PKI Public key Infrastructure (2)
Der binary encoding, base64 encoded files contain only certificates (suffix .cer)
The file in Pkcs12 format contains both the certificate and the private key (suffix .pfx, .p12)
The file in Pkcs7 format contains the certificate and all certificates in the certificate chain (suffix .p7b)
Pkcs10, the request of the client for a digital certificate from CA (which contains the user's personal information and the user's public key information. The P10 file is generated after the public key is owned. )
Pkcs7 (p7r), CA responds to client requests
The process of issuing an encryption certificate:
The client logs in to RA to register
RA validates and confirms registration information
RA will submit the certificate request information to the CA issuance center
KMC generates public and private key pairs of encryption certificates
CA extracts public and private keys (generates a complete P10 request)
CA issues certificates based on user registration information and public key information in the request
CA response message to RA
Users download certificates from RA
The process of issuing a signing certificate is similar to that of an encryption certificate, except that the public and private key pairs of the signing certificate are generated in the client USBkey.