In several places in this chapter, I have mentioned about the PKI hierarchy and components, such as root CAs, intermediate CAs, and issuing CAs. Based on the business and operation requirements, PKI topology will also change. There are three deployments models we can use to address the PKI requirements. In this section, we will look into these models and their characteristics.
PKI deployment models
The single-tier model
This model is also called as one-tier model, and it is the simplest deployment model for PKI. This is not recommended to use in any production network, as its single point of failure of entire PKI:
In this model, a single CA will act as root CA and issuing CA. As I explained before, the root CA is the highest...