Certification Authority (CA)
Definition
Frequently asked questions
What is the role of a certification authority?
It attests that a public key belongs to a person or organization. To do this, it verifies the identity of the applicant, issues a certificate that it signs with its own key, then ensures its management: renewal, suspension and revocation. Without this third party, there would be nothing to reliably link a digital signature to its author.
What is the difference between a certification authority and a registration authority?
The registration authority is responsible for contact with the applicant: it collects their supporting documents and verifies their identity. The certification authority then intervenes to issue the certificate. The two functions may be exercised by the same organization or entrusted to separate entities, with the certification authority remaining responsible for the whole.
How does a certification authority become qualified?
It must have its compliance with the eIDAS regulation evaluated by an accredited audit body, then obtain qualified status from the supervisory authority of its country, the ANSSI in France. Its registration on the official national trust list formalizes this status. A new audit is then required at least every twenty-four months.
What happens if a certification authority is compromised?
The certificates it issued can no longer be considered reliable. The authority, or the one that certifies it, then revokes the certificates in question, and software publishers remove the root from their trust stores. It is to limit this risk that root keys are kept offline, in secure hardware modules.
Related guides
Related terms
Ready to Put These Concepts Into Practice?
Certyneo allows you to create eIDAS-compliant signature envelopes in just a few clicks, without installation.