Reader small image

You're reading from  CompTIA Security+: SY0-601 Certification Guide - Second Edition

Product typeBook
Published inDec 2020
PublisherPackt
ISBN-139781800564244
Edition2nd Edition
Right arrow
Author (1)
Ian Neil
Ian Neil
author image
Ian Neil

Ian Neil is one of the world's top trainers of Security+. He is able to break down information into manageable chunks so that people with no background knowledge can gain the skills required to become certified. He has recently worked for the US Army in Europe and designed a Security+ course that catered to people from all backgrounds (not just IT professionals), with an extremely successful pass rate. He is an MCT, MCSE, A+, Network+, Security+, CASP, and RESILIA practitioner that has worked with high-end training providers over the past 23 years and was one of the first technical trainers to train Microsoft internal staff when they opened their Bucharest Office in 2006.
Read more about Ian Neil

Right arrow

Chapter 2 – Implementing Public Key Infrastructure

  1. A CA has a root certificate, which it uses to sign keys.
  2. You would use a private CA for internal use only; these certificates will not be accepted outside of your organization.
  3. You would use a public CA for B2B activities.
  4. If you were a military, security, or banking organization, you would keep the CA offline when it is not being used to prevent it from being compromised.
  5. PKI uses asymmetric encryption.
  6. The CA signs the X509 certificates.
  7. Certificate pinning can be used to prevent a CA from being compromised and fraudulent certificates from being issued.
  8. If two separate PKI entities want to set up cross-certification, the root CAs would set up a trust model between themselves, known as a bridge trust model.
  9. PGP uses a trust model known as a web of trust.
  10. A Certificate Revocation List (CRL) is used to determine whether a certificate is valid.
  11. If the CRL is going slow, you...
lock icon
The rest of the page is locked
Previous PageNext Page
You have been reading a chapter from
CompTIA Security+: SY0-601 Certification Guide - Second Edition
Published in: Dec 2020Publisher: PacktISBN-13: 9781800564244

Author (1)

author image
Ian Neil

Ian Neil is one of the world's top trainers of Security+. He is able to break down information into manageable chunks so that people with no background knowledge can gain the skills required to become certified. He has recently worked for the US Army in Europe and designed a Security+ course that catered to people from all backgrounds (not just IT professionals), with an extremely successful pass rate. He is an MCT, MCSE, A+, Network+, Security+, CASP, and RESILIA practitioner that has worked with high-end training providers over the past 23 years and was one of the first technical trainers to train Microsoft internal staff when they opened their Bucharest Office in 2006.
Read more about Ian Neil