← Back to the use case

Knowledge check

Running a PKI: how a certificate authority actually operates

10 questions testing what you just read — no login, no tracking, just immediate feedback.

Question 1 of 10

Why does a root CA's private key typically stay offline and air-gapped?

Question 2 of 10

What happens operationally if an intermediate CA's key is compromised, under the root/intermediate split?

Question 3 of 10

What is a "key ceremony" in the context of root CA key generation?

Question 4 of 10

What does the ACME protocol (RFC 8555) primarily automate?

Question 5 of 10

Which of these is NOT one of ACME's standard domain-validation challenge types?

Question 6 of 10

As of the CA/Browser Forum's current published schedule, what is the maximum publicly-trusted TLS certificate validity as of March 2026?

Question 7 of 10

By March 2029, the CA/Browser Forum's maximum certificate validity is scheduled to drop to how many days?

Question 8 of 10

Why has Let's Encrypt issued 90-day certificates since it launched in 2015, rather than a longer, more "convenient" lifetime?

Question 9 of 10

In a (k, n)-threshold key-ceremony scheme requiring 3 of 5 participants, what's the maximum number of participants who can be absent while the ceremony still proceeds?

Question 10 of 10

What's the main operational reason shrinking certificate lifetimes are pushing PKI automation industry-wide?

0 / 10 answered