TechKnowSurge
CompTIA Security+ 1.4 CompTIA SecurityX 2.2 Cisco CyberOps Associate 2.11 Cisco CCST Cybersecurity 1.4 NIST 800-53 SC-17 ISC2 CISSP 3.6
InteractiveSecurityFree

Root, Intermediate or End-Entity?

Sort each description to the certificate it fits: the root at the top, an intermediate in the middle, or the end-entity certificate on the website.

⚑ Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

Public key infrastructure applies hierarchy trust to certificates: trust starts at the top and is passed down, one certificate to the next. The root certificate sits at the top and is the anchor of trust that proves everything else. Its public key is already installed on your computer, so the website never has to send it. Because so much depends on it, certificate authorities put safeguards around it, and one of those is creating intermediate certificates beneath it. An intermediate certificate is issued to an intermediate, or subordinate, certificate authority, which keeps its own private key. It adds a layer of security, and it lets a CA pass some of its trust to another entity, though it can also be the same CA. There can be more than one intermediate level, so a chain can be longer than three certificates. The end-entity certificate is the one used on the service: techknowsurge.com's own certificate, which the site got by submitting a CSR. The site installs it together with the intermediate certificate, and your computer downloads both when it connects. Verification runs down the chain. The root certificate's public key decrypts the fingerprint on the intermediate certificate; if it checks out, the intermediate is valid. The intermediate certificate's public key then decrypts the fingerprint on the end-entity certificate. If that checks out too, the site's certificate is verified.

What you'll learn

Aligned to

CompTIA Security+
1.4 Explain the importance of using appropriate cryptographic solutions.
CompTIA SecurityX
2.2 Given a scenario, implement appropriate PKI infrastructure solutions.
Cisco CyberOps Associate
2.11 Identify the certificate components in a given scenario
Cisco CCST Cybersecurity
1.4 Explain encryption methods and applications
NIST 800-53
SC-17 Public Key Infrastructure Certificates
ISC2 CISSP
3.6 Select and determine cryptographic solutions

Key terms

Root Certificate
The self-signed certificate at the top of a PKI hierarchy that serves as the ultimate anchor of trust for all subordinate certificates.
Intermediate Certificate
A certificate issued by a root CA that passes trust down to end-entity certificates, adding a layer of security by keeping the root CA offline.
End-Entity Certificate
The certificate issued to a specific service or website that end users verify to confirm they are communicating with a legitimate source.
Chain of Trust
The linked sequence of trust relationships that connects an entity back to a trusted anchor, validating each step in the hierarchy.
Certificate Authority
CA
A trusted entity that issues digital certificates used to verify the identity of individuals, organizations, or devices.
Certificate Signing Request
CSR
A Certificate Signing Request is a block of encoded text containing an applicant's public key and identity information, submitted to a Certificate Authority to request a signed digital certificate.
Public Key
A cryptographic key that can be shared openly and is used to encrypt data or verify digital signatures.

Topics

Certificate Hierarchy Chain Of Trust Public Key Infrastructure Interactive Categorize

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →