Digital Certificate — CA, PKI models, Chain of Trust, Root Store

Part 1 of four-part series about digital certificate
  • Authenticated and encrypted web browsing (via HTTPS)
  • Signed and encrypted email (via S/MIME protocol)
  • Code Signing
  • Digital Signature
  • Server Authentication
  • Client Authentication, etc.
Hierarchical PKI
Bridge PKI²
DOD PKI External Interoperability Landscape³
Microsoft Trusted Root Program for Windows
Mozilla Firefox Certificate root store
Chrome Certificate root store
  • Path construction⁷ ⁸
Certificate Chain⁷
  • Path Validation



Deepak Singh

Sales Eng., Consultant, Solutions Architect, Analyst, Hobbyist Coder. 2 Masters — MBA Georgia Tech, MS Analytics. Interested in technology, business & strategy