3 ms·
Root certificates have their private keys in hardware security modules, which are kept in safes in secure facilities, only brought online when needed to sign in
by profmonocle 6y ago
Root certificates have their private keys in hardware security modules, which are kept in safes in secure facilities, only brought online when needed to sign intermediate certificates. Plus, it takes quite a while for new ones to be widely trusted - Let's Encrypt's root cert was issued in 2015 and still isn't trusted by a large percentage of older Android phones.
Intermediate certificates have shorter lifetimes. Even though they're kept online, they're also stored in HSMs. Even if the CA were compromised, the chance of the private key itself leaking is very small.
End user certificates, on the other hand, are usually handled much more cavalierly. Sure, you could store the key in an HSM, but most servers just keep them in memory (and in the file system). A server certificate's key is far, far more likely to be compromised than a CA key.