certificates are used solely within an organization, that organization can have its own CA domain within which a company CA issues and validates certificates for its employees. If that organization later wants its employees to exchange their certificates with those from another CA domain (for example, with employees at another organization that also has its own CA domain), the two CAs can develop cross-certification by agreeing to trust the authority of each other. In this case, the PKI structure does not extend vertically but does extend horizontally. See Figure 91.

Figure 91: Cross-Certification

Image g030623.gif


[Contents] [Prev] [Next] [Index] [Report an Error]