Knowledge check
10 questions testing what you just read — no login, no tracking, just immediate feedback.
Why does a root CA's private key typically stay offline and air-gapped?
What happens operationally if an intermediate CA's key is compromised, under the root/intermediate split?
What is a "key ceremony" in the context of root CA key generation?
What does the ACME protocol (RFC 8555) primarily automate?
Which of these is NOT one of ACME's standard domain-validation challenge types?
As of the CA/Browser Forum's current published schedule, what is the maximum publicly-trusted TLS certificate validity as of March 2026?
By March 2029, the CA/Browser Forum's maximum certificate validity is scheduled to drop to how many days?
Why has Let's Encrypt issued 90-day certificates since it launched in 2015, rather than a longer, more "convenient" lifetime?
In a (k, n)-threshold key-ceremony scheme requiring 3 of 5 participants, what's the maximum number of participants who can be absent while the ceremony still proceeds?
What's the main operational reason shrinking certificate lifetimes are pushing PKI automation industry-wide?