5.7: Elements of Public Key Infrastructure (Doshi) Flashcards

1
Q

What is a public key infrastructure?

A

A centralized function that is used to store and publish public keys and other information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

The process involved in PKI for Digital Certificate:

A

(1) Applicant applies for Digital certificate from Certifying Authority (CA).
(2) The CA delegates the process for verification of information to Registration Authority (RA).
(3) The RA validates the information and if it’s correct, tells CA to issue the certificate.
(4) CA issues the certificates and manages the same thought its life cycle.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Certificate revocation list:

A

A list of revoked/terminated certificates maintained by the CA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Certification Practice Statement (CPS)

A

Contains standard operating procedure for issuance of certificate

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What does CA do AFTER the certificate is issued?

A

CA validates and authenticates the holder after issuance of certificate

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What does RA do BEFORE the certificate is issued?

A

RA validates and authenticates information of the applicant before issuance of certificate.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Function of RA:

A

(1) Verify information supplied by the applicant
(2) Verifying that the applicant actually possesses the private key being registered and that matches public key requested for certificate. This is generally referred to as proof of possession (POP).
(3) Distributing the physical tokens containing the private keys.
(4) Generating shared secrets key for use during initialization and certificate pick-up phases of registration

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Authority that manages the certificate life cycle is the:

A. certificate authority (CA)
B. certificate revocation list (CRL)
C. certification practice statement (CPS)
D. registration authority (RA

A

A. certificate authority (CA)

In any given scenario, certifying authority (CA) is solely responsible for issuance of digital certificate and managing the certificate throughout its life cycle. Registration authority performs the process of identification and authentication by establishing a link between the identity of the requesting person or organization and the public key. In short, a CA manages and issues certificates, whereas a RA is responsible for identifying and authenticating the information provided by subscribers, but does not sign or issue certificates. CRL is a list of certificates that have been revoked before their scheduled expiration date. CPS is a detailed set of rules and processes of Certifying Authority’s (CA) operations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

In a public key infrastructure, role of a registration authority (RA) is to:

A. issue the certificate to subscriber.
B. manage certificate throughout its life cycle.
C. maintain list of revoked list.
D. validate the information provided by the subscriber requesting a certificate.

A

D. validate the information provided by the subscriber requesting a certificate.

In any given scenario, registration authority (RA) is responsible for identifying and authenticating subscribers, but does not sign or issue certificates. Certifying authority (CA) is solely responsible for issuance of digital certificate, managing the certificate throughout its life cycle and maintaining list of revoked certificates.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Which of the following PKI element control and manage the digital certificate life cycle to ensure proper security exist in digital signature applications?

A. Certification revocation list
B. Registration authority (RA)
C. Certificate authority (CA)
D. Certification practice statement

A

C. Certificate authority (CA)

In any given scenario, certifying authority (CA) is solely responsible for issuance of digital certificate and managing the certificate throughout its life cycle. Registration authority is an optional entity that is responsible for the administrative tasks like identifying and authenticating the information provided by applicants. Choice A is incorrect since a CRL is a list of certificates that have been revoked before their scheduled expiration date. Choice D is incorrect because a certification practice statement is a detailed set of rules governing the certificate authority’s operations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Which of the following processes can be delegated by a certificate authority (CA)?

A. issuance of digital certificates.
B. managing the certificate throughout its life cycle.
C. establishing a link between the requesting entity and its public key.
D. maintain list of revoked list.

A

C. establishing a link between the requesting entity and its public key.

Establishing a link between the requesting entity and its public key is a function of a registration authority. This function can be delegated to RA. Other functions have to be managed by CA only.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

In public key infrastructure, which of the following would an IS auditor consider a weakness?

A. Certificate authorities are centrally located however customers are widely dispersed geographically.
B. Transactions can be made from any computer or mobile device.
C The certificate authority has multiple data processing centers to manage the certificates.
D. The organization is the owner of the certificate authority

A

D. The organization is the owner of the certificate authority.

If an organization is the owner of the certificate authority, this would generate a conflict of interest. Independence of certifying authority will not be there in such cases and the third party may repudiate the transactions. The other options are not weaknesses.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

In a public key infrastructure, a registration authority:

A. issues the certificate.
B. verifies information supplied by the subject requesting a certificate.
C. signs the certificate to achieve authentication and non-repudiation.
D. managing the certificate throughout its life cycle.

A

B. verifies information supplied by the subject requesting a certificate.

In any given scenario, registration authority (RA) is responsible for identifying and authenticating subscribers, but does not sign or issue certificates. A registration authority is responsible for verifying information supplied by the subject requesting a certificate. Option A & Option D are the functions of CA. Option C is not the task performed by RA. . On the other hand, the sender who has control of his/her private key, signs the message, not the registration authority.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Detailed descriptions for dealing with a compromised private key is provided in which of the following public key infrastructure (PKI) elements?

A. Certificate policy (CP)
B. Certificate revocation list (CRL)
C. Certification practice statement (CPS)
D. PKI disclosure statement (PDS)

A

C. Certification practice statement (CPS)

Certification practice statement (CPS) is a detailed set of rules and processes of Certifying Authority’s (CA) operations. Certification Practice Statement (CPS) is a document in which standard operating procedure (SOP) for issuance of certificate and other relevant details are documented. The CPS is the how-to part in policy-based PKI. CRL is a list of certificates that have been revoked before their scheduled expiration date. The PDS covers critical items, such as the warranties, limitations and obligations that legally bind each party

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

In a public key infrastructure, the role of a certificate authority (CA) is to:

A. ensure secured communication and secured network services based on certificates.
B. validate the identity and authenticity of the entity owning the certificate and integrity of the certificate issued by that CA.
C. ensure secured communication infrastructure between parties.
D. hosting of private keys of subscribers in the public domain.

A

B. validate the identity and authenticity of the entity owning the certificate and integrity of the certificate issued by that CA.

The primary activity of a CA is to issue certificates and to validate the identity and authenticity of the entity owning the certificate and integrity of the certificate issued by that CA. CAs are not responsible of secured communication channel. Private keys are not made available in public domain.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

In any given scenario, certifying authority (CA) is solely responsible for

A

issuance of digital certificate and managing the certificate throughout its life cycle.

17
Q

In any given scenario, registration authority (RA) is responsible for

A

identifying and authenticating subscribers, but does not sign or issue certificates.

18
Q

In any given scenario, a digital certificate is composed of

A

public key and information about the owner of public key.

19
Q

In any given scenario, time gap between update of CRL (certificate revocation list) is

A

critical and is also posses risk in certification verification.