PKI Topology - Security Policy - Cisco Certified Expert (2024)

Last Updated on Thu, 08 Dec 2022 |Security Policy

PKIs can form different topologies of trust. In one model, a single or root CA issues all the certificates to the end users, as shown in Figure 13-4.

Figure 13-4. Single Root CA

Figure 13-4. Single Root CA

The advantage of this setup is its simplicity, but there are some pitfalls. The setup has a single point of failure, and it is not suitable for large-scale deployments. Because of its simplicity, this topology is often used in VPNs managed by a single organization. A more complex topology involves multiple CAs within the same organization. This is called a hierarchical CA and is shown in Figure 13-5.

Figure 13-5. Hierarchical CA

[View full size imagel

Figure 13-5. Hierarchical CA

[View full size imagel

Siabardinele CA

Siabardinele CA

In this system, CAs can issue certificates to both end users and subordinate CAs. Subordinate CAs can, in turn, issue certificates to end users and other CAs. This topology is more scalable and manageable than the single root model, but it has weaknesses. A serious issue with hierarchical CAs is in finding the certification path for a certificate. The more CAs that are involved in establishing trust between a root CA and the end user, the more difficult it is to find the certification path.

Another approach to hierarchical CAs is called cross certifying. Figure 13-6 shows a sample setup of this topology. With cross certifying, multiple single-root CAs establish trust horizontally by cross certifying each other's certificates.

Figure 13-6. Cross-Certified CA

[View full size imagel

PKI Topology - Security Policy - Cisco Certified Expert (1)

Continue reading here: Different WLAN Configurations

Was this article helpful?

PKI Topology - Security Policy - Cisco Certified Expert (2024)
Top Articles
Latest Posts
Article information

Author: Madonna Wisozk

Last Updated:

Views: 5786

Rating: 4.8 / 5 (48 voted)

Reviews: 95% of readers found this page helpful

Author information

Name: Madonna Wisozk

Birthday: 2001-02-23

Address: 656 Gerhold Summit, Sidneyberg, FL 78179-2512

Phone: +6742282696652

Job: Customer Banking Liaison

Hobby: Flower arranging, Yo-yoing, Tai chi, Rowing, Macrame, Urban exploration, Knife making

Introduction: My name is Madonna Wisozk, I am a attractive, healthy, thoughtful, faithful, open, vivacious, zany person who loves writing and wants to share my knowledge and understanding with you.