Module 7

X.509 and PKI

5 lessonsabout 170 minFoundations / Practitioner / Advisor

After this module you can

  • State with the correct figure how much an X.509 chain really grows under PQC
  • Explain the impact on OCSP, CRL and Merkle Tree Certificates
  • Defend a PKI hierarchy design with a checkable diagram

Before thisM6: Architecture decisions

  1. 01Refresher: X.509 certificates and PKIExplain in one paragraph what an X.509 certificate chain (root/intermediate/leaf) is and why trust rests on a chain rather than a single certificate
  2. 02Certificate chain bloatState from memory the PEM size of a real, single-encoding (PEM), single-composition (ML-DSA-65 throughout) three-certificate chain
  3. 03OCSP/CRL impact and Merkle Tree CertificatesExplain how PQC signatures affect OCSP and CRL size, separating which component grows and which does not
  4. 04Root rollover and cross-signingExplain the real triggers of a root rollover (algorithm transition included) and why it takes years
  5. 05Dual PKI, composite and the CA/B Forum timelineDistinguish the choice between dual PKI (parallel stack) and composite certificates in terms of operational cost
Next moduleM8: Protocols