Public Key Infrastructure (PKI)
At its Düsseldorf site, the Bundesbank operates a Public Key Infrastructure (PKI). This PKI uses a two-stage certification structure with self-signed root certificates. The root CA certificates certify only downstream specialist CAs.
Root CA certificates
CA certificates for e-mail security
CA certificates for user authentication
CA certificates for digital signature
PGP – Pretty Good Privacy
In addition to using the S/MIME encryption method, the Bundesbank uses the PGP method to encrypt confidential e-mails.
Current certificate revocation lists (CRLs)
The Bundesbank's PKI generates updated CRLs at regular intervals.