Glossary · Identity and trust

Certificate authority

An entity that issues digital certificates and vouches for the binding between a public key and a name. TLS and mutual TLS trust rest on CAs.

A certificate authority (CA) is an entity that issues digital certificates, usually X.509 certificates, and vouches for the binding between the public key in each certificate and the name and other data it contains.

How trust flows. RFC 5280, the internet profile for X.509, and RFC 4949 both use the name “certification authority”. A certificate for api.example.com is signed by a CA. That CA’s own certificate may be signed by another CA, which forms a certification path. A relying party accepts the path only if it starts at a trust anchor the relying party already holds, and RFC 5280 treats the choice of trust anchors as a matter of policy. Organizations can run a private CA for internal services or for mutual TLS with known partners.

Lifecycle duties. RFC 4949 describes a CA as responsible for managing each certificate’s life. That includes revoking a certificate before it expires when, for example, its private key is compromised. RFC 5280 profiles certificate revocation lists that CAs sign and publish for this.

Keeping CAs honest. Certificate Transparency (RFC 9162) runs public append-only logs of TLS server certificates. Public CAs are expected to submit every certificate they issue, and domain owners can monitor the logs for certificates they never requested. When misissuance is found, the RFC points to remedies such as revoking the certificate or asking maintainers of trust anchor lists to remove the CA.

For agents. A2A clients should validate a server’s TLS certificate against trusted CAs during the handshake, which ties the connection to the domain in the interface URL. That is domain-level identity only. A CA does not vouch for what an agent is allowed to do or whom it represents. Agent Card signatures are verified with keys fetched through kid and jku or held in a trusted key store, and the A2A specification does not tie those keys to a CA, so deciding who owns a card-signing key is a separate trust decision.

Neighbouring terms. Mutual TLS uses CA-issued certificates on both ends of a connection. Credential revocation covers how a CA withdraws a certificate early.

Sources

  1. RFC 4949: Internet Security Glossary, Version 2 (accessed )
  2. RFC 5280: Internet X.509 Public Key Infrastructure Certificate and CRL Profile (accessed )
  3. RFC 9162: Certificate Transparency Version 2.0 (accessed )
  4. A2A Protocol Specification, section 7.2: Server Identity Verification (accessed )
  5. A2A Protocol Specification, section 8.4.3: Signature Verification (accessed )