Glossary · OT cybersecurity
Certificate authority (CA)
Also known as: Certification authority
German: Zertifizierungsstelle (CA)
In public key infrastructure, a certificate authority (CA) is a trusted entity that issues, signs and revokes digital certificates binding a public key to an identity such as a device, user or server. Relying parties trust a certificate if it chains up to a CA they trust.
- OT security
In one sentence
A certificate authority (CA) issues, signs and revokes digital certificates that bind public keys to devices, users or servers.
Example
A plant operates its own CA that issues X.509 certificates to OPC UA servers and clients, so each connection can be authenticated with certificates instead of passwords.
How it applies
- Engineering: OT protocols such as OPC UA and secure variants of industrial Ethernet use X.509 certificates. The design must decide whether devices use certificates from an operator CA, a vendor CA or self-signed certificates, and how trust lists are distributed.
- Operation: Certificates expire. A CA process must renew them in time and publish revocation information; an expired certificate can stop communication between controllers and servers.
- Maintenance: The CA's private key is a critical asset. Compromise would let an attacker issue trusted certificates, so it needs strong protection and a documented recovery plan.
- Documentation: Product manuals should explain how certificates are installed, renewed and replaced on the device, what happens when a certificate expires, and which certificate formats and key lengths the device accepts.
CA vs. PKI
The CA is one component. Public key infrastructure (PKI) is the whole system of CAs, registration processes, policies, certificate storage and revocation services.