Module 7
X.509 and PKI
5 lessonsabout 170 minFoundations / Practitioner / Advisor
After this module you can
- State with the correct figure how much an X.509 chain really grows under PQC
- Explain the impact on OCSP, CRL and Merkle Tree Certificates
- Defend a PKI hierarchy design with a checkable diagram
Before thisM6: Architecture decisions
- 01Refresher: X.509 certificates and PKIExplain in one paragraph what an X.509 certificate chain (root/intermediate/leaf) is and why trust rests on a chain rather than a single certificate
- 02Certificate chain bloatState from memory the PEM size of a real, single-encoding (PEM), single-composition (ML-DSA-65 throughout) three-certificate chain
- 03OCSP/CRL impact and Merkle Tree CertificatesExplain how PQC signatures affect OCSP and CRL size, separating which component grows and which does not
- 04Root rollover and cross-signingExplain the real triggers of a root rollover (algorithm transition included) and why it takes years
- 05Dual PKI, composite and the CA/B Forum timelineDistinguish the choice between dual PKI (parallel stack) and composite certificates in terms of operational cost