170 likes | 238 Views
pkiuniversity.com. Honest Abe ’ s CA. Alice. Bob. Simple PKI hierarchy. Multi-level hierarchy. My personal Certificate (Installed on a Mac). Dartmouth CA ’ s Certificate (Installed on a Mac). Building a trust path.
E N D
Honest Abe’s CA Alice Bob
Building a trust path • To verify certificate α starting with a set of trusted certificates we need to: • Identify the issuer of α (i.e., β) • Verify if β is trusted • If β is among the set of trusted certificates, the original cert is trusted • Else if β is a root certificate, the original cert is untrusted • Else if β is not trustedset α=β and repeat the process until a trusted or a root certificate is identified