Specifications
6-14
Miscellaneous
Figure 6-8: Certificate hierarchy
The root certificate is either a CA-issued certificate or a self-signed one,
i.e. it is signed by its own private key. From this root certificate other
certificates can be created (intermediates), that enable other users to
digitally sign items in the name of the root via their private keys. Addi-
tionally, from intermediate certificates further certificates can be creat-
ed (either other intermediates or leaf certificates). The last link in the
chain is the leaf certificate that can only be used for signing, meaning
other certificates cannot be created from a leaf.
All certificates in a certificate chain refer back to the identity that is
bound to the root certificate and thus inherit the trustworthiness of the
root.
Root Certificate
Intermediate A2
Certificate
Leaf
Certificate
Intermediate A1
Certificate
Intermediate B2
Certificate
Intermediate B1
Certificate
Leaf
Certificate
Leaf
Certificate
Intermediate B4
Certificate
Intermediate B3
Certificate
Leaf
Certificate