Root & Sub CA Architecture
Root CA and Sub-CA Architecture¶
In enterprise PKI environments, the Root Certificate Authority (CA) and Sub-CAs form the backbone of trust hierarchies. This architecture enables scalable, secure certificate management by delegating authority to subordinate CAs while maintaining centralized control over root-level trust.
Root CA: The Trust Anchor¶
The Root CA is the top-level authority in the hierarchy. Its certificate is inherently trusted by systems and applications, forming the foundation of the PKI. Key responsibilities include:
- Issuing and revoking root certificates.
- Signing certificates for Sub-CAs and end-entity certificates.
- Managing long-term cryptographic keys (typically stored in Hardware Security Modules or offline).
Key Management:
- Root CA private keys must be offline and protected by strict access controls.
- Root certificates are often pre-installed in operating systems, browsers, or applications.
Example:
# Generate Root CA key pair
openssl genrsa -out root_ca_key.pem 4096
# Create self-signed root certificate
openssl req -new -x509 -days 365 -key root_ca_key.pem -out root_ca_cert.pem
Sub-CA: Delegation and Scalability¶
Sub-CAs act as intermediaries, enabling hierarchical delegation of certificate issuance. They:
- Issue end-entity certificates (e.g., for servers, clients).
- Rely on the Root CA for trust validation.
- Operate under strict access controls and audit policies.
Certificate Issuance Workflow:
1. Sub-CA requests a certificate from the Root CA.
2. Root CA signs the Sub-CA’s certificate, creating a trust chain.
3. Sub-CA issues end-entity certificates, which are validated against the Root CA’s certificate.
Example:
# Generate Sub-CA key pair
openssl genrsa -out sub_ca_key.pem 2048
# Request certificate from Root CA
openssl req -new -key sub_ca_key.pem -out sub_ca_csr.pem
# Sign Sub-CA certificate with Root CA (offline)
openssl x509 -req -in sub_ca_csr.pem -CA root_ca_cert.pem -CAkey root_ca_key.pem -CAcreateserial -out sub_ca_cert.pem -days 730
Trust Chain and Validation¶
A certificate chain is validated by tracing from the end-entity certificate up to the Root CA:
1. End-entity certificate → Sub-CA certificate → Root CA certificate.
2. Systems validate each certificate against the Root CA’s trusted store.
Revocation:
- Root CAs manage revocation lists (CRLs) or OCSP responders for all subordinate certificates.
- Sub-CAs must report revoked certificates to the Root CA.
Diagram: Root CA and Sub-CA Hierarchy¶
Root CA (Trusted Anchor)
│
├── Sub-CA 1 (Intermediate CA)
│ ├── End Entity A
│ └── End Entity B
│
└── Sub-CA 2 (Intermediate CA)
├── End Entity C
└── End Entity D
Key takeaways¶
- Root CAs are the ultimate trust anchors, with private keys stored offline for security.
- Sub-CAs enable scalable certificate issuance by delegating authority while relying on the Root CA for trust.
- Certificate chains validate trust by tracing from end-entity certificates to the Root CA.
- Key management and revocation processes must be rigorously enforced across all CAs in the hierarchy.