← Back to security

PKI Trust Chain

6 questions · ~5 min · intermediate

Six questions on the moving parts of PKI: CA hierarchy, SAN and Basic Constraints, stapled OCSP, CT logs, and what pinning actually narrows.

0 / 6

Why do public web PKIs use intermediate CAs instead of having roots issue every leaf certificate directly?

Press 1 to 4 to pick an answer