CA (certificate authority) is divided into independent CA and distributed CA.
Paginated CA refers to multi-level CA, including root CA, second-level CA, third-level CA and fourth-level CA. . .
The specific number of levels is decided by the enterprise.
Now it is generally divided into two levels of CA. Also called root CA and subordinate CA.
The root CA is the source of trust and manages subordinate CAs, which are what you call subordinate CAs.
The root CA formulates root policies, such as validity period, etc., and the validity period of the subordinate CA will not exceed the root CA.
Differences:
Root CA: Responsible for managing subordinate CAs, including issuance, revocation, etc., and publishing ARL
Subordinate CA: Responsible for managing user certificates (including Individual users, enterprise users, administrators, servers, code signing certificates, etc.), including issuance, revocation, freezing, thawing, etc., as well as publishing CRL