Skip to content

Root & Sub CA Architecture

Root CA and Sub-CA Architecture

In enterprise PKI environments, the Root Certificate Authority (CA) and Sub-CAs form the backbone of trust hierarchies. This architecture enables scalable, secure certificate management by delegating authority to subordinate CAs while maintaining centralized control over root-level trust.


Root CA: The Trust Anchor

The Root CA is the top-level authority in the hierarchy. Its certificate is inherently trusted by systems and applications, forming the foundation of the PKI. Key responsibilities include:
- Issuing and revoking root certificates.
- Signing certificates for Sub-CAs and end-entity certificates.
- Managing long-term cryptographic keys (typically stored in Hardware Security Modules or offline).

Key Management:
- Root CA private keys must be offline and protected by strict access controls.
- Root certificates are often pre-installed in operating systems, browsers, or applications.

Example:

# Generate Root CA key pair  
openssl genrsa -out root_ca_key.pem 4096  

# Create self-signed root certificate  
openssl req -new -x509 -days 365 -key root_ca_key.pem -out root_ca_cert.pem  


Sub-CA: Delegation and Scalability

Sub-CAs act as intermediaries, enabling hierarchical delegation of certificate issuance. They:
- Issue end-entity certificates (e.g., for servers, clients).
- Rely on the Root CA for trust validation.
- Operate under strict access controls and audit policies.

Certificate Issuance Workflow:
1. Sub-CA requests a certificate from the Root CA.
2. Root CA signs the Sub-CA’s certificate, creating a trust chain.
3. Sub-CA issues end-entity certificates, which are validated against the Root CA’s certificate.

Example:

# Generate Sub-CA key pair  
openssl genrsa -out sub_ca_key.pem 2048  

# Request certificate from Root CA  
openssl req -new -key sub_ca_key.pem -out sub_ca_csr.pem  

# Sign Sub-CA certificate with Root CA (offline)  
openssl x509 -req -in sub_ca_csr.pem -CA root_ca_cert.pem -CAkey root_ca_key.pem -CAcreateserial -out sub_ca_cert.pem -days 730  


Trust Chain and Validation

A certificate chain is validated by tracing from the end-entity certificate up to the Root CA:
1. End-entity certificate → Sub-CA certificate → Root CA certificate.
2. Systems validate each certificate against the Root CA’s trusted store.

Revocation:
- Root CAs manage revocation lists (CRLs) or OCSP responders for all subordinate certificates.
- Sub-CAs must report revoked certificates to the Root CA.


Diagram: Root CA and Sub-CA Hierarchy

Root CA (Trusted Anchor)
│
├── Sub-CA 1 (Intermediate CA)
│   ├── End Entity A
│   └── End Entity B
│
└── Sub-CA 2 (Intermediate CA)
    ├── End Entity C
    └── End Entity D

Key takeaways

  • Root CAs are the ultimate trust anchors, with private keys stored offline for security.
  • Sub-CAs enable scalable certificate issuance by delegating authority while relying on the Root CA for trust.
  • Certificate chains validate trust by tracing from end-entity certificates to the Root CA.
  • Key management and revocation processes must be rigorously enforced across all CAs in the hierarchy.