Is it important to OpenVPN security practices to build an intermediate certificate authority/key?

Unless you know that you need it, you generally don't -- just be very careful about keeping your CA safe.

Having an intermediate CA allows you to keep your "real" CA locked up with no network connections whatsoever and the intermediate CA located somewhere with security levels which, while high, impinge less on getting work done. Then, in the event that the intermediate CA is compromised, you can revoke it and create a new one without replacing your real CA.

If you're not going to be following this procedure (real CA locked up w/ no network connections), there's no value-add to having an intermediate CA.

Return to FAQ

Last modified 10 years ago Last modified on 01/30/14 15:15:48