Public Key Infrastructure
221/258
16.2.2
Hierarchy of trust
Certificates link with other certificates for authentication, that have been
issued by an instance classified as being trustworthy. Such a certificate
itself can link to another one, etc. So, a chain of concatenated certificates
linked pair-wise is generated. This chain is denominated as the hierarchy of
trust. One certificate is located at the end of this chain. This one is
denominated as the root certificate. It is not linked to another certificate, but
to itself, thus putting an end to the chain of certificates. Such certificates are
denominated as self-signed certificates. You will only trust a self-signed
certificate, if it has been signed by an extraordinarily trustworthy authority.
For this purpose, Certificate Authorities (CAs)s have been established who
sign certificate requests, who issue certificates and who check the identity
and authority of the requestors. Usually, these are renowned official
institutions, clubs or companies..
Consequently, the authenticity check of a certificate is practically done in
that way, that the complete hierarchy of trust is tracked up to the root
certificate, whose issuer is determined and a list of well-known trustworthy
root certificates is searched whether it contains the root certificate at the
end of the hierarchy of trust. Such lists are maintained by all browser
manufacturers within the scope of special membership programmes and
may be found within browsers, operating systems and mobile devices.
On the Edge Gatewaythe operating system Linux is run, which itself
maintains such a list of root certificates of renowned CAs. This list is
denominated as the Linux Trust Store and thus constitutes the Root
Certificate Store of Linux.
Note:
A list of trustworthy root certificates is maintained by the Mozilla
organisation under the denomination
Mozilla CA Certificate Store
,
see
https://www.mozilla.org/en-US/about/governance/policies/
. The display of root certificates in the Control
Panel of the Edge Gateway follows this list.
Edge Gateway | NIOT-E-TPI51-EN-RE (Connect)
DOC170502UM04EN | Revision 4 | English | 2018-08 | Released | Public
© Hilscher 2017 – 2018