Index
FAQ
How to activate the CA private key?
A threshold number of Secret Shares (m) out of the total number of Secret Shares created and distributed for a particular hardware cryptographic module (n) is required to activate a CA private key stored on the module. Using m-out-of-n to control IC card groups, the IC card groups are separately kept by an administrator and issuer.
How and when does CA carry out certificate Re-key?
Two months prior to expiration of the private key, the CA Re-key the key pair for certificate issuance. After Re-key, it is necessary to apply for a new certificate with the Government CA.
What is a private key?
- The key of a signature key pair used to create a digital signature.
- It is also the key of the key pair for decrypting confidential information.
What is a public key?
- The key of a signature key pair used to validate a digital signature.
- It is also the key of the key pair for encrypting confidential information.
What is Re-Key?
To change the value of a cryptographic key that is being used in a cryptographic system application; this normally entails issuing a new certificate on the new public key. It uses a new serial number and possibly specified a new validity period.
How and when do certificate subscribers have their certificate re-key?
Two months prior to the expiration of a private key, it is necessary for the Subscriber to Re-key the certificate to maintain continuity of Certificate usage. It is also necessary to apply for a new certificate with the Certification Authority.
What is a Key Pair?
Two mathematically related public and private keys with following characteristics:
- One key can be used for data encryption, and the other key for decryption.
- It is impossible to find out another key even though you know one key (from view of computing).