DoD PKI Management FAQs (2024)

  1. What is the Public Key Infrastructure?
    The Public Key Infrastructure (PKI) is the mechanism for distributing a large number of public keys to a large group of users in a trusted manner. These trusted public keys can be used to verify digital signatures on a document (i.e., authentication, document integrity, and non-repudiation) and to encrypt the documents.
  2. What is a Certification Authority?
    A Certification Authority (CA) is the entity that is responsible for issuing and revoking public key certificates and is trusted by the users of the PKI. The main functions it performs are issuance of public key certificates, publishing of user certificates, and promulgation of certificate revocation lists (CRLs).The public key certificates issued to users are signed by the associated CA to ensure that trust can be placed in their authenticity and integrity.
  3. What is a Root CA?
    The root CA is a trusted entity responsible for the issuing and administering of digital certificates that are to be used by subordinate CAs. The digital certificate of the root CA is self-signed, that is, the root CA authenticates its own identity. The root CA signs the digital certificates issued to subordinate CAs in its domain. The DoD root CA is the trust anchor for the DoD PKI subscribers. The DoD PKI subscriber verifies all certification paths starting with the DoD root CA public key. DoD PKI subscribers explicitly trust the DoD root CA public key.
  4. Why can't I download the certificate for the Root CA via this interface?
    The Root CA uses a self-signed certificate and it serves as the trust anchor for other CAs in its domain. Because of security concerns it must not be made available over clear, unprotected, unsecured and non-authenticated links.
    • Note: The certificate for a Root CA can be obtained from an appropriate source. However, being a self-signed certificate, it has ABSOLUTELY no security to it. Thus, its integrity must be verified using some trusted means. One must get the thumbprint of the DoD root from a trusted source and verify that the thumbprint of the downloaded root is the same as the thumbprint obtained from trusted source. If one does not do that, the security of the applicable PKI may be compromised. It may be noted that the Microsoft certificate processing tools (native to one's machine) can be used to obtain the thumbprint of any certificate.
  5. Why do I need to view the CA certificate?
    One should view the CA certificate in order to verify its proper ownership and to determine if it is still valid (i.e., it has not expired).
  6. What is a Certificate Revocation List?
    A Certificate Revocation List is a list of revoked certificates and the reason date of revocation. A CRL is periodically updated by each CA and promulgated.
  7. Why do I need to download the CRL?
    To verify if a particular CA or user certificate is still valid (not revoked).
  8. How often is the CRL updated?
    By default this interface checks for CRL updates every 5 minutes. The frequency of updates may become more or less dependent on the volatility of the underlying data.
  9. Why do I need a CA Certificate?
    The CA certificate is required to build a certification path (trust chain) from the DoD root (that you explicitly trust) to the user certificate. For example, if you need to verify a signature generated by "John Doe" or send an encrypted e-mail to "John Doe" you need the following certificate chain: DoD root CA -> Signing CA -> John Doe

If you have any technical questions about the PKI Management Interface, send inquiries to disa.meade.id.mbx.gds@mail.mil or dodpke@mail.mil.

DoD PKI Management FAQs (2024)
Top Articles
7 Key Blockchain Adoption Challenges in Banking
Budget Planning | Why Budgeting Is Important & Reasons For Budgeting
Friskies Tender And Crunchy Recall
Tmf Saul's Investing Discussions
Is pickleball Betts' next conquest? 'That's my jam'
Lowes 385
Sunday World Northern Ireland
Garrick Joker'' Hastings Sentenced
Lantana Blocc Compton Crips
Cool Math Games Bucketball
Local Dog Boarding Kennels Near Me
Echo & the Bunnymen - Lips Like Sugar Lyrics
Sony E 18-200mm F3.5-6.3 OSS LE Review
Stihl Km 131 R Parts Diagram
Viprow Golf
National Weather Service Denver Co Forecast
How Much Is Tay Ks Bail
Drago Funeral Home & Cremation Services Obituaries
Nordstrom Rack Glendale Photos
Lista trofeów | Jedi Upadły Zakon / Fallen Order - Star Wars Jedi Fallen Order - poradnik do gry | GRYOnline.pl
Kaitlyn Katsaros Forum
Raz-Plus Literacy Essentials for PreK-6
Isaidup
Like Some Annoyed Drivers Wsj Crossword
Galaxy Fold 4 im Test: Kauftipp trotz Nachfolger?
48 Oz Equals How Many Quarts
How To Tighten Lug Nuts Properly (Torque Specs) | TireGrades
3Movierulz
Abga Gestation Calculator
Summoners War Update Notes
Log in to your MyChart account
Best New England Boarding Schools
Does Circle K Sell Elf Bars
Kokomo Mugshots Busted
Forager How-to Get Archaeology Items - Dino Egg, Anchor, Fossil, Frozen Relic, Frozen Squid, Kapala, Lava Eel, and More!
Royal Caribbean Luggage Tags Pending
Plato's Closet Mansfield Ohio
Dreammarriage.com Login
2016 Honda Accord Belt Diagram
Ljw Obits
2008 Chevrolet Corvette for sale - Houston, TX - craigslist
Petsmart Northridge Photos
450 Miles Away From Me
My.lifeway.come/Redeem
Bbc Gahuzamiryango Live
D-Day: Learn about the D-Day Invasion
Sam's Club Gas Prices Deptford Nj
Dogs Craiglist
Jeep Forum Cj
Washington Craigslist Housing
Jigidi Jigsaw Puzzles Free
Fahrpläne, Preise und Anbieter von Bookaway
Latest Posts
Article information

Author: Greg O'Connell

Last Updated:

Views: 5880

Rating: 4.1 / 5 (42 voted)

Reviews: 81% of readers found this page helpful

Author information

Name: Greg O'Connell

Birthday: 1992-01-10

Address: Suite 517 2436 Jefferey Pass, Shanitaside, UT 27519

Phone: +2614651609714

Job: Education Developer

Hobby: Cooking, Gambling, Pottery, Shooting, Baseball, Singing, Snowboarding

Introduction: My name is Greg O'Connell, I am a delightful, colorful, talented, kind, lively, modern, tender person who loves writing and wants to share my knowledge and understanding with you.